The Senior Associate will manage and strengthen the organization’s information-security posture, Google Workspace environment, endpoints, and core IT infrastructure. The role will lead the migration from Microsoft 365 to Google Workspace and support secure, reliable day-to-day technology operations, compliance activities, incident response, and infrastructure improvements.
Key Responsibilities:
1. Microsoft 365 to Google Workspace Migration
- Plan and execute the migration of email, calendars, contacts, files, shared drives, user accounts, groups, permissions, and related services from Microsoft 365 to Google Workspace.
- Prepare migration plans, user mapping, data validation, rollback and cutover procedures while ensuring data integrity, security, compliance, and minimal business disruption.
- Coordinate with internal stakeholders and implementation partners; provide post-migration support, issue resolution, user guidance, and controlled decommissioning of redundant Microsoft services.
2. Google Workspace Administration & Security
- Administer users, organizational units, groups, domains, shared drives, licences, administrative roles, Gmail, Drive, Calendar, Meet, Groups, and Google Vault.
- Configure MFA, SSO, access controls, external-sharing restrictions, retention policies, email protection, security alerts, investigation rules, audit logging, eDiscovery, and legal holds.
- Perform periodic reviews of privileged access, inactive accounts, external sharing, security settings, and service health; resolve escalated administration, access, and email-delivery issues.
- Manage the lifecycle of Windows, macOS, Android, and iOS devices, including enrolment, configuration, patching, application deployment, inventory, compliance monitoring, and secure decommissioning.
- Operate MDM/UEM, EDR, antivirus, anti-malware, firewall, disk-encryption, device-control, and endpoint-compliance solutions; define secure configuration baselines for corporate and BYOD devices.
- Maintain endpoint and asset records and establish secure device processes for employee onboarding, role changes, offboarding, data removal, and warranty or lifecycle management.
4. Security Operations, DLP & Incident Response
- Conduct security-posture assessments, review policies and configurations, track identified risks and remediation actions and implement practical enhancements with internal teams and security partners.
- Implement and manage DLP controls across email, web, cloud applications, and endpoints; investigate alerts and refine rules to protect sensitive information while minimizing false positives.
- Manage escalated security incidents, including phishing, compromised accounts, malware, endpoint isolation, and suspected data leakage; document root cause, corrective actions, and lessons learned.
5. VAPT, ISO 27001 & Compliance
- Coordinate VAPT scope, access, schedules, rules of engagement, evidence, remediation, retesting, and closure with internal stakeholders and external vendors.
- Maintain vulnerability registers and support ongoing remediation across endpoints, networks, servers, cloud platforms, and applications.
- Support ISO 27001, internal, customer, and regulatory audits by coordinating evidence, control testing, risk assessments, non-conformities, corrective actions, and compliance documentation.
- Support secure and reliable office networks, internet connectivity, servers, storage, backups, recovery readiness, and related infrastructure upgrades or office migrations.
- Evaluate VDI and other secure-access solutions for remote work and BYOD, covering identity, data protection, device isolation, performance, scalability, and user experience.
- Coordinate service providers and technology vendors for evaluation, procurement, implementation, maintenance, escalations, and proofs of concept.
7. Operations, Documentation & Collaboration
- Resolve escalated IT infrastructure and information security issues and collaborate with business teams, management, auditors, and vendors on technical and security requirements.
- Maintain policies, SOPs, infrastructure diagrams, inventories, configuration records, troubleshooting guides, handover documents, licences, and operational reports.
- Evaluate new technologies and recommend solutions that improve security, scalability, reliability, operational efficiency, and user experience.
Required Skills & Experience:
- Over 4 Years + Hands-on experience in information security, IT infrastructure, endpoint administration, or a comparable role
- Strong Google Workspace administration and security expertise, including Admin Console, Gmail, Drive, Shared Drives, Vault, endpoint management, access controls, and audit capabilities.
- Experience with Microsoft 365-to-Google Workspace migrations and working knowledge of Microsoft 365, Entra ID, and Microsoft security controls.
- Practical knowledge of MDM/UEM, EDR, patching, device compliance, IAM, MFA, SSO, RBAC, DLP, incident response, VAPT, vulnerability management, and ISO 27001.
- Working understanding of networks, firewalls, VPNs, servers, storage, backups, cloud services, and business-continuity requirements.
- Strong troubleshooting, documentation, stakeholder-management, vendor-coordination, and project-execution skills.
Preferred Qualifications
- Bachelor’s degree in information technology, Computer Science, Cybersecurity, or a related discipline.
- Google Workspace Administrator, Google Cloud, ISO 27001, Security+, CEH, CISM, CISSP, or similar certification is advantageous but not mandatory.
Key Competencies Ownership and accountability
- Security-first thinking
- Structured problem-solving
- Cross-functional collaboration
- Attention to detail
- Ability to manage multiple priorities and escalations