21 Sep
|
Nexasphere
|
Ahuntsic
21 Sep
Nexasphere
Ahuntsic
Executive Information Security Governance and Policy Consultant Location:
Ottawa (Hybrid/Remote) Duration
6 Months Security Clearance:
Secret security clearance
Overview Our client is seeking a
Senior Executive Information Security Governance and Policy Consultant to lead the assessment, design, and implementation of a comprehensive information protection framework for sensitive government information.
This strategic advisory role requires deep expertise in information security, information governance, risk management, and policy development , with a robust understanding of Government of Canada security requirements. The successful consultant will help establish processes, controls, and governance standards to ensure the secure handling of
Protected A and Protected B information throughout its lifecycle, including when shared with external organizations.
Key Responsibilities
Assess current information security, governance, and information management practices.
Review and analyze how sensitive information is classified, labelled, transmitted, shared, stored, retained, and securely disposed of.
Research Government of Canada security policies, directives, standards, and industry best practices.
Conduct benchmarking activities across federal organizations, Crown corporations, financial institutions, and other regulated sectors.
Identify gaps, risks, and opportunities for improving information protection practices.
Develop or enhance information classification and sensitivity-labelling frameworks.
Define security controls associated with information classification levels.
Establish requirements for security markings, metadata tagging, encryption, access controls, audit logging,
retention, and secure disposal.
Assess technology capabilities supporting automated classification, data loss prevention (DLP), information protection, and secure external information sharing.
Provide recommendations related to Microsoft Purview, Microsoft Information Protection, sensitivity labels, rights management, and related security capabilities.
Develop policies, standards, procedures, governance models, and third-party information-sharing requirements.
Create implementation roadmaps, training materials, and executive-level recommendations.
Support the rollout and operationalization of approved frameworks, policies, and controls.
Deliverables Potential deliverables include:
Current-state assessment and gap analysis
Research and benchmarking report
Information classification and sensitivity-labelling framework
Protected information handling standards
Secure external information-sharing policies and procedures
Third-party information protection requirements and guidance
Technology assessment and recommendationsImplementation roadmap and change management plan
Training and awareness materials
Executive briefings and final recommendations
Required Experience The ideal candidate will possess:
Executive-level consulting experience in information security,
information governance, cybersecurity, or enterprise risk management.
In-depth knowledge of Government of Canada security policies, directives, standards, and guidance.
Demonstrated experience protecting Protected A, Protected B, or classified information.
Experience developing and implementing enterprise security policies, standards, procedures, and governance frameworks.
Strong expertise in information classification, security markings, metadata tagging, and sensitivity labelling.
Experience managing risks associated with information sharing involving third parties, suppliers, financial institutions, or external partners.
Knowledge of encryption, identity and access management, secure transmission, data loss prevention, records management, retention, and secure disposal practices.
Experience researching and benchmarking security practices across government and highly regulated environments.
Hands-on familiarity with Microsoft 365 security and compliance technologies, including:
Microsoft Purview
Microsoft Information Protection (MIP)
Sensitivity Labels
Data Loss Prevention (DLP)
Information Rights Management (IRM)
Excellent stakeholder management, executive communication, policy development, and implementation skills.
Preferred Qualifications
Experience within the Government of Canada, Crown corporations, or other highly regulated organizations.
Professional certifications such as CISSP, CISM, CRISC, CGEIT, or relevant Microsoft Security certifications.
Experience leading enterprise-wide information protection and governance initiatives.
📌 Executive Information Security Governance and Policy Consultant (Ahuntsic)
🏢 Nexasphere
📍 Ahuntsic