Live opening · Posted 4 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
We're seeking a hands-on Cyber Security Consultant to lead an AI Security Operating Capability workstream, helping a large federal agency stand up the ability to review, approve, monitor, and secure AI use cases running on Microsoft Power Platform. As workstream lead, this consultant will independently navigate Microsoft Copilot Studio, Power Automate, and Dataverse to identify where security controls apply, configure and validate those controls directly, and own the client relationship through delivery and knowledge transfer. This is a hands-on technical leadership role — not a policy-advisory position — and requires approximately 7+ years of cybersecurity/GRC experience, including at least 3 years configuring security controls directly within Microsoft Power Platform and/or Copilot environments. (Years of experience were not stated in the source notification; this range was inferred from the seniority and independence the responsibilities require — see Recruiter Notes.)
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
Key Responsibilities:
Lead the assessment of existing security tooling and identify gaps against AI-specific risk domains for Power Platform and Copilot
Identify and prioritize security controls aligned to Microsoft security benchmarks and industry best practices for Power Platform/Copilot Studio and connected AI use cases
Own execution of control configuration, testing, and documentation (runbooks) across selected AI use cases (chatbots, email automation, analytics/ML, computer vision) directly within Copilot Studio, Power Automate, Dataverse, and related Microsoft security tools (Entra, Purview)
Document detailed control specifications (objective, description, owner, implementation guidance, evidence/testing method) and overlay implemented controls onto existing architecture documentation
Direct and quality-check the work of the supporting consultant on the workstream
Lead client-facing knowledge transfer sessions so the client's security team can operate controls and the intake process independently going forward
Serve as the primary point of contact and escalation path with client security and platform teams throughout configuration and validation
Report workstream status and risk to engagement leadership
Requirements:
Must-Have:
Minimum ~7 years of cybersecurity/GRC experience, including demonstrated leadership of a technical security workstream
Strong, hands-on technical proficiency with Microsoft Copilot (including Copilot Studio) and the Power Platform (Power Automate, Dataverse) — able to independently navigate these platforms to identify where controls apply and configure/enable them directly, not just advise at a policy level
Working knowledge of Microsoft security suite tools (Entra, Purview) and how they integrate with Power Platform/Copilot environments
Demonstrated experience with security control design, testing, and runbook/technical documentation
Strong client-facing communication skills, with experience leading working sessions and delivering knowledge transfer
U.S. Citizenship or Permanent Residency
Preferred / Nice-to-Have:
Prior experience on federal contracting engagements
Relevant certifications (e.g., CISSP, Security+, Microsoft SC-900/SC-401 or equivalent)
Familiarity with AI/ML security risk domains and Microsoft security benchmarks/baselines
Experience directing or mentoring junior consultants within a workstream
Skill(s):
Technical Skills:
Microsoft Copilot Studio
Power Automate
Microsoft Dataverse
Microsoft Entra ID
Microsoft Purview
AI/ML security risk assessment
Security control design, configuration, and testing
Technical runbook documentation
Microsoft security benchmarks/baselines
GRC frameworks
Soft Skills:
Client-facing communication and workshop facilitation
Workstream leadership and ownership
Stakeholder management
Knowledge transfer and training delivery
Cross-functional collaboration
Benefits:
Dragonfli Group offers a comprehensive benefits package that includes:
Medical: Multiple POS health plan options including an HSA-compatible plan
Dental: PPO coverage for preventive, basic, and major services
Vision: Annual exam, frames, lenses, and contact lens allowance
401(k): Employer match up to 5% of eligible compensation
Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
PTO: 15–25 days annually based on tenure
Paid Federal Holidays: All 11 federal holidays observed
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.