M365 / Entra Security & Governance Specialist (Freelance/Contract) in Maidenhead
M365 / Entra Security & Governance Specialist (Freelance/Contract)

M365 / Entra Security & Governance Specialist (Freelance/Contract) in Maidenhead

Maidenhead Freelance 60000 - 80000 £ / year (est.) Home office (partial)
VE3

At a Glance

  • Tasks: Manage security and compliance for Microsoft 365 environments with hands-on technical expertise.
  • Company: Join a forward-thinking company focused on data protection and governance.
  • Benefits: Flexible freelance role with competitive pay and opportunities for skill development.
  • Other info: Ideal for tech-savvy individuals looking to grow in a dynamic environment.
  • Why this job: Make a real difference in safeguarding data while working with cutting-edge technology.
  • Qualifications: Experience in Microsoft security tools and a passion for data governance.

The predicted salary is between 60000 - 80000 £ per year.

The M365 / Entra Security & Governance Specialist owns the security posture, data governance, and compliance alignment of the customer's Microsoft estate. The role designs and operates Zero Trust controls, threat protection, information protection, insider risk management, and the audit / evidence machinery required to demonstrate alignment with ISO 27001, GDPR, NIST CSF and Microsoft's Secure Score baselines.

The customer processes personal and special-category data on behalf of public-sector programmes. The role therefore carries direct accountability for protecting beneficiary data, ensuring lawful processing within the EEA, and providing evidence of control effectiveness to the customer's Cyber Security team and external auditors. This is a senior, hands-on technical role — not a paper-only governance position.

Requirements

  • Key Technical Responsibilities:
  • Threat Protection — Microsoft Defender XDR
  • Operate Microsoft Defender XDR across Defender for Endpoint, Defender for Office 365 (Plan 2), Defender for Identity, Defender for Cloud Apps, and Defender Vulnerability Management.
  • Manage Defender for Endpoint deployment, onboarding (via Intune / GPO / script), attack surface reduction (ASR) rules, EDR in block mode, automated investigation and response (AIR), tamper protection, and live response.
  • Tune Defender for Office 365 anti-phishing, Safe Links, Safe Attachments, anti-spoofing, impersonation protection, attack simulation training, and Threat Explorer queries.
  • Operate Defender for Identity sensors on domain controllers and ADFS servers; investigate identity-based attack paths (DCSync, Golden Ticket, Pass-the-Hash) and remediate exposures.
  • Operate Defender for Cloud Apps for SaaS discovery, OAuth app governance, conditional access app control (reverse proxy), session policies, and shadow IT reporting.
  • Investigate alerts and incidents in the Defender XDR portal using KQL advanced hunting; build custom detections, suppression rules, and automated playbooks.
  • SIEM and SOAR — Microsoft Sentinel
    • Operate Microsoft Sentinel for the estate: data connectors (M365, Entra, Defender XDR, Azure Activity, Office 365, Threat Intelligence, Syslog/CEF), workspace architecture, retention, and cost optimisation.
    • Author analytics rules (scheduled, NRT, Fusion, Microsoft Security), build watchlists, threat intelligence integrations (TAXII / MISP), and User Entity Behaviour Analytics (UEBA).
    • Develop KQL detection content aligned to MITRE ATT&CK; operate hunting queries, bookmarks, and incident investigation graphs.
    • Build SOAR automation using Azure Logic Apps playbooks for incident enrichment, containment (e.g., disable user, force password reset, isolate device), and notification.
    • Operate the 24/7 Sentinel-based monitoring stack in collaboration with the NOC analyst function.
  • Information Protection and Data Governance — Microsoft Purview
    • Design and operate Microsoft Purview Information Protection: sensitivity labels, label policies, auto-labelling (client and service-side), encryption with rights management, and co-authoring on encrypted documents.
    • Build and tune Data Loss Prevention (DLP) policies for Exchange, SharePoint, OneDrive, Teams chat, Endpoint DLP and Power Platform; manage policy tips, overrides, and incident review.
    • Operate Insider Risk Management policies, content explorer, activity explorer, and communication compliance where in scope.
    • Design retention policies, retention labels, and records management aligned to the customer's records retention schedules and applicable public-sector records management frameworks.
    • Operate eDiscovery (Standard and Premium): cases, holds, collections, reviews, custodian management, and chain-of-custody documentation.
    • Operate Microsoft Purview Data Map, Data Catalog, and Data Estate Insights for the Microsoft Fabric / Power BI estate, including lineage, classification scans, and Data Loss Prevention for Fabric.
    • Maintain audit and reporting using Purview Audit (Standard / Premium), Compliance Manager templates (ISO 27001, GDPR, NIS2), and customer-managed Compliance Manager assessments.
  • Identity Security and Zero Trust
    • Define and maintain the Conditional Access policy baseline using a documented policy framework (Persona-based or Microsoft Zero Trust deployment guidance), including emergency / break-glass access, named locations, and report-only validation.
    • Operate Entra ID Protection — sign-in risk, user risk, risk policies, and risk investigation — including alignment with Defender XDR for unified incident view.
    • Govern privileged access via PIM, role-assignable groups, access reviews, and Just-In-Time elevation; co-own break-glass account procedures with the AD/Entra Specialist.
    • Operate Entra Permissions Management (CIEM) where licensed, providing visibility of multi-cloud permission risk.
  • Compliance and Audit
    • Maintain ISO 27001 control evidence and align with the customer's certification and surveillance audits; act as the technical lead for any audit observation related to the Microsoft estate.
    • Maintain GDPR records of processing, support Data Protection Impact Assessments for new applications, and operate technical and organisational measures (TOMs).
    • Map controls to NIST CSF, NIS2 (where applicable as an essential / important entity), and Microsoft Secure Score / Identity Secure Score; maintain a target posture and quarterly improvement plan.
    • Produce monthly security KPIs for the SLA report — Secure Score trend, MFA coverage, DLP incidents, phishing simulation results, vulnerability remediation, patch compliance — and quarterly executive risk reports.
  • Microsoft Copilot and AI Governance
    • Operate the security envelope for Microsoft 365 Copilot and Copilot Studio including SharePoint sharing hygiene ('oversharing'), sensitivity-label-aware grounding, restricted SearchableContent, and Copilot interaction audit log review.
    • Define and enforce a Responsible AI policy aligned with Microsoft's Responsible AI Standard — fairness, reliability, safety, privacy, security, inclusiveness, transparency, and accountability.
  • Mandatory Technical Skills
    • Microsoft Defender XDR (full stack) and Microsoft Sentinel — analytics, hunting (KQL), incident management, and SOAR playbook authoring.
    • Microsoft Purview — Information Protection, DLP, Insider Risk, Records Management, eDiscovery, Audit, and Compliance Manager.
    • Entra ID security: Conditional Access, MFA, PIM, Identity Protection, External Identities, and Permissions Management.
    • Zero Trust architecture knowledge per Microsoft Zero Trust deployment guidance; ability to lead a Zero Trust roadmap discussion with senior stakeholders.
    • ISO 27001:2022 control set; GDPR Articles 5, 6, 9, 25, 28, 30, 32–34; awareness of NIS2 and applicable national cyber-security guidance.
    • KQL (Kusto Query Language) — fluent across Defender Advanced Hunting, Sentinel, and Log Analytics.
    • PowerShell automation across Microsoft Graph Security, ExchangeOnlineManagement, and Compliance modules.
  • Desirable Technical Skills
    • Threat hunting using Sigma rules, MITRE ATT&CK navigator, and STIX/TAXII intel feeds.
    • SOC operations experience — shift handover, evidence preservation, incident lifecycle (NIST SP 800-61).
    • Familiarity with on-premises PAM (CyberArk, BeyondTrust) and hybrid SOC tooling beyond Microsoft.
    • Microsoft Fabric / Purview Data Loss Prevention (Fabric DLP) and AI hub for Purview.
    • Familiarity with Cyber Essentials Plus, NCSC Cyber Assessment Framework (CAF), and ENISA guidance.
  • Required Certifications
    • Microsoft Certified: Security Operations Analyst Associate (SC-200) — mandatory.
    • Microsoft Certified: Information Protection and Compliance Administrator Associate (SC-400) — mandatory.
    • Microsoft Certified: Identity and Access Administrator Associate (SC-300) — mandatory.
    • Microsoft Certified: Cybersecurity Architect Expert (SC-100) — preferred.
    • ISO/IEC 27001 Lead Implementer or Lead Auditor — preferred.
    • CISSP, CISM, or equivalent — desirable.

    M365 / Entra Security & Governance Specialist (Freelance/Contract) in Maidenhead employer: VE3

    As a leading provider in the realm of Microsoft security and governance, we pride ourselves on fostering a dynamic work culture that prioritises innovation and collaboration. Our freelance/contract roles offer competitive compensation, flexible working arrangements, and ample opportunities for professional development, ensuring that our specialists can thrive while making a meaningful impact on public-sector programmes. Join us in a supportive environment where your expertise in M365 and Entra can truly shine, all while contributing to the protection of vital beneficiary data.
    VE3

    Contact Detail:

    VE3 Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land M365 / Entra Security & Governance Specialist (Freelance/Contract) in Maidenhead

    ✨Tip Number 1

    Network like a pro! Attend industry meetups, webinars, or online forums related to M365 and security. Engaging with professionals in the field can lead to job opportunities that aren't even advertised yet.

    ✨Tip Number 2

    Show off your skills! Create a portfolio showcasing your projects and achievements in M365 security and governance. This can be a game-changer during interviews, giving you an edge over other candidates.

    ✨Tip Number 3

    Prepare for those interviews! Research common questions for M365 roles and practice your responses. We recommend using the STAR method (Situation, Task, Action, Result) to structure your answers effectively.

    ✨Tip Number 4

    Apply through our website! We often have exclusive listings that you won't find elsewhere. Plus, it shows you're genuinely interested in joining our team and makes it easier for us to connect with you.

    We think you need these skills to ace M365 / Entra Security & Governance Specialist (Freelance/Contract) in Maidenhead

    Microsoft Defender XDR
    Microsoft Sentinel
    KQL (Kusto Query Language)
    PowerShell automation
    Microsoft Purview
    Data Loss Prevention (DLP)
    Insider Risk Management
    eDiscovery
    ISO 27001
    GDPR compliance
    Zero Trust architecture
    Conditional Access
    Identity Protection
    Privileged Identity Management (PIM)
    Threat Protection

    Some tips for your application 🫡

    Tailor Your CV: Make sure your CV is tailored to the M365 / Entra Security & Governance Specialist role. Highlight your relevant experience with Microsoft Defender, Sentinel, and Purview, and don’t forget to mention any certifications you hold!

    Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security and governance in the Microsoft ecosystem. Share specific examples of how you've tackled similar challenges in the past.

    Showcase Your Technical Skills: Be sure to list all your technical skills that align with the job description. Mention your proficiency in KQL, PowerShell automation, and any experience with Zero Trust architecture. We want to see what makes you stand out!

    Apply Through Our Website: Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining the StudySmarter team!

    How to prepare for a job interview at VE3

    ✨Know Your Stuff

    Make sure you’re well-versed in M365, Entra, and all the security protocols mentioned in the job description. Brush up on Zero Trust architecture and be ready to discuss how you've implemented these strategies in past roles.

    ✨Showcase Your Hands-On Experience

    This role is hands-on, so be prepared to share specific examples of your work with Microsoft Defender XDR, Sentinel, and Purview. Talk about challenges you faced and how you overcame them to demonstrate your problem-solving skills.

    ✨Understand Compliance Inside Out

    Since compliance is a big part of this role, make sure you can discuss ISO 27001, GDPR, and NIST CSF confidently. Be ready to explain how you’ve ensured compliance in previous positions and what measures you took to maintain data governance.

    ✨Ask Smart Questions

    Prepare insightful questions that show your interest in the company’s security posture and governance strategies. This not only demonstrates your knowledge but also your enthusiasm for the role and the organisation.

    M365 / Entra Security & Governance Specialist (Freelance/Contract) in Maidenhead
    VE3
    Location: Maidenhead

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    >