Executive Information Security Governance and Policy Consultant
Job Summary
Executive Information Security Governance and Policy Consultant
Location: Ottawa (Hybrid/Remote)
Duration: 6 Months
Security Clearance: Secret security clearance
Overview
Our client is seeking a Senior Executive Information Security Governance and Policy Consultant to lead the assessment design and implementation of a comprehensive information protection framework for sensitive government information.
This strategic advisory role requires deep expertise in information security information governance risk management and policy development with a strong understanding of Government of Canada security requirements. The successful consultant will help establish processes controls and governance standards to ensure the secure handling of Protected A and Protected B information throughout its lifecycle including when shared with external organizations.
Key Responsibilities
- Assess current information security governance and information management practices.
- Review and analyze how sensitive information is classified labelled transmitted shared stored retained and securely disposed of.
- Research Government of Canada security policies directives standards and industry best practices.
- Conduct benchmarking activities across federal organizations Crown corporations financial institutions and other regulated sectors.
- Identify gaps risks and opportunities for improving information protection practices.
- Develop or enhance information classification and sensitivity-labelling frameworks.
- Define security controls associated with information classification levels.
- Establish requirements for security markings metadata tagging encryption access controls audit logging retention and secure disposal.
- Assess technology capabilities supporting automated classification data loss prevention (DLP) information protection and secure external information sharing.
- Provide recommendations related to Microsoft Purview Microsoft Information Protection sensitivity labels rights management and related security capabilities.
- Develop policies standards procedures governance models and third-party information-sharing requirements.
- Create implementation roadmaps training materials and executive-level recommendations.
- Support the rollout and operationalization of approved frameworks policies and controls.
Deliverables
Potential deliverables include:
- Current-state assessment and gap analysis
- Research and benchmarking report
- Information classification and sensitivity-labelling framework
- Protected information handling standards
- Secure external information-sharing policies and procedures
- Third-party information protection requirements and guidance
- Technology assessment and recommendations
- Implementation roadmap and change management plan
- Training and awareness materials
- Executive briefings and final recommendations
Required Experience
The ideal candidate will possess:
- Executive-level consulting experience in information security information governance cybersecurity or enterprise risk management.
- In-depth knowledge of Government of Canada security policies directives standards and guidance.
- Demonstrated experience protecting Protected A Protected B or classified information.
- Experience developing and implementing enterprise security policies standards procedures and governance frameworks.
- Strong expertise in information classification security markings metadata tagging and sensitivity labelling.
- Experience managing risks associated with information sharing involving third parties suppliers financial institutions or external partners.
- Knowledge of encryption identity and access management secure transmission data loss prevention records management retention and secure disposal practices.
- Experience researching and benchmarking security practices across government and highly regulated environments.
- Hands-on familiarity with Microsoft 365 security and compliance technologies including:
- Microsoft Purview
- Microsoft Information Protection (MIP)
- Sensitivity Labels
- Data Loss Prevention (DLP)
- Information Rights Management (IRM)
- Excellent stakeholder management executive communication policy development and implementation skills.
Preferred Qualifications
- Experience within the Government of Canada Crown corporations or other highly regulated organizations.
- Professional certifications such as CISSP CISM CRISC CGEIT or relevant Microsoft Security certifications.
- Experience leading enterprise-wide information protection and governance initiatives.