Practice Lead - GRC
Summary
Leads the GRC business unit, delivering vCISO and advisory services, managing strategy, finances, and a team of consultants.
What they ask for
Required
- Significant experience in information security governance, cyber risk, compliance or security advisory services.
- Demonstrated experience leading a GRC, cyber advisory, consulting or professional services function.
- Experience providing CISO, virtual CISO or senior security advisory services to customers.
- Strong knowledge of cyber governance, enterprise risk, security controls, compliance and assurance environments.
- Experience developing security strategies, risk registers, maturity assessments and improvement roadmaps.
- Experience advising executives, boards, risk committees or other senior stakeholders.
- Demonstrated commercial management experience, including budgeting, forecasting, scope, utilisation and practice performance.
- Experience leading, coaching and developing consultants or security professionals.
- Excellent facilitation, written communication, presentation and stakeholder management skills.
- Ability to translate complex technical and regulatory matters into clear business implications and decisions.
- Strong professional judgement, integrity and discretion, with the ability to manage competing priorities across multiple customers.
Preferred
- Experience delivering recurring or subscription-based security advisory services within an MSP or managed security environment.
- Experience supporting mid-market and enterprise organisations.
- Relevant certifications such as CISM, CISSP, CRISC, CISA or equivalent.
- Experience supporting security assurance, audit readiness or certification programs.
- Experience in third-party risk, cloud governance, privacy, data governance or operational resilience.
- Tertiary qualifications in information security, technology, risk, business or a related discipline.
- Experience in service design, solution development and go-to-market activity.