The Copilot SME assesses how Microsoft 365 Copilot on Government Community Cloud (GCC) accesses, retrieves, and processes organizational data, and identifies the security, governance, and extensibility risks that must be resolved before Copilot is rolled out to end users. This role evaluates Copilot's core behavior alongside its extensibility surface — agents, plugins, Microsoft Graph connectors, and web grounding — to ensure Copilot only surfaces information users are authorized to see.
Key Responsibilities
- Assess how Copilot retrieves and summarizes content through Microsoft Graph, and identify where existing permissions could create unintended data exposure once Copilot is enabled.
- Review Copilot tenant controls, including web search/web grounding behavior, AI DISCLAIMERS, responsible AI protections, and preview or in-development features.
- Evaluate agent, plugin, and Graph connector governance — including who can create, install, approve, publish, and use them — to prevent unapproved extensions from expanding Copilot's access to sensitive content.
- Identify third-party integrations and connectors that could broaden Copilot's reach beyond intended data boundaries.
- Partner with identity, data governance, and compliance SMEs to validate that Copilot findings align with broader Zero Trust, DLP, and sensitivity-labeling controls.
- Document findings in plain, business-readable language, with risk ratings and prioritized, actionable recommendations.
- Support controlled, non-destructive validation testing of Copilot behavior using approved test accounts and synthetic data.
- Stay current on Microsoft's evolving Copilot governance guidance (Microsoft Learn, Zero Trust for Copilot, Purview DSPM for AI) and translate updates into assessment practice.
Job Requirements and Qualifications
- 3+ years of hands-on experience with Microsoft 365 Copilot deployment on GCC, governance, or security assessment.
- Working knowledge of Microsoft Graph and how it underlies Copilot's data access model.
- Practical experience with Copilot extensibility: agents, plugins, Copilot Studio, and Graph connectors.
- Familiarity with Microsoft Entra ID, Conditional Access, and Microsoft Purview (DLP, sensitivity labels, DSPM for AI) as they relate to Copilot.
- Understanding of Zero Trust principles as applied to AI/Copilot environments.
- Experience with Microsoft 365 Government Community Cloud (GCC) a plus, including awareness of feature-parity gaps versus commercial tenants.
- Strong written communication skills; able to translate technical findings for both administrators and executives.
Certifications Preferred
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
- Microsoft Certified: Information Protection and Compliance Administrator Associate (SC-400) or Administrator (SC-401)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft 365 Certified: Copilot-related credentials (e.g., Copilot for Microsoft 365 certification, when applicable)
- CISSP or equivalent security certification (preferred)