Executive Information Security Governance and Policy Consultant (Ottawa)

Executive Information Security Governance and Policy Consultant (Ottawa)

18 Sep
|
Nexasphere
|
Ottawa

18 Sep

Nexasphere

Ottawa

Executive Information Security Governance and Policy Consultant Location: Ottawa (Hybrid/Remote) Duration: 6 Months Security Clearance: Secret security clearance Overview Our client is seeking a Senior Executive Information Security Governance and Policy Consultant to lead the assessment, design, and implementation of a comprehensive information protection framework for sensitive government information.

This strategic advisory role requires deep expertise in information security, information governance, risk management, and policy development , with a strong understanding of Government of Canada security requirements.

The successful consultant will help establish processes, controls, and governance standards to ensure the secure handling of Protected A and Protected B information throughout its lifecycle, including when shared with external organizations.

Key Responsibilities Assess current information security, governance, and information management practices.

Review and analyze how sensitive information is classified, labelled, transmitted, shared, stored, retained, and securely disposed of.

Research Government of Canada security policies, directives, standards, and industry best practices.

Conduct benchmarking activities across federal organizations, Crown corporations, financial institutions, and other regulated sectors.

Identify gaps, risks, and opportunities for improving information protection practices.

Develop or enhance information classification and sensitivity-labelling frameworks.

Define security controls associated with information classification levels.

Establish requirements for security markings, metadata tagging, encryption, access controls,



audit logging, retention, and secure disposal.

Assess technology capabilities supporting automated classification, data loss prevention (DLP), information protection, and secure external information sharing.

Provide recommendations related to Microsoft Purview, Microsoft Information Protection, sensitivity labels, rights management, and related security capabilities.

Develop policies, standards, procedures, governance models, and third-party information-sharing requirements.

Create implementation roadmaps, training materials, and executive-level recommendations.

Support the rollout and operationalization of approved frameworks, policies, and controls.

Deliverables Potential deliverables include: Current-state assessment and gap analysis Research and benchmarking report Information classification and sensitivity-labelling framework Protected information handling standards Secure external information-sharing policies and procedures Third-party information protection requirements and guidance Technology assessment and recommendations Implementation roadmap and change management plan Training and awareness materials Executive briefings and final recommendations Required Experience The ideal candidate will possess: Executive-level consulting experience in information security,



information governance, cybersecurity, or enterprise risk management.

In-depth knowledge of Government of Canada security policies, directives, standards, and guidance.

Demonstrated experience protecting Protected A, Protected B, or classified information.

Experience developing and implementing enterprise security policies, standards, procedures, and governance frameworks.

Solid expertise in information classification, security markings, metadata tagging, and sensitivity labelling.

Experience managing risks associated with information sharing involving third parties, suppliers, financial institutions, or external partners.

Knowledge of encryption, identity and access management, secure transmission, data loss prevention, records management, retention, and secure disposal practices.

Experience researching and benchmarking security practices across government and highly regulated environments.

Hands-on familiarity with Microsoft 365 security and compliance technologies, including: Microsoft Purview Microsoft Information Protection (MIP) Sensitivity Labels Data Loss Prevention (DLP) Information Rights Management (IRM) Excellent stakeholder management, executive communication, policy development, and implementation skills.

Preferred Qualifications Experience within the Government of Canada, Crown corporations, or other highly regulated organizations.

Professional certifications such as CISSP, CISM, CRISC, CGEIT, or relevant Microsoft Security certifications.

Experience leading enterprise-wide information protection and governance initiatives.

📌 Executive Information Security Governance and Policy Consultant (Ottawa)
🏢 Nexasphere
📍 Ottawa

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: executive information security governance and policy consultant (ottawa) / ottawa