Microsoft 365 Copilot Security Subject Matter Expert (SME)

Potomac Haven

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Potomac Haven seeks a Copilot SME to assess how Microsoft 365 Copilot on GCC accesses and processes organizational data, identifies security and governance risks, and ensures only authorized information surfaces to end users.

The role reviews Copilot's extensibility surface—agents, plugins, Graph connectors, and web grounding—and partners with identity and compliance SMEs to align findings with Zero Trust and DLP controls. Strong communication skills are essential.

Qualifications

  • 3+ years of hands-on experience with Microsoft 365 Copilot deployment on GCC, governance, or security assessment.
  • Working knowledge of Microsoft Graph and how it underlies Copilot's data access model.
  • Practical experience with Copilot extensibility: agents, plugins, Copilot Studio, and Graph connectors.
  • Familiarity with Microsoft Entra ID, Conditional Access, and Purview (DLP, sensitivity labels, DSPM for AI) as they relate to Copilot.
  • Understanding of Zero Trust principles as applied to AI/Copilot environments.
  • Experience with Microsoft 365 Government Community Cloud (GCC) a plus, including awareness of feature-parity gaps versus commercial tenants.
  • Strong written communication skills; able to translate technical findings for both administrators and executives.

Responsibilities

  • Assess how Copilot retrieves and summarizes content through Microsoft Graph, and identify where existing permissions could create unintended data exposure once Copilot is enabled.
  • Review Copilot tenant controls, including web search/web grounding behavior, AI DISCLAIMERS, responsible AI protections, and preview or in-development features.
  • Evaluate agent, plugin, and Graph connector governance — including who can create, install, approve, publish, and use them — to prevent unapproved extensions from expanding Copilot's access to sensitive content.
  • Identify third-party integrations and connectors that could broaden Copilot's reach beyond intended data boundaries.
  • Partner with identity, data governance, and compliance SMEs to validate that Copilot findings align with broader Zero Trust, DLP, and sensitivity-labeling controls.
  • Document findings in plain, business-readable language, with risk ratings and prioritized, actionable recommendations.
  • Support controlled, non-destructive validation testing of Copilot behavior using approved test accounts and synthetic data.
  • Stay current on Microsoft's evolving Copilot governance guidance (Microsoft Learn, Zero Trust for Copilot, Purview DSPM for AI) and translate updates into assessment practice.

Skills

Microsoft 365 Copilot deployment
Governance & security assessment
Microsoft Graph data access model
Copilot extensibility (agents, plugins
Zero Trust for AI/Copilot
Written communication

Tools

Graph connectors
Copilot Studio
Microsoft Entra ID
Conditional Access
Purview (DLP, sensitivity labels)
DSPM for AI

Job description

The Copilot SME assesses how Microsoft 365 Copilot on Government Community Cloud (GCC) accesses, retrieves, and processes organizational data, and identifies the security, governance, and extensibility risks that must be resolved before Copilot is rolled out to end users. This role evaluates Copilot's core behavior alongside its extensibility surface — agents, plugins, Microsoft Graph connectors, and web grounding — to ensure Copilot only surfaces information users are authorized to see.

Key Responsibilities
  • Assess how Copilot retrieves and summarizes content through Microsoft Graph, and identify where existing permissions could create unintended data exposure once Copilot is enabled.
  • Review Copilot tenant controls, including web search/web grounding behavior, AI DISCLAIMERS, responsible AI protections, and preview or in-development features.
  • Evaluate agent, plugin, and Graph connector governance — including who can create, install, approve, publish, and use them — to prevent unapproved extensions from expanding Copilot's access to sensitive content.
  • Identify third-party integrations and connectors that could broaden Copilot's reach beyond intended data boundaries.
  • Partner with identity, data governance, and compliance SMEs to validate that Copilot findings align with broader Zero Trust, DLP, and sensitivity-labeling controls.
  • Document findings in plain, business-readable language, with risk ratings and prioritized, actionable recommendations.
  • Support controlled, non-destructive validation testing of Copilot behavior using approved test accounts and synthetic data.
  • Stay current on Microsoft's evolving Copilot governance guidance (Microsoft Learn, Zero Trust for Copilot, Purview DSPM for AI) and translate updates into assessment practice.
Job Requirements and Qualifications
  • 3+ years of hands-on experience with Microsoft 365 Copilot deployment on GCC, governance, or security assessment.
  • Working knowledge of Microsoft Graph and how it underlies Copilot's data access model.
  • Practical experience with Copilot extensibility: agents, plugins, Copilot Studio, and Graph connectors.
  • Familiarity with Microsoft Entra ID, Conditional Access, and Microsoft Purview (DLP, sensitivity labels, DSPM for AI) as they relate to Copilot.
  • Understanding of Zero Trust principles as applied to AI/Copilot environments.
  • Experience with Microsoft 365 Government Community Cloud (GCC) a plus, including awareness of feature-parity gaps versus commercial tenants.
  • Strong written communication skills; able to translate technical findings for both administrators and executives.
Certifications Preferred
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
  • Microsoft Certified: Information Protection and Compliance Administrator Associate (SC-400) or Administrator (SC-401)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft 365 Certified: Copilot-related credentials (e.g., Copilot for Microsoft 365 certification, when applicable)
  • CISSP or equivalent security certification (preferred)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Copilot Security & Governance Expert (GCC)
Copilot Security & Governance Expert (GCC)

Potomac Haven • Washington

On-site
USD 120,000 - 170,000
M365 Copilot Advanced Solutions Architect
M365 Copilot Advanced Solutions Architect

Kroger Family of Companies • Blue Ash (OH)

On-site
USD 150,000 - 210,000
Microsoft 365 Copilot AI Platform Administrator
Microsoft 365 Copilot AI Platform Administrator

duvari group • St. Louis (MO)

Hybrid
USD 90,000 - 130,000
Sr MS365 Engineer - Copilot & Power Platform Operations
Sr MS365 Engineer - Copilot & Power Platform Operations

Lockton • Kansas City (MO)

On-site
USD 120,000 - 180,000
Systems Engineer - MS 365/Copilot 5582
Systems Engineer - MS 365/Copilot 5582

Tier4 Group • Milwaukee (WI)

On-site
USD 90,000 - 120,000
Competitive Rates
Benefits
free daily lunch when onsite
Collaboration & Productivity Engineer - Copilot - Microsoft 365
Collaboration & Productivity Engineer - Copilot - Microsoft 365

Request Technology, LLC • Houston (TX)

Hybrid
USD 90,000 - 130,000
M365 Power Platform Admin - Copilot (Onsite in Boston)
M365 Power Platform Admin - Copilot (Onsite in Boston)

Confidential Company • Boston (MA)

On-site
USD 140,000 - 190,000
Microsoft 365 Copilot Administrator
Microsoft 365 Copilot Administrator

Grove Technical Resources, INC • Massachusetts

Hybrid
USD 90,000 - 120,000
Microsoft 365 Copilot Administrator
Microsoft 365 Copilot Administrator

GTS Technology Solutions • Austin (TX)

On-site
USD 90,000 - 96,000
Copilot Solutions Engineer
Copilot Solutions Engineer

Planet Technologies • Washington

On-site
USD 150,000 - 190,000