
Data Security Architect
Hover or tap a row for full statistics (EUR / month on this chart).
Salary analysis
Compared with the selected benchmark ("All roles in Helsinki, Finland"), this listing's salary midpoint is about 93% lower. The offer sits below the benchmark range (€2,070–€5,000). The listed pay band (€219–€265) is tighter than the benchmark, which suggests lower salary variability. This benchmark is based on 2534 comparable listings.
| Market | Lower bound (25th percentile) | Median | Upper bound (75th percentile) |
|---|---|---|---|
| All roles in Helsinki, Finland | €2,070/per month | €2,907/per month | €5,000/per month |
| Pay in our data — not quoted in ad (Senior) | €219/per month | €242/per month | €265/per month |
At KPMG, we believe that shared values are the key to job satisfaction, growth, and commitment. Our culture is based on our company values. We act with integrity, think boldly, and aim for excellence. We value each other and work together for a better future. We are now looking for a Senior Microsoft Purview & Data Security Architect for our Cyber team! In this role, you will be in a central position designing, implementing, and operating our clients' data governance and security strategies. As a technical expert, you will be responsible for ensuring that the organization's sensitive information is comprehensively protected throughout the Microsoft 365 ecosystem. Since security is strongly linked to identity management, you will use your deep expertise in the Microsoft Entra environment and the features of the wider M365 platform to build a modern Zero Trust architecture. In your role, you will also ensure the quality of data governance and readiness for the secure implementation of Microsoft 365 Copilot AI solutions. Responsibilities in the Senior Microsoft Purview & Data Security Architect role include: - Security and data governance design: Design, implement, and maintain data classification frameworks (Sensitivity Labels), identification of sensitive information types (SITs), and automatic classification models. - Data Loss Prevention (DLP): Build, test, and fine-tune complex DLP rules for Exchange, SharePoint, OneDrive, and Teams environments as well as endpoints. - Identity management integration: Link Purview security violations and classifications directly to Microsoft Entra Conditional Access rules (e.g., restricting access to highly confidential information from unprotected devices). - M365 & Copilot readiness: Lead data governance cleanup projects and permission audits so that Microsoft 365 Copilot and AI tools can be implemented securely. - Lifecycle and risk management: Build data retention and deletion rules (Retention Labels & Lifecycle Management) to ensure compliance, and manage internal risk identification (Insider Risk Management). We hope for: - At least 5 years of strong and practical experience in the architectural design and management of Microsoft 365 security and compliance environments. - Deep technical expertise in Microsoft Purview solutions (such as Information Protection, Endpoint DLP, and Data Map/Catalog). - Strong expertise in the Microsoft Entra ID environment (modern authentication protocols, Conditional Access architectures, PIM, and Identity Governance). - Fluent PowerShell and Microsoft Graph API skills for automating Purview configurations and reporting. - Fluent Finnish and English language skills, both spoken and written. - Certifications supporting the role are seen as an advantage (e.g., SC-400: Information Protection Administrator, SC-300: Identity Engineer, or MS-102: Enterprise Administrator Expert). You will help our team succeed if you also have: - The ability to translate business and regulatory requirements (such as GDPR or ISO 27001) into clear technical Purview rules. - Excellent interaction and collaboration skills – you understand that implementing strict security rules requires smooth change management and an understanding of end-user needs. - A proactive and solution-oriented attitude in solving complex problems. We offer you: An interesting field of work in a large international professional organization and the opportunity to be involved in building the business of the future at KPMG. Your colleagues in the Cyber team are top experts in the field, you will have modern tools and a wide range of training available, and you will be able to grow your business expertise broadly. KPMG offers you versatile employee benefits and wide-ranging services supporting well-being at work. The position is permanent and starts according to agreement. Your office can be located in Helsinki (Töölönlahdenkatu 3 A, Helsinki) or alternatively in Jyväskylä, Oulu, Tampere, or Turku. Seize the opportunity and come create the business of the future for KPMG! If the above text described you or otherwise piqued your interest, please send your application by Sunday, August 16, 2026! Further information about the position can be provided by Ilkka Heimo (ilkka.heimo@kpmg.fi). For questions regarding recruitment, you can contact our recruiter Anna Ruokamo (available from Thursday, August 6; anna.ruokamo@kpmg.fi / +358 44 564 2794) or our recruitment team by email at recruitment@kpmg.fi. Please send your application only through the recruitment system, as we do not accept applications by email for privacy reasons. If you need assistance in the recruitment process due to a disability or special need, please contact the recruiter mentioned in the job advertisement. We can, if necessary, adapt our application process to take your support needs into account.
Job Details
Responsibilities
- Design, implement, and maintain data classification frameworks (Sensitivity Labels) and automatic classification models
- Build and fine-tune complex Data Loss Prevention (DLP) rules for Exchange, SharePoint, OneDrive, Teams, and endpoints
- Integrate Purview security violations and classifications with Microsoft Entra Conditional Access rules
- Lead data governance cleanup projects and permission audits for Microsoft 365 Copilot readiness
- Manage data retention and deletion rules (Retention Labels & Lifecycle Management) for compliance
- Manage internal risk identification (Insider Risk Management)
Requirements
- At least 5 years of strong and practical experience in Microsoft 365 security and compliance architectural design and management
- Deep technical expertise in Microsoft Purview solutions (Information Protection, Endpoint DLP, Data Map/Catalog)
- Strong expertise in Microsoft Entra ID (modern authentication protocols, Conditional Access architectures, PIM, and Identity Governance)
- Proficiency in PowerShell and Microsoft Graph API for automation
- Fluent Finnish and English language skills (spoken and written)
- Ability to translate business and regulatory requirements (GDPR, ISO 27001) into technical rules
- Excellent interaction and collaboration skills
- Proactive and solution-oriented attitude
Skills & Technologies

Related Opportunities
Discover more opportunities that match your interests and skills