The role:
You'll lead the classification and protection of unstructured data across a large insurance estate, working within a consultancy delivery team.
- Scan and discover content across SharePoint Online, OneDrive, Teams, Exchange Online and on-prem file shares
- Set up and run the Purview on-prem scanner, including the Azure SQL results store and Windows Server scanner nodes
- Build an inventory of document types, locations, sensitivity and access patterns to shape label design and policy priorities
- Design a sensitivity label taxonomy for a Lloyd's market insurer, from Public up to Highly Confidential, with sector-specific sub-labels
- Create and tune custom SITs (keywords, regex, confidence-weighted rules) for marine insurance and Lloyd's document types
- Roll out auto-labelling for SharePoint, OneDrive and Exchange, plus client-side labelling in Office apps
- Run a phased DLP rollout across M365, from audit-only to policy tips, block-with-override and full enforcement where it makes sense
- Review permissions across SharePoint, OneDrive, shared drives and file shares, flagging over-permissioned accounts, orphaned access and odd group memberships
- Report access governance findings and least-privilege recommendations that fit the sensitivity model
- Document what can't be auto-classified, such as password-protected files, third-party documents and regulated or evidential workloads
- Work with IT, compliance and legal stakeholders, run working sessions and explain outcomes in plain English
- Produce discovery reports, taxonomy documentation, policy design rationale, test scripts and deployment runbooks
Essential
- Hands-on Microsoft Purview Information Protection experience (not Azure Purview data governance)
- Sensitivity labels, label policies and auto-labelling across SharePoint, OneDrive, Exchange and Teams
- Building and testing custom SITs, including keyword dictionaries, regex and trainable classifiers
- Deploying and managing the Purview on-prem scanner, including Azure SQL and scanner node setup
- DLP design and deployment across at least three M365 workloads
- RBAC and access governance reviews in SharePoint Online and M365
- Comfortable in regulated environments and with data handling and confidentiality rules
- Background in financial services, insurance or Lloyd's market, with knowledge of underwriting and claims documents
- Strong communicator who can present technical findings to non-technical people
- M365 E5 licensing experience
Desirable
- SC-400 or equivalent
- Endpoint DLP
- Defender for Cloud Apps integration with Purview
- Consultancy or professional services experience
- GDPR, FCA data handling and Lloyd's regulatory knowledge
- Wider Purview exposure (Compliance Manager, eDiscovery, Insider Risk Management