Titre du poste ou emplacement

Executive Information Security Governance and Policy Consultant

Nexasphere - 2 emplois

Ottawa, ON

Publié il y a 2 jours

Détails de l'emploi :

Télétravail
Temps plein
Contractuel
Exécutif

Executive Information Security Governance and Policy Consultant

Location: Ottawa (Hybrid/Remote)
Duration: 6 Months
Security Clearance: Secret security clearance

Overview

Our client is seeking a Senior Executive Information Security Governance and Policy Consultant to lead the assessment, design, and implementation of a comprehensive information protection framework for sensitive government information.

This strategic advisory role requires deep expertise in information security, information governance, risk management, and policy development, with a strong understanding of Government of Canada security requirements. The successful consultant will help establish processes, controls, and governance standards to ensure the secure handling of Protected A and Protected B information throughout its lifecycle, including when shared with external organizations.

Key Responsibilities

  • Assess current information security, governance, and information management practices.
  • Review and analyze how sensitive information is classified, labelled, transmitted, shared, stored, retained, and securely disposed of.
  • Research Government of Canada security policies, directives, standards, and industry best practices.
  • Conduct benchmarking activities across federal organizations, Crown corporations, financial institutions, and other regulated sectors.
  • Identify gaps, risks, and opportunities for improving information protection practices.
  • Develop or enhance information classification and sensitivity-labelling frameworks.
  • Define security controls associated with information classification levels.
  • Establish requirements for security markings, metadata tagging, encryption, access controls, audit logging, retention, and secure disposal.
  • Assess technology capabilities supporting automated classification, data loss prevention (DLP), information protection, and secure external information sharing.
  • Provide recommendations related to Microsoft Purview, Microsoft Information Protection, sensitivity labels, rights management, and related security capabilities.
  • Develop policies, standards, procedures, governance models, and third-party information-sharing requirements.
  • Create implementation roadmaps, training materials, and executive-level recommendations.
  • Support the rollout and operationalization of approved frameworks, policies, and controls.

Deliverables

Potential deliverables include:

  • Current-state assessment and gap analysis
  • Research and benchmarking report
  • Information classification and sensitivity-labelling framework
  • Protected information handling standards
  • Secure external information-sharing policies and procedures
  • Third-party information protection requirements and guidance
  • Technology assessment and recommendations
  • Implementation roadmap and change management plan
  • Training and awareness materials
  • Executive briefings and final recommendations

Required Experience

The ideal candidate will possess:

  • Executive-level consulting experience in information security, information governance, cybersecurity, or enterprise risk management.
  • In-depth knowledge of Government of Canada security policies, directives, standards, and guidance.
  • Demonstrated experience protecting Protected A, Protected B, or classified information.
  • Experience developing and implementing enterprise security policies, standards, procedures, and governance frameworks.
  • Strong expertise in information classification, security markings, metadata tagging, and sensitivity labelling.
  • Experience managing risks associated with information sharing involving third parties, suppliers, financial institutions, or external partners.
  • Knowledge of encryption, identity and access management, secure transmission, data loss prevention, records management, retention, and secure disposal practices.
  • Experience researching and benchmarking security practices across government and highly regulated environments.
  • Hands-on familiarity with Microsoft 365 security and compliance technologies, including:
    • Microsoft Purview
    • Microsoft Information Protection (MIP)
    • Sensitivity Labels
    • Data Loss Prevention (DLP)
    • Information Rights Management (IRM)
  • Excellent stakeholder management, executive communication, policy development, and implementation skills.

Preferred Qualifications

  • Experience within the Government of Canada, Crown corporations, or other highly regulated organizations.
  • Professional certifications such as CISSP, CISM, CRISC, CGEIT, or relevant Microsoft Security certifications.
  • Experience leading enterprise-wide information protection and governance initiatives.

Partager un emploi :

Foire aux questions