Microsoft Purview & Security Architect — Contract
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 30, 2026
Role Overview
Spyglass Solutions seeks a senior, client-facing Microsoft Purview & Security Architect to lead assessments, workshops, pilots, implementations, and operationalization engagements across multiple client projects at any given time. This hands-on trusted advisor will translate business and regulatory needs into practical designs across Microsoft Purview, Entra ID, Microsoft Security, data governance, compliance, Copilot, and AI governance; configure and validate solutions; balance competing priorities and deadlines; and enable sustainable adoption with minimal oversight.
Key Responsibilities
• Lead discovery, stakeholder interviews, assessments, design workshops, whiteboarding, and implementation workstreams with executive, security, compliance, data governance, IT, and business teams.
• Design, configure, test, and optimize Microsoft Purview across Microsoft 365, endpoints, cloud, and structured data, including Information Protection, DLP, sensitivity labels, DSPM, Insider Risk, Communication Compliance, Records Management, eDiscovery, Retention, Compliance Manager, Sensitive Information Types, Exact Data Match, document fingerprinting, and trainable classifiers.
• Develop classification, labeling, retention, protection, and governance strategies aligned with business, privacy, regulatory, and security requirements. Establish testing, investigations, audit evidence, incident workflows, documentation, and ongoing tuning.
• Assess Microsoft 365 Copilot, Copilot Studio, Microsoft Foundry, enterprise AI applications, and custom or third-party agents. Define governance for prompts, outputs, grounding data, access, retention, monitoring, auditability, approvals, exceptions, escalation, change control, incident response, and retirement.
• Build enterprise data-governance operating models, including charters, policies, standards, decision rights, roadmaps, stewardship, councils, glossaries, data domains, metadata, lineage, quality, procedures, training, and knowledge transfer.
• Design Zero Trust and access-governance recommendations using Entra ID, Conditional Access, MFA, Identity Governance, Access Reviews, PIM, external identities, application consent, service principals, managed identities, and authentication methods. Align identity, device, application, endpoint, network, and data controls; integrate Purview with Defender, Sentinel, and Intune where in scope.
• Produce customer-ready architectures, findings, roadmaps, configuration guides, governance models, runbooks, test plans, training, and executive presentations. Lead pilots, MVPs, production deployments, validation, tuning, handoff, status reporting, risk management, and escalation.
Required Qualifications
• 5+ years of Microsoft security, compliance, identity, or data-governance experience, including substantial customer-facing consulting and independent professional-services delivery.
• Hands-on Microsoft Purview expertise across structured data, Information Protection, DLP, Records Management, Insider Risk, eDiscovery, Retention, and DSPM.
• Experience with data-governance operating models; Entra ID, Conditional Access, MFA, Identity Governance, Access Reviews, PIM, external identities, service principals, and managed identities; and governance of Microsoft 365 Copilot, Copilot Studio agents, enterprise AI, or custom AI solutions.
• Demonstrated ability to manage three or more concurrent client projects, balance competing priorities and deadlines, and communicate risks early. Candidates should be prepared to describe how they organized the work, what made their approach successful, and where they encountered challenges or needed to adjust.
• Ability to lead executive and technical workshops, configure and troubleshoot solutions, manage competing priorities, and deliver clear customer documentation in a remote, project-based environment.
Preferred Qualifications
Preferred certifications include SC-401, SC-300, SC-200, SC-100, and/or MS-102. Additional value includes Defender XDR, Defender for Cloud Apps or Endpoint, Sentinel, Intune, Microsoft Graph, PowerShell, KQL, governance Centers of Excellence, Responsible AI, secure development lifecycle and CI/CD governance, agent identities, MCP servers, APIs, models, tools, and AI supply-chain controls.
Typical Deliverables
Assessments and readiness findings; Purview implementations; Copilot and AI governance frameworks; agent lifecycle and identity-governance models; architectures, roadmaps, configuration guides, runbooks, and test plans; training and knowledge transfer; and pilot, production deployment, validation, tuning, handoff, and continuous-improvement recommendations.