Job Description
Lead the redesign and migration of a decoupled Microsoft Teams and SharePoint Online environment into a linked architecture while preserving least-privilege access. Design and enforce a data governance layer using Microsoft Purview sensitivity labels and DLP policies to ensure that Teams membership does not inadvertently extend SharePoint permissions beyond operational need.
Responsibilities: - Audit the existing decoupled Teams/SharePoint environment; document permission models, site structures, and access patterns.
- Design a target-state linked architecture with fine-grained SharePoint permission boundaries (site, library, and item level) using Entra ID and SharePoint security groups.
- Develop and execute a phased migration plan with rollback procedures and user acceptance testing.
- Design and deploy a Purview sensitivity labelling taxonomy with auto-labelling policies (client-side and service-side) to classify content across Teams, SharePoint, Exchange, and OneDrive.
- Implement Purview DLP policies to prevent unauthorised sharing and exfiltration, with policy tips and incident reporting.
- Configure label-driven access controls so that sensitivity classification governs content access independently of Teams membership.
- Produce architecture documentation, governance runbooks, permission matrices, and deliver knowledge transfer to the client's internal IT team.
Qualifications: - 5+ years hands-on experience architecting and managing Microsoft Teams, SharePoint Online, and Microsoft Purview in enterprise environments.
- Proven experience migrating or restructuring Teams/SharePoint environments with complex or non-standard permission models.
- Strong working knowledge of Entra ID group management, Conditional Access, and identity governance as they relate to M365 access control.
- Proficiency in PowerShell (SPO Management Shell, Teams PS) and SharePoint migration tooling (ShareGate, SPMT).
- Certifications: At least two of the following (current):
- Teams Administrator Associate (MS-700)
- Info Protection & Compliance Admin (SC-400)
- SharePoint Administrator (MS-102 or equiv.)
- Desirable: Identity & Access Admin (SC-300) / Cybersecurity Architect Expert (SC-100)
Additional Information:
- M to F, 1pm to 10pm Manila Time
- Homebased