AI Governance Architect Microsoft Agent 365
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- Microsoft Agent 365
- Power Platform admin
- Microsoft Entra
Summary
AI Governance Architect Microsoft Agent 365
Exp: 13+
The engagement
OrionTek is building a hands-on delivery team for a multinational financial services client that operates in a federally regulated environment. The client is moving from proofs of concept to production AI: scaling supervised machine learning on Snowflake across several countries, and establishing enterprise-wide governance and administration of AI agents on the Microsoft platform (Agent 365, Copilot Studio, Microsoft Foundry).
The team is organized in three streams Snowflake ML, AI Governance on Microsoft Agent 365, and Governed Agent Development each staffed with one lead and one senior engineer. This is a continuing, time-and-materials engagement: the team onboards together, establishes the facts in the client's environment, sets direction, and ships the first working piece in each stream inside the first 30 days, then continues on the roadmap.
The client has been explicit about the profile: hands-on architects and engineers who know the right way, lead the work, and execute without waiting for a task list. Advisory-only profiles will not be considered. Every candidate is named to the client, interviewed by the client, and demonstrates live before starting.
The client's operations are subject to federal regulation, including federal reporting obligations on financial transactions, audit and record-keeping controls, service-level commitments, and contractual restrictions on the use of customer data for AI training. Candidates with experience delivering technology in federally regulated environments are strongly preferred.
The role
You own the AI Governance stream: the operating model and hands-on administration that gives the client an AI control tower one reconciled register of every agent in the estate with owners and tiers, an intake and approval path, a real-time cost view, and a drilled suspension path per plane. The client has standardized on Microsoft as its authorized generative-AI platform; Agent 365 administration sits outside its outsourcing partner's scope, and executives are building agents in Copilot Studio today with Microsoft Foundry held closed until controls exist. You build from exports first, then operate hands-on in the roles the client grants, and you set the criteria for opening further platforms. You lead one Senior Agent 365 & Security Engineer from day one.
What you will do
- Reconcile the estate into one register: Microsoft 365 admin center agent registry, Power Platform admin center (environments, Copilot Studio agents, credit reports), Entra agent identities, Azure Resource Graph for Foundry, Defender and Purview exports, and any integration-layer agent registry with owners, provisional tiers and an exception list.
- Define and issue the governance controls: agent definition and tiering standard, authorized-use statement, inventory reconciliation, intake and approval workflow; write the build requirements agents must meet before they are published.
- Establish real-time cost and consumption governance: credit view by environment first, per-agent credit limits through intake; define who may spend what, where.
- Design the suspension ('kill switch') path per plane Copilot Studio, Entra, Foundry name who executes each step, and drill it with time-to-stop measured.
- Define authorized-versus-unauthorized detection and data-loss and compliance monitoring at prompt and model level using Purview DSPM for AI, DLP and Defender; state plainly what Agent 365 can and cannot see.
- Draft and agree the RACI with the client's outsourcing partner (tenant, identity and security administration) and CISO; request least-privilege roles through the partner's process; execute changes only through its change control.
- Position complementary tools (endpoint-style AI activity monitors, integration-layer agent brokers) as layers with a clear responsibility split, never as competing platforms; define the criteria under which Microsoft Foundry is opened.
- Lead the Senior Agent 365 & Security Engineer; present to the client's AI leader, Legal, CISO and enterprise-architecture leaders; hand over operation to the client's team or partner when the client elects it.
Required qualifications
- 13+ years in enterprise platform governance, security architecture or Microsoft 365 / Power Platform administration at scale, including control design in a regulated industry.
- Hands-on Microsoft Agent 365 since general availability: agent registry, Agent Map, administration and policy; Copilot Studio governance at scale.
- Power Platform admin center: environment strategy, connector and data-loss-prevention policies, credit and consumption reporting.
- Microsoft Entra: Entra Agent ID, conditional access, identity governance for non-human identities.
- Microsoft Purview (DSPM for AI, DLP, audit) and Microsoft Defender as they apply to agents and prompts.
- Operating-model design: registers, tiering, intake workflows, RACI, runbooks and drills; cost governance for consumption-based platforms.
- Works comfortably alongside an outsourced infrastructure and security partner and within its change-control process.
Preferred qualifications
- Security or governance, risk and compliance (GRC) background; NIST AI Risk Management Framework; ISO/IEC 42001.
- FinOps practices for consumption-metered platforms (tokens, credits).
- Microsoft certifications such as SC-100, SC-300, SC-400, MS-102 or PL-900.
- Familiarity with integration-layer agent registries (for example MuleSoft Agent Fabric) and ServiceNow or Salesforce agent capabilities.
- Experience in federally regulated financial environments: federal reporting obligations, audit evidence, and customer-data handling restrictions.
- Dice Id: 91092536
- Position Id: 9083235
- Posted 17 hours ago
Company Info
About Oriontek Inc
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs