Executive Information Security Governance and Policy Consultant

Nexasphere

Ottawa

Hybrid

CAD 130,000 - 190,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Nexasphere is seeking a Senior Executive Information Security Governance and Policy Consultant to lead assessment, design, and implementation of a comprehensive information protection framework for sensitive government information in Ottawa. The role is hybrid/remote and scoped to a 6-month duration with Secret clearance requirements.

The ideal candidate will bring deep expertise in information security, governance, risk management, and policy development, with hands-on experience protecting

Qualifications

  • Executive-level consulting experience in information security, governance, or enterprise risk management.
  • Deep knowledge of Government of Canada security policies, directives, and guidance.
  • Experience protecting Protected A/B or classified information.
  • Experience developing and implementing enterprise security policies, standards, procedures, and governance frameworks.
  • Strong expertise in information classification, security markings, metadata tagging, and sensitivity labelling.

Responsibilities

  • Assess current information security, governance, and information management practices.
  • Review classification, labelling, transmission, sharing, storage, retention, and disposal of sensitive data.
  • Benchmark against federal organizations and highly regulated sectors.
  • Define security controls for information classification levels and governance models.
  • Develop policies, standards, procedures, and third-party information-sharing requirements.
  • Support rollout of approved frameworks, policies, and controls; create training materials.

Skills

Executive-level consulting
Information security
Governance
Policy development
Risk management
Stakeholder management
Executive communication

Education

CISSP
CISM
CRISC
CGEIT
Microsoft Security certs

Tools

Microsoft Purview
Microsoft Information Protection
Sensitivity Labels
Data Loss Prevention (DLP)
Information Rights Management

Job description

Executive Information Security Governance and Policy Consultant

Location: Ottawa (Hybrid/Remote)
Duration: 6 Months
Security Clearance: Secret security clearance

Overview

Our client is seeking a Senior Executive Information Security Governance and Policy Consultant to lead the assessment, design, and implementation of a comprehensive information protection framework for sensitive government information.

This strategic advisory role requires deep expertise in information security, information governance, risk management, and policy development, with a strong understanding of Government of Canada security requirements. The successful consultant will help establish processes, controls, and governance standards to ensure the secure handling of Protected A and Protected B information throughout its lifecycle, including when shared with external organizations.

Key Responsibilities
  • Assess current information security, governance, and information management practices.
  • Review and analyze how sensitive information is classified, labelled, transmitted, shared, stored, retained, and securely disposed of.
  • Research Government of Canada security policies, directives, standards, and industry best practices.
  • Conduct benchmarking activities across federal organizations, Crown corporations, financial institutions, and other regulated sectors.
  • Identify gaps, risks, and opportunities for improving information protection practices.
  • Develop or enhance information classification and sensitivity-labelling frameworks.
  • Define security controls associated with information classification levels.
  • Establish requirements for security markings, metadata tagging, encryption, access controls, audit logging, retention, and secure disposal.
  • Assess technology capabilities supporting automated classification, data loss prevention (DLP), information protection, and secure external information sharing.
  • Provide recommendations related to Microsoft Purview, Microsoft Information Protection, sensitivity labels, rights management, and related security capabilities.
  • Develop policies, standards, procedures, governance models, and third-party information-sharing requirements.
  • Create implementation roadmaps, training materials, and executive-level recommendations.
  • Support the rollout and operationalization of approved frameworks, policies, and controls.
Deliverables

Potential deliverables include:

  • Current-state assessment and gap analysis
  • Research and benchmarking report
  • Information classification and sensitivity-labelling framework
  • Protected information handling standards
  • Secure external information-sharing policies and procedures
  • Third-party information protection requirements and guidance
  • Technology assessment and recommendationsImplementation roadmap and change management plan
  • Training and awareness materials
  • Executive briefings and final recommendations
Required Experience

The ideal candidate will possess:

  • Executive-level consulting experience in information security, information governance, cybersecurity, or enterprise risk management.
  • In-depth knowledge of Government of Canada security policies, directives, standards, and guidance.
  • Demonstrated experience protecting Protected A, Protected B, or classified information.
  • Experience developing and implementing enterprise security policies, standards, procedures, and governance frameworks.
  • Strong expertise in information classification, security markings, metadata tagging, and sensitivity labelling.
  • Experience managing risks associated with information sharing involving third parties, suppliers, financial institutions, or external partners.
  • Knowledge of encryption, identity and access management, secure transmission, data loss prevention, records management, retention, and secure disposal practices.
  • Experience researching and benchmarking security practices across government and highly regulated environments.
  • Hands-on familiarity with Microsoft 365 security and compliance technologies, including:
    • Microsoft Purview
    • Microsoft Information Protection (MIP)
    • Sensitivity Labels
    • Data Loss Prevention (DLP)
    • Information Rights Management (IRM)
  • Excellent stakeholder management, executive communication, policy development, and implementation skills.
Preferred Qualifications
  • Experience within the Government of Canada, Crown corporations, or other highly regulated organizations.
  • Professional certifications such as CISSP, CISM, CRISC, CGEIT, or relevant Microsoft Security certifications.
  • Experience leading enterprise-wide information protection and governance initiatives.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

10 Percent Recruiting Ltd. • Canada

Hybrid
CAD 110,000 - 140,000
RQ08753 - Security Specialist - Senior
RQ08753 - Security Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 90,000 - 130,000
Cybersercurity Compliance Analsyst
Cybersercurity Compliance Analsyst

Aplin • Edmonton

On-site
CAD 110,000 - 150,000
Data Security Advisor - Data Strategy
Data Security Advisor - Data Strategy

Altis Technology • Toronto

On-site
CAD 90,000 - 120,000
RQ09054 - Security Specialist - Threat Risk Assessment - Senior
RQ09054 - Security Specialist - Threat Risk Assessment - Senior

Rubicon Path • Toronto

On-site
CAD 85,000 - 110,000
RQ08587 - Security Specialist - Senior
RQ08587 - Security Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 90,000 - 130,000
Human Resources Consultant
Human Resources Consultant

Protak Consulting Group, Inc. • Ottawa

Hybrid
CAD 90,000 - 120,000
Senior Cloud Security Consultant - KMS/HMS Options Analysis (SSC/DND)
Senior Cloud Security Consultant - KMS/HMS Options Analysis (SSC/DND)

49 Solutions • Ottawa

On-site
CAD 166,000 - 240,000
Senior Project Management Specialist
Senior Project Management Specialist

Maplesoft Group, an SEB Company • Ottawa

Hybrid
CAD 124,000 - 152,000
Senior IT Project Manager – Federal Government
Senior IT Project Manager – Federal Government

Maplesoft Group, an SEB Company • Ottawa

On-site
CAD 124,000 - 207,000