If G-Suite is the SAML IDP then you can role map on the PCS using whatever attributes are returned in the assertion, similar to how you define the User Name template on the PCS SAML SP configuration (https://docs.pulsesecure.net/WebHelp/PCS/8.3R1/Home.htm#PCS/PCS_AdminGuide_8.3/Configuring_Connect_Secure_2.htm)