NewRef: a0GP900000JZaaL.1_1786978562

Microsoft Security Consultant (contract)

England, London

  • £450 to £450 GBP
  • Associate Role
  • Skills: Copilot said: Microsoft Defender, Microsoft Purview, Data Loss Prevention, Microsoft 365 Security, Microsoft Entra ID, Defender for Endpoint, Defender for Office 365, Information Protection, Records Management, GDPR Compliance
  • Level: Mid-level

Job description

Microsoft Security Consultant (contract)

a0GP900000JZaaL.1_1786978562

Microsoft Security & Compliance Consultant

3-Month Rolling Contract
£450/day | Outside IR35
London Hybrid (3 Days Per Week)

We're supporting a specialist consultancy engaged on a major Microsoft 365 security and compliance programme for one of its clients. They're looking for an experienced Microsoft Security & Compliance Consultant to lead the assessment, design, and implementation of security monitoring, data protection, and information governance controls across the Microsoft ecosystem.

This is a hands-on consulting engagement requiring strong technical expertise across Microsoft Defender and Microsoft Purview, coupled with the ability to engage stakeholders, provide strategic recommendations, and deliver practical improvements.

The Role

You'll work closely with technical and business stakeholders to evaluate the current Microsoft security estate, identify gaps and risks, and design a roadmap for improving detection, response, data protection, and information lifecycle management.

The engagement will focus on three key areas:

Security Monitoring & Threat Detection

* Review and assess the deployment of Microsoft Defender technologies across the organisation.
* Benchmark existing security configurations against Microsoft best practices and recognised industry standards.
* Evaluate alert quality, incident response processes, and overall monitoring effectiveness.
* Identify gaps in detection capability and security visibility.
* Assess coverage against MITRE ATT&CK techniques and tactics.
* Produce a prioritised remediation roadmap, balancing risk, effort, and business impact.
* Design alerting, escalation, and operational response processes.

Data Loss Prevention & Information Protection

* Assess how sensitive information is created, shared, stored, and transferred across the organisation.
* Define an information classification and sensitivity labelling framework.
* Design and implement Microsoft Purview DLP controls across Microsoft 365 services and endpoints.
* Develop a phased deployment approach, including simulation, testing, tuning, and enforcement.
* Establish exception management and governance processes.
* Integrate DLP monitoring and incidents into wider security operations.

Retention, Governance & Compliance

* Review retention obligations and compliance requirements across Microsoft 365 workloads.
* Translate regulatory and business requirements into implementable Purview controls.
* Design retention policies, retention labels, and automated policy application.
* Support GDPR-related processes, including data access and data deletion workflows.
* Develop operational procedures and governance documentation.
* Ensure appropriate auditability and evidencing of policy operation.

Required Experience

* Extensive Microsoft 365 Security and Compliance experience.
* Strong hands-on Microsoft Defender expertise, including Endpoint, Identity, Office 365, Cloud Apps, and associated security controls.
* Microsoft Purview Information Protection and Data Loss Prevention.
* Purview Records Management and Retention.
* Microsoft Entra ID and identity security controls.
* Security Operations, alert management, and incident response.
* MITRE ATT&CK framework experience.
* Strong understanding of GDPR, information governance, and compliance requirements.
* Experience delivering security and compliance programmes within enterprise Microsoft environments.
* Previous consultancy or client-facing delivery experience.

Desirable

* Microsoft Security certifications (SC-200, SC-300, SC-400, MS-102 or equivalent).
* Azure security experience.
* Experience working within regulated industries.
* Previous delivery of large-scale DLP, governance, or compliance transformation programmes.

What's Important

This role would suit a consultant who combines strong technical delivery capability with the ability to assess complex environments, engage senior stakeholders, and provide clear, pragmatic recommendations that improve both security posture and regulatory compliance.

3-Month Rolling Contract | Outside IR35 | £450/day | London Hybrid (3 Days Per Week)