IT Administrator (Google Workspace & Rippling)
About Us
Concierge Auctions sells the world's finest art, automobiles, antiques, and luxury real estate at auction. Our expert team curates premier properties, connects them with global buyers, and facilitates seamless, market-driven transactions. Since 2008, we have closed over $5B in luxury properties, with typical sales ranging from $2.5M to $30M, and lead the $20M-plus market. Operating in 46 U.S. states and 38 countries, we maintain a database of nearly 1 billion global contacts. Majority-owned by Sotheby’s and Compass (NYSE: COMP), Concierge Auctions operates independently, partnering with top real estate agents to host luxury property auctions.
About the Role
We are hiring an IT Administrator to manage the day-to-day administration of our core internal systems, primarily Google Workspace and Rippling. This role serves as the first point of contact for employee technology needs—accounts, devices, access, and troubleshooting—ensuring smooth and secure onboarding and offboarding. Beyond daily operations, you will partner on a strategic initiative: building a unified access control layer across all Concierge Auctions systems. This includes inventorying applications, defining role-based access standards, consolidating identity and provisioning, and automating access management. This hands-on, execution-focused role is ideal for someone with 1-3 years of IT support or systems administration experience who wants ownership of a modern, cloud-first stack and exposure to identity and access management (IAM) architecture.
Responsibilities
- Google Workspace administration
- Manage users, groups, organizational units, and aliases in the Google Admin console
- Administer Gmail, Drive, shared drives, Calendar, Meet, and Groups settings
- Enforce security policies: 2-step verification, app access controls, third-party OAuth review, and device management
- Monitor admin audit and login reports; investigate suspicious activity and respond to phishing reports
- Manage license assignment and storage usage; handle data retention, exports, and account transfers on departures
- Rippling administration
- Maintain employee records, org structure, and role-based permissions in Rippling
- Build and run onboarding and offboarding workflows, including app provisioning and de-provisioning
- Administer app management and SSO connections for third-party tools
- Support device inventory, enrollment, and MDM policies through Rippling
- Partner with HR and Finance on employee lifecycle changes, reporting, and app spend visibility
- Access control layer (major initiative)
This role will dedicate 30-40% of time to designing, building, and operating a company-wide access control layer. Responsibilities include:
- Build and maintain a complete inventory of applications, systems, and data stores, including owners, sensitivity, and current access methods
- Define a role-based access control (RBAC) model mapping job roles and departments to standardized permission sets
- Consolidate authentication behind SSO where possible; document exceptions and plan remediation for non-integrated systems
- Implement automated provisioning and de-provisioning to align access with the employee lifecycle (hire, transfer, promote, depart)
- Build recurring access review workflows and produce evidence of completion
- Instrument logging and alerting for privileged access, permission changes, and anomalous sign-ins
- Document access policies, request and approval paths, and break-glass procedures in Notion
- Track and report on progress: systems covered, percentage behind SSO, orphaned accounts closed, and average time to provision/de-provision
- End-user support and IT operations
- Serve as first-line support for hardware, software, account, and access requests
- Track, prioritize, and resolve tickets within agreed response targets; escalate when needed
- Prepare, image, ship, and recover laptops and peripherals for a distributed workforce
- Maintain accurate asset inventory and license records
- Write and maintain internal documentation, how-to guides, and IT onboarding materials in Notion
- Support conference room A/V, VPN, printers, and other office technology as needed
- Security and compliance
- Apply least-privilege access principles across all managed systems
- Run periodic access reviews and confirm timely removal of departed users
- Assist with security awareness reminders and incident response tasks
- Follow documented change and approval procedures for policy or permission changes
Requirements
- 1-3 years of experience in IT support, helpdesk, or systems administration
- Hands-on experience administering Google Workspace (users, groups, security settings, admin console)
- Experience with an HRIS or IT lifecycle platform — Rippling strongly preferred (Gusto, Justworks, BambooHR, or Okta/JumpCloud experience considered)
- Working knowledge of macOS and Windows support, plus basic networking (DNS, DHCP, VPN, Wi-Fi)
- Comfort with SaaS app administration, SSO, and role-based permission models
- Genuine interest in identity and access management, with patience for inventory, documentation, and cleanup work
- Clear written and verbal communication; ability to explain technical topics to non-technical staff
- Strong organizational habits, discretion with confidential data, and a bias toward documentation
Preferred Qualifications
- Google Workspace Administrator certification or CompTIA A+ / Network+
- Experience supporting a fully remote or hybrid workforce
- Familiarity with MDM tooling, endpoint security, or device compliance programs
- Basic scripting or automation experience (Apps Script, Python, or similar) and comfort with app APIs or SCIM provisioning
- Exposure to IAM tooling (Okta, JumpCloud, Entra ID) or SOC 2 / access review and audit processes
- Exposure to Slack, Zoom, Notion, Salesforce, or Atlassian administration
Success in the First 90 Days
- 30 days: Fully ramped on Google Workspace and Rippling configuration; handling routine tickets independently
- 60 days: Onboarding and offboarding checklists documented and running end-to-end without escalation; draft RBAC role-to-permission map in review
- 90 days: Completed a full access review, cleaned up license and asset inventory, published core IT documentation, and delivered a full application and access inventory as the foundation of the access control layer
Benefits
Employment type: Contract