Senior Microsoft Azure AI & Power Platform EngineerAbout WGA Advisors
WGA Advisors is a global management consulting firm and a world-class alternative to the big-name consulting firms. We help senior leaders make and execute the decisions that matter most, across AI and digital transformation strategy, ESG, growth, culture, operations, and enterprise transformation. Our firm focuses on areas of senior management concern, creating enduring value and delivering measurable impact at the intersection of strategy, technology, and operating model design.
WGA’s AI Workforce Solutions practice is at the forefront of helping global enterprises move from isolated AI experimentation to scaled, business-led agentic AI deployment.
The Opportunity
WGA Advisors is engaging a Senior Microsoft Azure AI & Power Platform Engineer to design, configure, build, test, and deploy the Microsoft technology foundation supporting production enterprise AI Agents.
This is a highly hands-on engineering role responsible for implementing a secure Microsoft-based agentic AI environment using Microsoft Copilot Studio, Microsoft Foundry, Azure AI services, Microsoft Power Platform, Microsoft Presidio, Azure Container Apps, API Management, Azure Key Vault, Microsoft Entra ID, and related Azure services.
A major component of the role is implementing a secure data-protection layer that identifies and tokenizes or pseudonymizes personally identifiable information (PII) before information is provided to large language models. The engineer will deploy and configure Microsoft Presidio within Azure and implement custom PII recognizers, tokenization services, APIs, and integration patterns required to prevent protected information from being unnecessarily exposed to LLMs.
The engineer will work alongside WGA engagement leadership, AI Agent builders, a Microsoft Azure Security & Governance Engineer, and client technology teams. The role requires strong hands-on Microsoft platform expertise, practical software engineering capability, disciplined security practices, and the ability to deliver production-ready solutions to the quality and governance standards of top-tier consulting engagements.
This is a temporary project-based engagement structured around architecture, environment setup, configuration, build, integration, testing, deployment, and go-live support. Strong potential for extension based on performance and continued client demand across WGA’s pipeline.
Core ResponsibilitiesMicrosoft AI Platform Build and Configuration
- Configure Microsoft Azure and Microsoft Foundry environments supporting enterprise AI Agent development and deployment.
- Configure and integrate Microsoft Copilot Studio agents with Microsoft Foundry and supporting Azure services.
- Establish development, test, and production environments with appropriate separation, configuration management, and deployment controls.
- Configure Foundry projects, model endpoints, agent services, connections, credentials, and supporting resources.
- Configure Microsoft Power Platform components including Copilot Studio, Power Automate, Dataverse, connectors, custom connectors, environment variables, and solutions.
- Build secure APIs and integration services connecting Copilot Studio, Foundry, Presidio, enterprise applications, and data platforms.
- Configure Azure Container Apps or comparable Azure container services for custom AI and data-protection services.
- Implement Azure API Management where required to establish controlled API access, authentication, throttling, logging, and policy enforcement.
- Configure Azure Key Vault for secrets, credentials, certificates, encryption keys, and other protected configuration.
- Implement managed identities and Microsoft Entra ID authentication wherever technically appropriate rather than embedding credentials within applications or flows.
PII Protection, Presidio and Tokenization
- Deploy and configure Microsoft Presidio Analyzer and Presidio Anonymizer within the client’s Azure environment.
- Configure Presidio recognizers for standard personally identifiable information and other sensitive data.
- Implement custom Presidio recognizers for organization-specific and country-specific identifiers not supported by predefined recognizers.
- Develop recognizers using regular expressions, contextual analysis, validation logic, confidence scoring, deny lists, allow lists, and Python-based validation where appropriate.
- Develop and maintain Presidio YAML configuration files, custom Python recognizers, analyzer configuration, anonymizer configuration, and associated deployment artifacts.
- Implement tokenization and pseudonymization patterns that replace sensitive values with non-sensitive tokens before information is submitted to an LLM.
- Implement secure token mapping and controlled re-identification where business processes require original values to be restored after LLM processing.
- Ensure token mappings, encryption keys, and original sensitive values remain segregated from LLM-accessible services.
- Build the processing sequence necessary to enforce a pattern such as:
Business Application / Copilot Studio → PII Protection Service → Tokenized Data → Foundry / LLM → Controlled Re-identification → Business Application
- Develop automated positive, negative, boundary, and false-positive tests for custom PII recognizers.
- Tune recognizer confidence thresholds based on testing and production observations.
- Support recognition of sensitive information contained within structured and unstructured text.
- Implement appropriate application logging without inadvertently writing unmasked PII into logs, telemetry, prompts, or exception messages.
Foundry and LLM Integration
- Configure Microsoft Foundry for enterprise LLM and AI Agent workloads.
- Implement secure model and agent endpoints.
- Integrate Foundry with Copilot Studio and other Microsoft services.
- Configure model access, deployment settings, endpoint configuration, authentication, and consumption controls.
- Implement prompt and response processing pipelines that ensure required PII protection occurs before LLM invocation.
- Build reliable exception handling for model, API, tokenization, and integration failures.
- Implement retries, timeout handling, idempotency, and appropriate human review paths.
- Support integration with approved Microsoft-hosted and externally hosted models where required by solution architecture.
- Implement appropriate telemetry and observability for model and agent execution.
Azure Infrastructure and Application Security
- Work with the Azure Security & Governance Engineer to implement private and controlled connectivity between AI services.
- Configure managed identities, service principals, role-based access control, and least-privilege application permissions.
- Integrate applications with Azure Key Vault.
- Support private endpoints, virtual network integration, private DNS, firewall rules, and controlled outbound connectivity where required.
- Ensure production AI components are deployed without unnecessary public exposure.
- Implement secure configuration management across development, test, and production environments.
- Ensure application architecture supports enterprise security, auditability, monitoring, and change-management requirements.
Integration and Data Services
- Integrate AI Agents with enterprise applications, databases, APIs, Microsoft 365 services, and cloud data platforms.
- Build Power Automate flows and Copilot Studio actions supporting agent orchestration.
- Develop REST API integrations and custom connectors where standard Microsoft connectors are insufficient.
- Implement reliable read/write integration patterns with least-privilege access.
- Implement guarded and idempotent write logic where AI Agents perform transactional operations.
- Ensure agent actions can be traced through appropriate transaction, correlation, or request identifiers.
- Collaborate with client application and data teams to establish field definitions, API contracts, credentials, and system-of-record boundaries.
Testing, Deployment and Production Readiness
- Develop technical test plans covering infrastructure, integrations, PII protection, agent execution, security controls, and failure scenarios.
- Perform unit, integration, regression, and production smoke testing.
- Validate that protected data cannot bypass required PII-processing controls.
- Test false positives and false negatives associated with custom Presidio recognition.
- Support security and architecture reviews prior to production deployment.
- Deploy solutions through client change-control processes.
- Monitor production services during go-live and hypercare.
- Troubleshoot application, integration, identity, networking, model, and PII-processing issues.
- Stabilize production services as real-world usage exposes edge cases.
Documentation and Knowledge Transfer
- Produce clear architecture and configuration documentation for deployed Microsoft AI services.
- Document custom Presidio recognizers, tokenization logic, APIs, security dependencies, and operational procedures.
- Maintain deployment and configuration instructions sufficient for another qualified engineer to reproduce the environment.
- Document environment-specific configuration without embedding production credentials or secrets.
- Transition deployed solutions and operating procedures to client technology teams.
QualificationsEducation
- Bachelor’s degree required in a relevant discipline, including but not limited to Computer Science, Software Engineering, Information Systems, Data Science, Artificial Intelligence, Cybersecurity, Engineering, or a closely related technical field.
- Strong academic record from a recognized institution; relevant Microsoft Azure, AI, Power Platform, or security certifications a plus.
Experience
- 8+ years of overall professional technology experience, with significant hands-on cloud engineering or enterprise application delivery experience.
- Demonstrated hands-on delivery with Microsoft Azure in enterprise production environments.
- Demonstrated experience with Microsoft Copilot Studio, Microsoft Power Platform, Azure AI, Microsoft Foundry/Azure AI Foundry, or comparable enterprise AI platforms.
- Experience implementing APIs, containerized services, Python applications, and cloud-based integrations.
- Experience implementing enterprise authentication, managed identity, RBAC, Key Vault, and secure application integration patterns.
- Experience deploying AI or LLM-enabled applications into production environments.
- Experience delivering client-facing technology solutions under structured acceptance criteria, change control, and high-quality consulting or enterprise delivery standards.
Required Expert Skills
- Microsoft Azure architecture and hands-on configuration.
- Microsoft Foundry / Azure AI services.
- Microsoft Copilot Studio.
- Microsoft Power Automate and Power Platform.
- Python development.
- REST APIs and enterprise system integration.
- Docker/containerized application deployment.
- Azure Container Apps or equivalent Azure container technologies.
- Microsoft Entra ID, managed identities, and Azure RBAC.
- Azure Key Vault and secure secret management.
- Enterprise LLM integration and agentic AI architecture.
- Secure handling of PII and sensitive data.
Experience with Microsoft Presidio is strongly preferred but not mandatory for an otherwise exceptional Azure/Python AI engineer. Candidates should have demonstrated experience implementing PII detection, anonymization, pseudonymization, tokenization, data masking, or comparable sensitive-data protection patterns.
Technical Fluency
- Strong understanding of LLM architecture, prompt/response processing, agent orchestration, and enterprise AI security considerations.
- Ability to write and troubleshoot Python code rather than relying exclusively on low-code development.
- Understanding of regex, entity recognition, confidence scoring, validation logic, and data classification.
- Understanding of OAuth, REST APIs, JSON, managed identities, service principals, RBAC, and API authentication.
- Understanding of Azure networking concepts including VNets, private endpoints, DNS, firewalls, and controlled egress.
- Strong understanding of development/test/production environment management and deployment discipline.
- Familiarity with Purview, Sentinel, Azure Monitor, Application Insights, and enterprise logging is desirable.
- Familiarity with the broader agentic AI landscape, orchestration frameworks, and enterprise LLM deployment considerations.
Communication and Execution
- Clear written and verbal communication, including the ability to explain AI architecture, security controls, PII-processing behavior, and integration design to both business and technical audiences.
- Proven ability to work independently and take ownership of complex technical workstreams.
- Ability to translate architecture requirements into functioning production configurations rather than limiting work to conceptual design.
- Proven ability to deliver on a pipelined schedule with iterative feedback, tight timelines, and high-quality standards.
- Demonstrated ownership, follow-through, disciplined troubleshooting, and attention to technical detail.
- Comfortable working directly with senior consultants, enterprise architects, security teams, application owners, and client technology leadership.
Engagement Details
- Hourly Rate: $80-$100/hour, commensurate with experience
- Engagement Type: Temporary / Contract
- Duration: 5 Months
- Work Location: Los Angeles, CA; hybrid/remote minimal on-site presence at Los Angeles-area locations as required by project build, testing, and deployment cadence
- Travel: 25%, Travel to Singapore, and Toyko for testing 1-2 weeks session
- Authorization: Must be based in the United States and authorized to work in the United States
WGA Advisors is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation
Pay: $80.00 - $100.00 per hour
Expected hours: 40.0 per week
Benefits:
Experience:
- Microsoft Presidio: 3 years (Required)
- Microsoft Foundry: 3 years (Required)
- PII Protection, Presidio and Tokenization: 3 years (Required)
- Microsoft AI Platform Build and Configuration: 3 years (Required)
Language:
Willingness to travel:
Work Location: Hybrid remote in Manhattan Beach, CA 90266