Executive Information Security Governance and Policy Consultant at Nexasphere — NeverHard
Executive Information Security Governance and Policy Consultant at Nexasphere in Ottawa, Ottawa region. Skills: Government Security Standards, Information Security, Policy Development, Risk Management, information governance. Apply on NeverHard.
Company
Nexasphere
Location
Ottawa, Ottawa region
Type
contract
Required skills:
Government Security Standards
Information Security
Policy Development
Risk Management
information governance
information management
Executive Information Security Governance and Policy Consultant
Location:
Ottawa (Hybrid/Remote)
Duration:
6 Months
Security Clearance:
Secret security clearance
Overview
Our client is seeking a
Senior Executive Information Security Governance and Policy Consultant
to lead the assessment, design, and implementation of a comprehensive information protection framework for sensitive government information.
This strategic advisory role requires deep expertise in
information security, information governance, risk management, and policy development
, with a strong understanding of Government of Canada security requirements. The successful consultant will help establish processes, controls, and governance standards to ensure the secure handling of
Protected A and Protected B information
throughout its lifecycle, including when shared with external organizations.
Key Responsibilities
Assess current information security, governance, and information management practices.
Review and analyze how sensitive information is classified, labelled, transmitted, shared, stored, retained, and securely disposed of.
Research Government of Canada security policies, directives, standards, and industry best practices.
Conduct benchmarking activities across federal organizations, Crown corporations, financial institutions, and other regulated sectors.
Identify gaps, risks, and opportunities for improving information protection practices.
Develop or enhance information classification and sensitivity-labelling frameworks.
Define security controls associated with information classification levels.
Establish requirements for security markings, metadata tagging, encryption, access controls, audit logging, retention, and secure disposal.
Assess technology capabilities supporting automated classification, data loss prevention (DLP), information protection, and secure external information sharing.
Provide recommendations related to Microsoft Purview, Microsoft Information Protection, sensitivity labels, rights management, and related security capabilities.
Develop policies, standards, procedures, governance models, and third-party information-sharing requirements.
Create implementation roadmaps, training materials, and executive-level recommendations.
Support the rollout and operationalization of approved frameworks, policies, and controls.
Deliverables
Potential deliverables include:
Current-state assessment and gap analysis
Research and benchmarking report
Information classification and sensitivity-labelling framework
Protected information handling standards
Secure external information-sharing policies and procedures
Third-party information protection requirements and guidance
Technology assessment and recommendations
Implementation roadmap and change management plan
Training and awareness materials
Executive briefings and final recommendations
Required Experience
The ideal candidate will possess:
Executive-level consulting experience in information security, information governance, cybersecurity, or enterprise risk management.
In-depth knowledge of Government of Canada security policies, directives, standards, and guidance.
Demonstrated experience protecting Protected A, Protected B, or classified information.
Experience developing and implementing enterprise security policies, standards, procedures, and governance frameworks.
Strong expertise in information classification, security markings, metadata tagging, and sensitivity labelling.
Experience managing risks associated with information sharing involving third parties, suppliers, financial institutions, or external partners.
Knowledge of encryption, identity and access management, secure transmission, data loss prevention, records management, retention, and secure disposal practices.
Experience researching and benchmarking security practices across government and highly regulated environments.
Hands-on familiarity with Microsoft 365 security and compliance technologies, including:
Microsoft Purview
Microsoft Information Protection (MIP)
Sensitivity Labels
Data Loss Prevention (DLP)
Information Rights Management (IRM)
Excellent stakeholder management, executive communication, policy development, and implementation skills.
Preferred Qualifications
Experience within the Government of Canada, Crown corporations, or other highly regulated organizations.
Professional certifications such as CISSP, CISM, CRISC, CGEIT, or relevant Microsoft Security certifications.
Experience leading enterprise-wide information protection and governance initiatives.