Role Overview
NetworkSharks is seeking a Senior Cybersecurity Consultant to join our advisory practice. In this role, you will lead cybersecurity assessments, maturity reviews, and strategic advisory engagements for clients in regulated and high-consequence sectors — primarily federal and provincial government agencies, energy companies, and critical infrastructure operators across Canada.
This is not a generalist role. Our clients expect depth. You will be expected to lead client engagements independently, facilitate workshops with senior stakeholders, produce high-quality deliverables, and advise on complex security architecture and control design decisions. You will work directly alongside our technical and advisory leadership on engagements that carry real operational and regulatory weight.
Key Responsibilities
- Lead end-to-end cybersecurity assessments including maturity reviews, control gap analysis, and risk assessments across enterprise IT environments
- Map client environments to frameworks including NIST CSF, NIST SP 800-53, ISO/IEC 27001, IEC 62443, CIS Controls, and NERC CIP
- Develop detailed security roadmaps, remediation plans, and prioritized treatment strategies aligned to business risk and regulatory context
- Advise on security architecture and control design across identity, endpoint, network, cloud, and monitoring domains
- Facilitate stakeholder interviews, technical workshops, and executive-level briefings
- Support incident response readiness assessments and tabletop exercise design and facilitation
- Develop and review security policies, standards, procedures, and governance documentation
- Advise on vCISO-level security program strategy for organizations building or maturing their security function
- Produce high-quality consulting deliverables — assessment reports, architecture recommendations, risk registers, and presentations
- Support business development activities including proposal development and client scoping
Required Technical Skills
- Deep knowledge of cybersecurity frameworks: NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls v8
- Experience with SIEM platforms (Microsoft Sentinel, Splunk), EDR/XDR (CrowdStrike, Microsoft Defender), and SOAR
- Working knowledge of IAM, PAM, and MFA architecture — including CyberArk, Entra ID, Okta, and BeyondTrust
- Understanding of network security architecture — NGFW (Palo Alto, Fortinet, Cisco), segmentation, Zero Trust, and secure remote access
- Familiarity with vulnerability management platforms (Tenable, Qualys, Rapid7)
- Experience assessing cloud environments, particularly Microsoft Azure and Microsoft 365
- Understanding of OT/ICS environments and the specific constraints of industrial security (IEC 62443, NIST SP 800-82) is an asset
Preferred Qualifications
- CISSP, CISM, CISA, or equivalent senior-level certification
- Experience delivering engagements in government or regulated energy sector environments
- Familiarity with ITSG-33, GC Security Policy, and Protected B/C classification requirements
- Experience supporting audit preparation, evidence collection, and regulatory review processes
- Prior consulting or advisory firm experience
Experience Requirements
- Minimum 6 years of cybersecurity experience with at least 3 years in a consulting or advisory capacity
- Demonstrated experience leading client-facing engagements and managing senior stakeholder relationships
- Track record of producing consulting-grade deliverables independently
Professional Competencies
- Excellent technical writing and documentation skills — reports must be clear, precise, and client-ready without heavy editing
- Strong executive communication and presentation skills
- Ability to facilitate structured workshops and interviews with technical and non-technical audiences
- High degree of professional judgment — able to work autonomously on complex engagements
- Collaborative working style within a small, high-performing team
What Success Looks Like
- You lead engagements from scoping through delivery with minimal oversight, producing deliverables that exceed client expectations
- Clients request you by name for follow-on work
- Your assessments identify issues that prior reviews missed, and your remediation roadmaps are adopted and implemented
- You are trusted by clients to advise at the CISO and executive level, not just the technical team
- You contribute to the firm's knowledge base and help develop junior consultants
Why Join NetworkSharks
NetworkSharks is a boutique firm with a deliberate client base. We work on complex, meaningful engagements for organizations where security failures have real-world consequences. There are no mandatory billable-hour metrics pushing you toward low-value work. Our team is small, highly capable, and trusted by clients who expect genuine expertise. If you are looking for a firm where your depth of knowledge is valued and your work has impact, this is the right place.