School Systems & Cloud Administrator
Province Hồ Chí Minh
Department Office
Report to Software Development Team Leader
Type Full time
Postion Vietnamese
Posted 15/12/2025

About Victoria School

Victoria School is proud to be the first school in Vietnam built and developed under UNESCO’s “Happy School” model. We believe that every child deserves to learn in a safe, joyful environment and have access to a world-class education. With a seamless 12-year educational pathway that integrates the best of both national and international curricula, we focus not only on academic excellence but also on holistic physical and emotional development—creating a truly happy experience for students, teachers, and parents alike.

 

We take pride in our team of highly qualified teachers and dedicated staff, supported by continuous training and professional development policies that empower each individual to achieve their career goals in a professional, collaborative, and inspiring environment. Joining the Victoria Education System is an opportunity to make a real difference—not only in the classroom but also in the community and the future of global education.

 

Working Location

📍Victoria School - Saigon South: 803A Nguyen Huu Tho, Nha Be, HCMC

 

About the Role

Own the reliability, security, and compliance of our Google Workspace for Education Plus tenant, AWS cloud services, key education platforms, and campus network. Lead identity & access, Google Classroom + SIS rostering, cloud security baselines, data governance/retention, endpoint and network controls, and strong documentation. Align all operations to academic cycles (Start of year SOY / End of year EOY) and Vietnam’s regulatory environment, while partnering with teaching/operations teams to keep learning tools fast, safe, and easy to use.

 

Key Responsibilities

A. Google Workspace for Education Plus

  • Own Admin Console posture: OUs, groups, delegated roles, least-privilege access, zero trust model.

  • Enforce security controls: 2-Step Verification, OAuth app governance, context-aware access.

  • Operate Security/Investigation Tool for threat hunting, incidents, and audit.

  • Manage Google Classroom lifecycle: automated rostering, co-teacher access, EOY archiving.

  • Govern data: Vault retention/holds/ediscovery; Drive sharing policies, labels/DLP, storage hygiene.

  • Chromebook integration.

B. AWS Cloud Administration

  • Operate a multi-account baseline (e.g., AWS Organizations/Control Tower or equivalent guardrails).

  • Implement identity federation (Google Workspace → AWS SSO/SCIM) and least-privilege IAM.

  • Enable centralized logging & findings: CloudTrail, Config, GuardDuty/Security Hub; drive remediation.

  • Protect data by design: S3 Block Public Access, encryption (KMS), AWS Backup policies.

  • Apply Well-Architected principles to reliability, cost, and performance; plan and review regions.

  • Automate where practical (CLI/Terraform/CDK), use tagging and budgets for cost visibility.

C. Education Platforms & SIS

  • Integrate SIS ↔ Google Classroom via OneRoster APIs/connectors.

  • Provide SSO (SAML/OIDC) and group-based access for LMS, assessment, and library systems.

  • Monitor vendor security posture; ensure student-data handling meets school policy and law.

  • Partner with academics to align platform settings to curriculum, assessment windows, and reporting.

D. Network & Identity Infrastructure

  • Maintain secure network design: VLAN segmentation, firewall/ACL hygiene, safe guest/student networks.

  • Engineer voice/video quality: QoS/DSCP for Google Meet, Zoom capacity and port readiness.

  • Enforce 802.1X/WPA3-Enterprise where feasible; manage VPN/SD-WAN, DNS/DHCP/IPAM.

  • Track asset/endpoint posture; support ChromeOS/mobile management standards.

E. Data Protection, Compliance & Continuity

  • Map retention and legal-hold needs in Vault and AWS Backup; test restores.

  • Manage incident response playbooks; drive phishing and data-loss exercises.

  • Build reporting: Admin SDK/Reports API, Meet quality, audit exports; AWS metrics/dashboards.

F. Operations, Documentation & Support

  • Own SOPs/runbooks for SOY/EOY, change control, onboarding/offboarding, and incident handling.

  • Deliver Tier-2/3 support and enablement for staff (safe sharing, phishing awareness).

  • Maintain architecture diagrams, risk registers, access reviews, and post-incident reports.

  • Deployment of new schools or renovations of existing schools infrastructure.

Required Qualifications

  • Certifications:

    • Associate Google Workspace Administrator (or obtained within 6 months)

    • AWS Associate (Solutions Architect or SysOps; or within 6 months)

  • Hands-on administration of:

    • Admin Console, Security/Investigation Tool, Vault; Classroom + SIS rostering;

    • AWS IAM/SSO, CloudTrail/Config, GuardDuty/Security Hub, S3/KMS/Backup

  • Networking: L2/L3 fundamentals, firewall policy design, QoS for Meet, 802.1X

  • Process discipline: Evidence of SOY/EOY playbooks, change management, and recoverability tests

  • Data protection: Practical understanding of student-data handling and cross-border considerations

  • Language: Vietnamese fluency; professional English for documentation and vendor collaboration (written and spoken)

Salary & Benefits

  • Salary: Negotiable (based on qualifications, skills, and experience).
  • Insurance: Social insurance, health insurance, and other benefits in accordance with state regulations.
  • Health insurance: Additional healthcare coverage as per school policy.
  • Leave: Public holidays and other leave entitlements according to school policy.
  • Welfare: Birthday gifts, welcome gifts, participation in parties, company trips, and team-building activities.
  • Lunch: Provided by the school.
  • Scholarships: Tuition discounts for children/relatives enrolled in the Victoria School system.
  • Training: Sponsored training programs and workshops conducted by internal and external experts.
  • Career path: Clear opportunities for professional growth and promotion.