We are looking for an experienced ICT Architect (Expert) with strong SharePoint and Microsoft 365 expertise to support the development of a secure, sustainable and NIS2-compliant rights and access management framework within a Microsoft 365 environment.
The architect will be responsible for developing the M365 architecture, defining the governance structure, establishing practical technical processes and providing standardised agreements and templates. The role requires strong architectural expertise combined with hands‑on knowledge of SharePoint, Microsoft 365, information management, security and enterprise content management.
The successful candidate must be native-level Dutch-speaking, CEFR C2.
Key Responsibilities
- Develop the Microsoft 365 architecture and establish a sustainable rights and access management framework.
- Design the governance structure for Microsoft 365 rights management.
- Define standard agreements, procedures and templates.
- Establish the technical and practical follow‑up processes for rights and access management.
- Ensure the architecture remains sustainable and can accommodate frequent Microsoft updates.
- Develop dashboarding and monitoring capabilities for ICT and Information Management.
- Establish a NIS2‑compliant division of responsibilities, including a functional administrator role for Information Management and a technical administrator role for the Service Desk.
SharePoint / Document Management System
- Design the rights management framework for SharePoint in compliance with NIS2.
- Establish a clear distinction between confidential and non‑confidential document libraries based on the organisation's internal data classification.
- Define the role and responsibilities of the designated contact person for each SharePoint site.
- Establish responsibilities for rights management, library structure, page and navigation management, metadata and site configuration changes.
- Develop a procedure for granting access to the SharePoint DMS through the central ICT access management process.
- Develop a user framework that complies with NIS2 requirements.
- Establish a monitoring system for rights management and related procedures.
- Fully document the solution so that the internal Service Desk can maintain the SharePoint rights management system independently.
Document Sharing
- Design a NIS2‑compliant solution for internal document sharing at document level.
- Design a NIS2‑compliant solution for sharing documents with external partners.
- Account for external partners who do not have a Microsoft 365 account.
- Provide an alternative for transferring large volumes of documents, such as through WeTransfer.
- Ensure the solution is developed within the existing Microsoft 365 licensing framework.
- If OneDrive is proposed, clearly distinguish between personal OneDrive usage and the document‑sharing environment and prevent unintended sharing of users' complete personal OneDrive environments.
- Develop user guidelines and monitoring procedures.
- Document the technical and organisational setup so the internal Service Desk can maintain the solution.
Microsoft Teams
- Design a NIS2‑compliant rights and access management framework for Microsoft Teams collaboration with internal and external partners.
- Account for external partners without Microsoft 365 accounts.
- Define the responsibilities of the designated contact person for each Teams site, including rights management, private channels and the underlying SharePoint site.
- Establish a controlled procedure for granting access to Teams sites through the central ICT access management process.
- Develop NIS2‑compliant user guidelines.
- Document the technical and organisational setup to enable future internal management, evaluation and adaptation.
Security & Access Management
The architecture must support the organisation's policy objectives, including:
- Preventing unauthorised access to information, applications, infrastructure and services.
- Ensuring that every identity and assigned access can be clearly identified and justified.
- Applying least‑privilege access based on the user's role or assignment.
- Preventing accumulation of access rights following role changes.
- Timely revocation of access when an assignment ends or access is no longer required.
- Applying stricter protection to privileged and administrative access.
- Managing and monitoring access by suppliers and external partners separately.
- Logging and monitoring access changes, authentication and elevated privileges.
- Periodically reviewing whether access rights remain necessary and appropriate.
- Maintaining an auditable trail for material access decisions.
- Formally recording, risk‑assessing and time‑limiting exceptions.
- Measuring the effectiveness of the process and reporting periodically to management.
Required Skills & Experience
Must‑Have Requirements
- At least 8 years of demonstrable experience as a specialist architect in a specific domain such as networking, security, server infrastructure, application architecture, ERP, ECM platforms, Data Warehouse/BI, or as an Enterprise Architect.
- Demonstrable knowledge and experience with modelling techniques, including ArchiMate, TOGAF, UML and/or Sparx Enterprise Architect.
- Dutch language proficiency at CEFR C2 level.
Preferred / Should‑Have Experience
- At least 8 years of experience as a SharePoint Specialist.
- Experience implementing Microsoft 365 environments and supporting their rollout and ongoing management.
- Experience in Information Security, for example IS governance, cybersecurity implementation plans and defining risk appetite.
- Experience with NIS2.
- Knowledge and experience of business processes.
- Knowledge and experience of Project Management disciplines, including costs, timing, coordination, planning and estimations.
- Broad knowledge across different architectural domains, combined with proven specialist expertise in at least one domain such as infrastructure, application, security, data or processes.
- Knowledge and experience with an Enterprise Content Management (ECM) system, such as SharePoint or Documentum, and its application to business solutions.
- Experience establishing rights and access management within Microsoft 365.
Project Context
The organisation is moving towards an Microsoft E5 licensing model, with E5 licences and a limited number of E7 licences for office employees. Microsoft Purview will be implemented for, among other things, security labels and retention.
The organisation also has Copilot licences. The rights management framework must therefore ensure that Copilot cannot bypass established access rights, that its scope is clearly defined and that the solution complies with NIS2 requirements.
The organisation's existing intranet is built on SharePoint and must be taken into account when designing the rights management architecture.