
The client is a leading international consulting company specializing in real estate, infrastructure, and industrial sector solutions. Headquartered in Stuttgart, Germany, they operate in over 60 locations worldwide with approximately 6,000 employees.
They are recognized for their strong focus on sustainability, digital transformation, and industrial modernization, delivering cost-efficient, future-ready solutions tailored to complex enterprise environments.
We are looking for a Microsoft Purview expert to lead a two month reference implementation for an international client. You will join their Cybersecurity GRC team and report to the Head of Global Cyber Security GRC.
The project is driven by security governance. Your job is to make sure the organisation meets data privacy regulations and its own information classification rules. You will find regulatory and data risks, then fix them using Purview's data protection, compliance and governance capabilities. The work runs from discovery workshops through a test deployment and into the live rollout.
You will work with an internal cross-functional team, collaborating with engineers and business stakeholders to deliver scalable, high-quality data solutions.
You will own the reference implementation end to end. That covers:
Hands-on delivery of Microsoft Purview projects, especially sensitivity labels, information protection, data loss prevention and retention
Deep knowledge of ISO/IEC 27001, 27017 and 27701, NIST and GDPR
A track record running compliance programmes and getting organisations audit-ready
Experience turning policy into working processes and technical controls
Strong analytical thinking and attention to detail
Confidence leading workshops with security, legal and business stakeholders
Microsoft certification in Azure and Purview, for example SC-401 Information Security Administrator, SC-100 or AZ-500
Fluent English
Nice to have
Experience with Purview Insider Risk Management or Communication Compliance to detect risky user behaviour
Background in Microsoft cloud security and threat protection beyond Purview, such as Defender
Earlier work in a global company with data across several regions and privacy regimes
Consulting experience on short, fixed-scope engagements