Microsoft Security and Governance Consultant

Infrastructure/Engineering Remote, United States


Description

Please note: This position is for US based candidates only. There is no sponsorship for this position.

We are seeking an experienced Microsoft Security & Governance Consultant to lead the security work stream for a Microsoft 365 Copilot adoption initiative. This individual will provide strategic and hands-on guidance across data protection, information governance, identity security, Copilot readiness, AI governance, and Microsoft Purview. The consultant will work closely with Security, Compliance, Infrastructure, and Modern Workplace teams to ensure AI adoption aligns with enterprise security requirements, regulatory obligations, and risk management objectives.

Key Responsibilities

Copilot Security & Readiness

  • Assess Microsoft 365 environment readiness for Copilot deployment.
  • Evaluate data exposure risks, oversharing concerns, and permissions posture.
  • Develop recommendations for secure Copilot implementation.
  • Establish AI governance frameworks, guardrails, and usage policies.
  • Define monitoring and reporting requirements for Copilot activity and risk management.
  • AI firewalls and other security tasks review.

Microsoft Purview & Data Protection

  • Review and optimize Purview configurations.
  • Assess sensitivity labeling, DLP, retention, and records management controls.
  • Define data protection strategies for regulated and sensitive content.
  • Support security logging, auditing, and compliance reporting requirements.
  • Recommend control enhancements to reduce risk of inappropriate content exposure. AI Governance & Compliance
  • Define governance roles and responsibilities for Copilot and AI initiatives.
  • Develop approval processes, usage standards, and risk management procedures.
  • Align AI security controls with enterprise compliance requirements.
  • Establish responsible AI practices and prompt governance guidelines.
  • Partner with stakeholders on retention, content lifecycle, and information management policies.

Identity & Endpoint Security

  • Evaluate Microsoft Entra ID governance and Conditional Access strategies.
  • Review device compliance and Intune management controls.
  • Assess BYOD and mobile access considerations for Copilot.
  • Recommend identity protection and access control improvements.
  • Support integration of security controls across Microsoft security platforms.

Security Operations Collaboration

  • Work with Security Operations and Incident Management teams.
  • Review logging, audit, and monitoring requirements.
  • Advise on integration of Copilot-related security events into existing security monitoring platforms.
  • Support operationalization of new security controls and processes.

Required Experience

  • 7+ years in Microsoft Security, Compliance, or Governance consulting.
  • Deep expertise with:
    • Microsoft Purview
    • Microsoft Entra ID
    • Microsoft Intune
    • Microsoft Defender Suite
    • Microsoft 365 Security & Compliance
    • Microsoft 365 Copilot Governance
  • Experience in highly regulated environments such as financial services, insurance, healthcare, or government.
  • Strong understanding of information protection, DLP, retention, records management, and AI governance.
  • Experience conducting security assessments and developing remediation roadmaps. Preferred Qualifications
  • Microsoft Security certifications (SC-100, SC-200, SC-300, SC-400).
  • Experience with AI governance and secure AI adoption programs.
  • Familiarity with Microsoft SharePoint Advanced Management.
  • Experience leading security workshops and executive stakeholder discussions.
  • Understanding of enterprise security modernization programs and E5/E7 value realization initiatives. Ideal Consultant Profile