
Azure Security & Governance Engineer – Microsoft AI Platform
WGA Consulting, LLC
Job description
About WGA Advisors
WGA Advisors is a global management consulting firm and a world-class alternative to the big-name consulting firms. We help senior leaders make and execute the decisions that matter most across AI and digital transformation strategy, ESG, growth, culture, operations, and enterprise transformation.
Our firm focuses on areas of senior management concern, creating enduring value and delivering measurable impact at the intersection of strategy, technology, and operating model design. WGA’s AI Workforce Solutions practice is at the forefront of helping global enterprises move from isolated AI experimentation to scaled, business-led agentic AI deployment.
The Opportunity
WGA Advisors is engaging an Azure Security & Governance Engineer – Microsoft AI Platform to hands-on design, configure, secure, test, and support the production deployment of an enterprise Microsoft AI Agent platform.
This is a high-impact execution role responsible for implementing the security, identity, governance, networking, data-protection, and monitoring controls surrounding a Microsoft AI environment built using Microsoft Foundry, Microsoft Copilot Studio, Microsoft Power Platform, Microsoft Purview, Microsoft Sentinel, Microsoft Entra ID, Azure Key Vault, and Presidio.
The Azure Security & Governance Engineer will work directly alongside WGA’s Microsoft Azure AI and Power Platform engineering resources, engagement leadership, and enterprise technology and security teams. The role is responsible for turning approved security architecture and governance requirements into configured, tested, documented, and production-ready Microsoft controls.
A major focus of the environment is the protection of personally identifiable information and sensitive enterprise data used by AI Agents. The architecture requires PII to be detected, tokenized or pseudonymized before applicable data is submitted to large language models, with tightly controlled re-identification where business processes require the original values.
This role therefore requires more than policy or security advisory experience. The successful candidate must be able to personally configure Azure and Microsoft security services, troubleshoot integrations, validate controls, and work alongside the AI engineering team through deployment.
This is a temporary project-based engagement structured around platform configuration, security implementation, integration testing, production readiness, deployment, and stabilization. Strong potential for extension based on performance and continued client demand across WGA’s AI Workforce Solutions pipeline.
Core Responsibilities
-
Azure security architecture and configuration
-
Configure the Azure security architecture supporting enterprise AI Agents, Microsoft Foundry, Copilot Studio, Power Platform, and related Azure services
-
Implement security controls against accepted architecture and production-readiness requirements
-
Configure secure service-to-service communication between AI platform components
-
Establish least-privilege access patterns across development, test, and production environments
-
Configure Azure subscriptions, resource groups, policies, roles, and security boundaries as required by the approved architecture
-
Review and remediate inappropriate public exposure of Azure resources
-
Configure Azure security controls protecting AI workloads, APIs, data services, tokenization services, and application components
-
Support environment separation and controlled promotion between development, test, and production
-
Implement production security configurations in accordance with enterprise change-control requirements
-
Document configurations so the environment can be transitioned cleanly to enterprise ownership
Microsoft Entra ID and identity security
-
Configure Microsoft Entra ID identity and access controls supporting users, applications, AI Agents, workflows, and Azure services
-
Configure managed identities and service principals wherever appropriate in place of embedded credentials
-
Configure application registrations, authentication flows, API permissions, and service-to-service access
-
Establish Azure RBAC and other authorization controls using least-privilege principles
-
Configure developer, administrator, production-support, application, and service access roles
-
Support Conditional Access and related identity-security requirements where applicable
-
Validate privileged access and eliminate unnecessary persistent administrative privileges
-
Troubleshoot authentication, authorization, token, and managed-identity issues across integrated Microsoft services
-
Support controlled access between Copilot Studio, Foundry, Azure-hosted services, APIs, and enterprise data platforms
Azure networking and private connectivity
-
Design and configure secure Azure network connectivity supporting the AI platform
-
Configure Azure Virtual Networks and appropriate network segmentation
-
Configure Private Link and private endpoints for supported Azure services
-
Restrict public network access where required by the target security architecture
-
Configure Network Security Groups and related Azure network controls
-
Establish secure communication between application, data, AI, and security services
-
Review outbound connectivity and reduce unnecessary public egress
-
Validate DNS, private endpoint, routing, firewall, and connectivity configurations
-
Work with enterprise network teams to resolve cross-environment connectivity requirements
-
Perform network-security validation before production deployment
Azure Key Vault, secrets, and cryptographic controls
-
Configure Azure Key Vault for centralized protection of secrets, keys, certificates, and sensitive application configuration
-
Configure Key Vault RBAC and access controls
-
Integrate Azure services with Key Vault using managed identities wherever technically appropriate
-
Ensure credentials, API keys, certificates, and encryption keys are not hard-coded into applications, workflows, agents, or configuration files
-
Establish key and secret rotation practices
-
Support encryption requirements associated with sensitive information and PII protection
-
Protect keys and mapping information used for tokenization, pseudonymization, and controlled re-identification
-
Validate that AI Agents and LLM services cannot access protected token mappings or re-identification capabilities unless explicitly authorized
Microsoft Purview configuration and data governance
-
Configure Microsoft Purview controls supporting enterprise AI and agentic workflows
-
Configure and validate sensitive information classifications relevant to the AI environment
-
Configure appropriate Data Loss Prevention policies and controls
-
Establish information-protection and data-handling rules applicable to AI Agents and connected business processes
-
Configure auditing and governance controls supporting AI activity
-
Review data movement through Copilot Studio, Foundry, Power Platform, APIs, and associated Azure services
-
Support creation or extension of custom Sensitive Information Types where business-specific identifiers or patterns require additional classification
-
Configure policies designed to prevent inappropriate movement or disclosure of sensitive information
-
Validate Purview controls using representative positive and negative test cases
-
Document governance rules and support transition to enterprise security and compliance teams
Microsoft Sentinel configuration and monitoring
-
Configure Microsoft Sentinel to provide centralized security monitoring for the AI environment
-
Connect appropriate Azure, Microsoft, identity, application, and security data sources
-
Establish security logging requirements across the AI platform
-
Configure analytics rules and alerting for relevant security events
-
Develop detection logic for suspicious authentication, authorization, administrative, and service activity
-
Monitor privileged access and material security configuration changes
-
Configure monitoring for abnormal application and service-to-service behavior
-
Configure workbooks, dashboards, and operational security views where required
-
Establish alerts supporting investigation of security events associated with production AI Agents
-
Validate that material AI platform security events are observable, traceable, and auditable
-
Support incident investigation and troubleshooting during production testing and stabilization
PII protection and AI security
-
Work alongside the Azure AI engineer to implement and validate a secure PII-protection architecture surrounding Microsoft Foundry and enterprise LLM processing
-
Secure Azure-hosted Presidio analyzer, anonymization, tokenization, and re-identification services
-
Validate that designated PII and sensitive information is removed, tokenized, masked, or pseudonymized before applicable content is submitted to an LLM
-
Establish access boundaries between raw information, tokenized information, AI-processing services, and re-identification capabilities
-
Protect token mappings and other sensitive re-identification data from access by LLM services
-
Configure cryptographic and Key Vault controls supporting reversible pseudonymization where required
-
Review application, API, security, and diagnostic logging to prevent inadvertent storage of unprotected PII
-
Validate security controls through positive and negative test cases
-
Ensure failure conditions do not inadvertently bypass the required PII-protection layer
-
Support secure deployment of Presidio containers or services within Azure
-
Review application architecture for potential paths that could allow unprotected sensitive information to reach an LLM
The primary Azure AI engineer will own agent and Presidio application development. This role owns the security architecture and enforcement controls surrounding those services.
AI platform production readiness
-
Perform security reviews of Microsoft Copilot Studio, Microsoft Foundry, Power Platform, Azure AI services, Presidio, Azure Container Apps or equivalent hosting services, Key Vault, storage, databases, APIs, and related platform components
-
Validate identity and permissions before production release
-
Validate private endpoint and network-security configurations
-
Validate secrets-management and encryption controls
-
Validate Purview policies and DLP behavior
-
Validate Sentinel logging, analytics, and alerts
-
Validate PII-processing and tokenization security boundaries
-
Review service principals, managed identities, application registrations, and administrative access
-
Confirm development, test, and production separation
-
Identify security defects, classify severity, and work directly with engineering resources to remediate them
-
Execute final production security validation and document outstanding risks or exceptions
-
Support production smoke testing and stabilization following deployment
Qualifications
Education
-
Bachelor’s degree required in a relevant discipline, including but not limited to Computer Science, Cybersecurity, Information Systems, Software Engineering, Engineering, Data Science, or a closely related technical field
-
Strong academic record from a recognized institution
-
Relevant Microsoft security, Azure, identity, or architecture certifications are a plus
Experience
-
10+ years of overall professional technology experience, with significant hands-on Azure security engineering experience
-
Demonstrated hands-on delivery of enterprise Microsoft Azure security environments
-
Experience configuring Azure security controls in production rather than solely providing architecture or governance recommendations
-
Strong practical experience with Microsoft Entra ID, Azure RBAC, managed identities, Azure Key Vault, Azure networking, and private connectivity
-
Demonstrated experience with Microsoft Purview and/or Microsoft Sentinel in enterprise environments
-
Experience securing Azure PaaS applications, APIs, data services, and distributed cloud architectures
-
Experience working directly with application and platform engineering teams through build, testing, remediation, and production deployment
-
Track record of client-facing delivery under structured acceptance criteria, change control, tight timelines, and enterprise security standards
-
Experience supporting large enterprise or tier-one consulting environments strongly preferred
Required Expert Skills
-
Hands-on configuration of Microsoft Entra ID, managed identities, service principals, application registrations, authentication, and Azure RBAC
-
Azure Virtual Networks, Private Link, private endpoints, Network Security Groups, routing, and secure PaaS connectivity
-
Azure Key Vault and secure management of application secrets, keys, certificates, and cryptographic material
-
Microsoft Purview information protection, sensitive information classification, DLP, governance, and audit capabilities
-
Microsoft Sentinel data connectors, analytics rules, alerting, monitoring, and security investigation
-
Securing Azure-hosted APIs, application services, containers, databases, storage, and AI services
-
Implementing least-privilege and Zero Trust security principles within Microsoft cloud environments
-
Diagnosing and resolving identity, authorization, connectivity, security-policy, and logging issues
-
Conducting technical security reviews and personally implementing identified remediation
Technical Fluency
-
Strong command of Azure security architecture and Microsoft cloud security controls
-
Working knowledge of Microsoft Foundry and enterprise generative AI architectures
-
Working knowledge of Microsoft Copilot Studio and Power Platform security models
-
Understanding of AI Agent architectures, tool invocation, API integration, and enterprise LLM deployment
-
Understanding of PII detection, anonymization, tokenization, masking, and pseudonymization concepts
-
Familiarity with Presidio or comparable PII-detection and anonymization frameworks preferred
-
Familiarity with Azure Container Apps, Kubernetes, App Service, or comparable container/application hosting
-
Familiarity with Azure API Management and secure API architecture
-
Understanding of encryption at rest, encryption in transit, cryptographic-key management, and secrets management
-
Understanding of security logging and the risk of sensitive information appearing in logs, traces, prompts, or diagnostic data
-
Familiarity with secure software-development and DevSecOps practices
-
Familiarity with the broader agentic AI landscape and enterprise AI-security considerations
Preferred Microsoft Certifications
Relevant certifications are preferred but are not a substitute for demonstrated hands-on delivery experience.
-
AB-100 - Agentic AI Business Solutions Architect Expert
-
AI-103 – Azure AI Apps and Agents Developer Associate
-
AB-620 – AI Agent Builder Associate
-
AB-410 – Intelligent Applications Builder Associate
-
SC-401 – Information Security Administrator Associate
-
SC-200 – Security Operations Analyst Associate
-
SC-300 – Identity and Access Administrator Associate
-
SC-500 – Cloud and AI Security Engineer Associate
Communication and Execution
-
Clear written and verbal communication, including the ability to explain security architecture and technical controls to both business and technical audiences
-
Ability to work closely with AI engineers, application developers, enterprise architects, security teams, and engagement leadership
-
Proven ability to deliver against a structured implementation schedule with iterative feedback, tight timelines, and high quality standards
-
Demonstrated ownership, follow-through, and ability to independently drive security workstreams to completion
-
Ability to distinguish material production security risks from theoretical or low-impact concerns
-
Strong troubleshooting skills and willingness to work directly within the environment rather than limiting involvement to architecture recommendations
-
Ability to document configuration decisions, security controls, testing results, and operating procedures to a standard suitable for enterprise transition
Engagement Details
-
Hourly Rate: $90–$120/hour, commensurate with experience and demonstrated Microsoft security expertise
-
Engagement Type: Temporary / Independent Contractor / Project-Based
-
Schedule: 40 hours week/6 month project
-
Duration: Project-based engagement spanning platform configuration, testing, deployment, and production stabilization, with potential for extension based on performance and continued client demand
-
Work Location: Remote; collaboration with WGA and client technology teams as required by the implementation and testing cadence
-
Travel: There will be a single 8-day trip to Singapore, travel is reimbursed per travel policy, travel to/from paid up to 8 hours per travel day.
-
Authorization: Must be based in the United States and currently authorized to work in the United States
This role is designed to work alongside WGA’s primary Microsoft Azure AI & Power Platform engineering resource. It is therefore particularly well suited to a senior Microsoft security engineer who can provide focused technical expertise during architecture, configuration, validation, and production deployment.
WGA Advisors is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard
Pay: $90.00 - $120.00 per hour
Benefits:
- Flexible schedule
Experience:
-
Microsoft Presidio: 3 years (Required)
-
Microsoft Foundry: 3 years (Required)
-
Microsoft Purview: 3 years (Required)
-
Azure Key Vault: 3 years (Required)
-
Microsoft Copilot Studio: 3 years (Required)
-
Microsoft Sentinel: 3 years (Required)
Language:
- English (Required)
Willingness to travel:
- 25% (Required)
Work Location: Remote