Bank of America logo

Senior Architect- M365 Platform Security, Compliance & AI

Bank of America

Addison, TXJobSeen 5 days agoSeen in employer's feed 5 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Addison, TX
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Senior M365 Platform Security, Compliance & AI Architect defines and governs enterprise architecture for Microsoft 365 control and enablement capabilities. The role establishes target states, integration patterns, technical standards, and control frameworks across Microsoft Purview, Information Protection, Defender, Power Platform, Copilot, and Copilot Studio. It enables secure data use, governed automation, and responsible AI while strengthening information protection, threat defense, regulatory compliance, application governance, and operational resilience.

Skills & qualifications

RequiredNice to have

Skills

Microsoft PurviewMicrosoft Information ProtectionMicrosoft DefenderEntra IDPower PlatformMicrosoft 365 CopilotCopilot StudioSecurity ArchitectureCompliance ArchitectureInformation ProtectionLow-Code AutomationData GovernanceAI Platform ArchitectureData ClassificationSensitivity LabelsEncryptionData Loss PreventionRetention ManagementRecords ManagementeDiscoveryAuditingInsider Risk ManagementCommunication ComplianceData Security Posture ManagementSecurity TelemetryExposure ManagementThreat DetectionIncident ResponseZero TrustSecurity OperationsPower AppsPower AutomateDataverseApplication Lifecycle ManagementApplication GovernanceCopilot GovernanceAgent SecurityData ReadinessGrounding SourcesConnector Security

Qualifications

10+ Years Enterprise Technology Experience5+ Years Architecture ExperienceMust Be 18+

Full job description

Senior Architect- M365 Platform Security, Compliance & AI

Charlotte, North Carolina;Jacksonville, Florida; Addison, Texas

To proceed with your application, you must be at least 18 years of age.

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Charlotte/Senior-Architect--M365-Platform-Security--Compliance---AI\_26036237-1)

Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Charlotte/Senior-Architect--M365-Platform-Security--Compliance---AI\_26036237-1)

Refer a friend

To proceed with your application, you must be at least 18 years of age.

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Charlotte/Senior-Architect--M365-Platform-Security--Compliance---AI\_26036237-1)

Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Charlotte/Senior-Architect--M365-Platform-Security--Compliance---AI\_26036237-1)

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Job Description:

This job is responsible for defining an architectural vision and solution that supports the strategic outcomes of the Business' Products and Services. Key responsibilities include defining the target operating environment, designing for client resiliency, assisting with solution design, and defining non-functional requirements. Job expectations include working with stakeholders and service providers aligned to the Business' strategic objectives, evaluating the impact of strategic design decisions, and contributing to the architecture roadmap.

The Senior M365 Platform Security, Compliance & AI Architect defines and governs the enterprise architecture for the control and enablement capabilities that underpin Microsoft 365. The role establishes the target state, integration patterns, technical standards, and control framework for Microsoft Purview, Microsoft Information Protection, Microsoft Defender, Power Platform, Microsoft 365 Copilot, and Copilot Studio. Acting as a senior technical authority, this architect enables secure data use, governed automation, and responsible AI while strengthening information protection, threat defense, regulatory compliance, application governance, and operational resilience across the enterprise.

Responsibilities:

  • Own the target-state architecture and multi-year roadmap for Microsoft Purview, Microsoft Information Protection, Microsoft Defender, Power Platform, Microsoft 365 Copilot, Copilot Studio, and their dependencies on identity, data, security operations, and enterprise integration services.

  • Define reference architectures, service boundaries, integration models, configuration standards, reusable patterns, and architecture guardrails for information protection, compliance, threat protection, low-code automation, agents, and generative AI.

  • Lead architecture reviews and provide hands-on design direction for data classification, sensitivity labeling, encryption, retention, records management, DLP, eDiscovery, auditing, insider risk, compliance monitoring, and data security posture management.

  • Define the architecture for Microsoft Defender capabilities, including security signal integration, threat detection and response, exposure management, incident workflows, telemetry, and alignment with enterprise security operations.

  • Establish enterprise architecture and guardrails for Power Apps and Power Automate, including environment strategy, connectors, data policies, identity, application ownership, Application Lifecycle Management, monitoring, support models, and lifecycle controls.

  • Define the governed foundation for Microsoft 365 Copilot and Copilot Studio agents, including data readiness, grounding sources, agent identity and permissions, connectors, monitoring, auditability, and responsible AI controls.

  • Partner with Information Security, Data Management, Risk, Compliance, Legal, Privacy, Records Management, Engineering, and Operations to embed Zero Trust, least privilege, separation of duties, policy enforcement, evidence capture, and secure-by-design controls.

  • Identify and reduce risks from oversharing, excessive permissions, unmanaged applications and agents, inappropriate connector use, sensitive-data exposure, policy gaps, control fragmentation, technology obsolescence, and third-party dependencies.

  • Evaluate Microsoft roadmap changes, licensing implications, control impacts, and emerging AI and security capabilities; translate them into architecture decisions, investment options, adoption sequencing, and risk-based recommendations.

  • Maintain architecture health and control metrics and communicate material risks, dependencies, exceptions, lifecycle status, and value realization to technical and executive governance forums.

Required Qualifications:

  • 10+ years of enterprise technology experience, including 5+ years designing or governing security, compliance, information protection, low-code, automation, data governance, or AI platform architectures at enterprise scale.

  • Demonstrated architecture experience with Microsoft Purview, Microsoft Information Protection, Microsoft Defender, Entra ID dependencies, Power Platform, Microsoft 365 Copilot, Copilot Studio, and related security, data, and integration services.

  • Deep expertise in Microsoft Purview and Microsoft Information Protection, including data classification, sensitivity labels, encryption, DLP, retention, records management, eDiscovery, auditing, insider risk, communication compliance, and data security posture management.

  • Strong understanding of Microsoft Defender architecture, security telemetry, exposure management, threat detection and response, incident integration, and alignment with Zero Trust and security operations.

  • Expertise in Power Platform architecture and governance, including environments, connectors, data policies, identity, Dataverse, ALM, application ownership, monitoring, supportability, and lifecycle management.

  • Ability to design secure and governed Copilot and agent foundations addressing data readiness, grounding, identity and permissions, connector security, prompt and response protection, evaluation, monitoring, regulatory obligations, and responsible AI.

  • Expertise in architecture methods and artifacts, including capability models, current- and target-state views, roadmaps, dependency and data flows, threat models, control design, architecture decisions, and requirements-to-control traceability.

  • Working knowledge of Entra ID, Microsoft Graph, APIs, connectors, PowerShell, automation, CI/CD, telemetry, and platform operations sufficient to guide engineering and assess implementation quality.

  • Excellent written, verbal, facilitation, and executive communication skills, with the ability to make complex security, compliance, AI, and platform tradeoffs clear to technical and nontechnical stakeholders.

  • Experience establishing platform standards, reference architectures, policy and control patterns, architecture governance, lifecycle roadmaps, and technical decision processes.

  • Experience enabling and governing low-code applications, workflow automation, generative AI, copilots, or Copilot agents in a large enterprise.

  • Experience in a highly regulated environment and in supporting technology risk assessments, audits, regulatory examinations, control testing, security reviews, and remediation programs.

  • Bachelor’s degree in computer science, engineering, information systems, cybersecurity, or equivalent practical experience; relevant Microsoft, cloud, security, architecture, AI, or governance certifications preferred.

Desired Qualifications :

  • Strategic, pragmatic, and outcome-oriented; balances security, compliance, responsible innovation, control effectiveness, cost, and operational sustainability.

  • Demonstrates platform stewardship, proactive ownership, sound risk judgment, intellectual curiosity, and the courage to challenge assumptions while remaining collaborative.

  • Able to operate through ambiguity, prioritize competing demands, and move fluently between enterprise strategy, regulatory expectations, cross-platform dependencies, and detailed technical analysis.

  • Builds trusted relationships across security, risk, data, compliance, business, and technology teams and influences decisions without relying on direct authority.

  • Demonstrates disciplined execution, attention to detail, continuous learning, and a commitment to measurable improvement in security posture, control maturity, and governed innovation.

Skills:

  • Analytical Thinking

  • Architecture

  • Result Orientation

  • Solution Design

  • Technical Strategy Development

  • Application Development

  • Collaboration

  • Data Management

  • DevOps Practices

  • Risk Management

  • Agile Practices

  • Automation

  • Influence

  • Solution Delivery Process

  • Test Engineering

Shift:

1st shift (United States of America)

Hours Per Week:

40

Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.

View your "Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088\_EEOC\_KnowYourRights6.12.pdf) " poster.

View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .

Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (“Policy”) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank’s required accommodation request process before your first day of work.

This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.

Investment products offered through MLPF&S and insurance and annuity products offered through MLLA:

Are Not FDIC Insured Are Not Bank Guaranteed May Lose Value

Are Not Deposits Are Not Insured by Any Federal Government Agency Are not a condition to Any Banking Service or Activity

Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as “MLPF&S” or “Merrill”) makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation (“BofA Corp.”). MLPF&S is a registered broker-dealer, registered investment adviser, Member SIPC and a wholly owned subsidiary of BofA Corp. Insurance and annuity products are offered through Merrill Lynch Life Agency Inc., a licensed insurance agency and wholly owned subsidiary of Bank of America Corporation.

Trust, fiduciary and investment management services are provided by Bank of America, N.A., Member FDIC and wholly owned subsidiary of Bank of America Corporation (“BofA Corp.”).

Bank of America Private Bank is a division of Bank of America, N.A.

Banking products are provided by Bank of America, N.A. and affiliated banks, Members FDIC and wholly owned subsidiaries of Bank of America Corporation.

© 2026 Bank of America Corporation. All rights reserved.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.