18 Sep
|
Nexasphere
|
Ottawa
Executive Information Security Governance and Policy Consultant
Location: Ottawa (Hybrid/Remote)
Duration: 6 Months
Security Clearance: Secret security clearance
Overview
Our client is seeking a Senior Executive Information Security Governance and Policy Consultant to lead the assessment, design, and implementation of a comprehensive information protection framework for sensitive government information.
This strategic advisory role requires deep expertise in information security, information governance, risk management, and policy development, with a solid understanding of Government of Canada security requirements. The successful consultant will help establish processes, controls, and governance standards to ensure the secure handling of Protected A and Protected B information throughout its lifecycle, including when shared with external organizations.
Key Responsibilities
- Assess current information security, governance, and information management practices.
- Review and analyze how sensitive information is classified, labelled, transmitted, shared, stored, retained, and securely disposed of.
- Research Government of Canada security policies, directives, standards, and industry best practices.
- Conduct benchmarking activities across federal organizations, Crown corporations, financial institutions, and other regulated sectors.
- Identify gaps, risks, and opportunities for improving information protection practices.
- Develop or enhance information classification and sensitivity-labelling frameworks.
- Define security controls associated with information classification levels.
- Establish requirements for security markings, metadata tagging, encryption, access controls, audit logging,
retention, and secure disposal.
- Assess technology capabilities supporting automated classification, data loss prevention (DLP), information protection, and secure external information sharing.
- Provide recommendations related to Microsoft Purview, Microsoft Information Protection, sensitivity labels, rights management, and related security capabilities.
- Develop policies, standards, procedures, governance models, and third-party information-sharing requirements.
- Create implementation roadmaps, training materials, and executive-level recommendations.
- Support the rollout and operationalization of approved frameworks, policies, and controls.
Deliverables
Potential deliverables include
- Current-state assessment and gap analysis
- Research and benchmarking report
- Information classification and sensitivity-labelling framework
- Protected information handling standards
- Secure external information-sharing policies and procedures
- Third-party information protection requirements and guidance
- Technology assessment and recommendations
- Implementation roadmap and change management plan
- Training and awareness materials
- Executive briefings and final recommendations
Required Experience The ideal candidate will possess:
- Executive-level consulting experience in information security,
information governance, cybersecurity, or enterprise risk management.
- In-depth knowledge of Government of Canada security policies, directives, standards, and guidance.
- Demonstrated experience protecting Protected A, Protected B, or classified information.
- Experience developing and implementing enterprise security policies, standards, procedures, and governance frameworks.
- Strong expertise in information classification, security markings, metadata tagging, and sensitivity labelling.
- Experience managing risks associated with information sharing involving third parties, suppliers, financial institutions, or external partners.
- Knowledge of encryption, identity and access management, secure transmission, data loss prevention, records management, retention, and secure disposal practices.
- Experience researching and benchmarking security practices across government and highly regulated environments.
- Hands-on familiarity with Microsoft 365 security and compliance technologies, including:
- Microsoft Purview
- Microsoft Information Protection (MIP)
- Sensitivity Labels
- Data Loss Prevention (DLP)
- Information Rights Management (IRM)
- Excellent stakeholder management, executive communication, policy development, and implementation skills.
Preferred Qualifications
- Experience within the Government of Canada, Crown corporations, or other highly regulated organizations.
- Professional certifications such as CISSP, CISM, CRISC, CGEIT, or relevant Microsoft Security certifications.
- Experience leading enterprise-wide information protection and governance initiatives.
📌 Executive Information Security Governance and Policy Consultant (Ottawa)
🏢 Nexasphere
📍 Ottawa