Enter a job title or keyword

Executive Information Security Governance and Policy Consultant

Nexasphere


Job Location:

Ottawa - Canada

Monthly Salary: Not provided by the employer
Posted: 19 September 2026 (15 hours ago)
Application Deadline: 17 December 2026
Vacancies: 1 Vacancy

Job Summary

Executive Information Security Governance and Policy Consultant

Location: Ottawa (Hybrid/Remote)
Duration: 6 Months
Security Clearance: Secret security clearance

Overview

Our client is seeking a Senior Executive Information Security Governance and Policy Consultant to lead the assessment design and implementation of a comprehensive information protection framework for sensitive government information.

This strategic advisory role requires deep expertise in information security information governance risk management and policy development with a strong understanding of Government of Canada security requirements. The successful consultant will help establish processes controls and governance standards to ensure the secure handling of Protected A and Protected B information throughout its lifecycle including when shared with external organizations.

Key Responsibilities

  • Assess current information security governance and information management practices.
  • Review and analyze how sensitive information is classified labelled transmitted shared stored retained and securely disposed of.
  • Research Government of Canada security policies directives standards and industry best practices.
  • Conduct benchmarking activities across federal organizations Crown corporations financial institutions and other regulated sectors.
  • Identify gaps risks and opportunities for improving information protection practices.
  • Develop or enhance information classification and sensitivity-labelling frameworks.
  • Define security controls associated with information classification levels.
  • Establish requirements for security markings metadata tagging encryption access controls audit logging retention and secure disposal.
  • Assess technology capabilities supporting automated classification data loss prevention (DLP) information protection and secure external information sharing.
  • Provide recommendations related to Microsoft Purview Microsoft Information Protection sensitivity labels rights management and related security capabilities.
  • Develop policies standards procedures governance models and third-party information-sharing requirements.
  • Create implementation roadmaps training materials and executive-level recommendations.
  • Support the rollout and operationalization of approved frameworks policies and controls.

Deliverables

Potential deliverables include:

  • Current-state assessment and gap analysis
  • Research and benchmarking report
  • Information classification and sensitivity-labelling framework
  • Protected information handling standards
  • Secure external information-sharing policies and procedures
  • Third-party information protection requirements and guidance
  • Technology assessment and recommendations
  • Implementation roadmap and change management plan
  • Training and awareness materials
  • Executive briefings and final recommendations

Required Experience

The ideal candidate will possess:

  • Executive-level consulting experience in information security information governance cybersecurity or enterprise risk management.
  • In-depth knowledge of Government of Canada security policies directives standards and guidance.
  • Demonstrated experience protecting Protected A Protected B or classified information.
  • Experience developing and implementing enterprise security policies standards procedures and governance frameworks.
  • Strong expertise in information classification security markings metadata tagging and sensitivity labelling.
  • Experience managing risks associated with information sharing involving third parties suppliers financial institutions or external partners.
  • Knowledge of encryption identity and access management secure transmission data loss prevention records management retention and secure disposal practices.
  • Experience researching and benchmarking security practices across government and highly regulated environments.
  • Hands-on familiarity with Microsoft 365 security and compliance technologies including:
    • Microsoft Purview
    • Microsoft Information Protection (MIP)
    • Sensitivity Labels
    • Data Loss Prevention (DLP)
    • Information Rights Management (IRM)
  • Excellent stakeholder management executive communication policy development and implementation skills.

Preferred Qualifications

  • Experience within the Government of Canada Crown corporations or other highly regulated organizations.
  • Professional certifications such as CISSP CISM CRISC CGEIT or relevant Microsoft Security certifications.
  • Experience leading enterprise-wide information protection and governance initiatives.