Governance, Risk & Compliance Specialist
moving to Head of GRC
London NW6 - hybrid
To £80k + benefits
GRC Specialist - moving to Head of GRC - overview
This is a new role with one one our regular clients, a well-established, award-winning IT Managed Services provider, recognised as one of the fastest-growing MSPs in the country.
The company has always prided itself on progressing staff through the ranks but they're excelling themselves in this instance: they are hiring someone who can specialise in an emerging part of their business and who will ultimately be given the chance to build a practice around them.
This is a fantastic opportunity for someone who's built up expertise in Governance, Risk and Compliance and sees themselves heading a function within a year or two.
GRC Specialist - moving to Head of GRC - background
The company has been around for 20+ years and has a tremendous track record as a Microsoft-centric IT MSP, with more than 300 clients from a wide range of sectors.
The business has seen growing demand for GRC-related services. These include Cyber Essentials, Cyber Essentials Plus, ISO 27001, GDPR and Data Protection compliance, compliance in regulated sectors, BC and DR planning, vCISO assignments and AI governance.
The company has developed a thorough Cyber Security Framework, is launching a Complance-as-a-Service offering, has various relevant technical partnerships and capabilities in-house. However, the potential to scale the GRC offering goes beyond the capacity of the current team. Hence, the business wants to hire a dedicated GRC specialist who has the desire and potential to grow out a soecialist business unit.
GRC Specialist - moving to Head of GRC - duties
Currently, this role is effectively undertaken by the CEO, CTO and Head of Sales. The first twelve months in the role will focus on assuming an increasing amount of responsibility for GRC consulting activities from these three. This will be a very supportive process, engaging mainly with long-standing clients and ensuring that the positioning of GRC services, or delivery of GRC assignments, is well aligned to the company's established ways of working and dovetails well with existing relationships.
A more detailed summary of the duties looks like this: -
-
Client Compliance & Governance engagements including Compliance as a Service
-
Conduct governance reviews, maturity assessments, compliance audits
-
Develop & maintain client risk registers, remediation plans, governance frameworks
-
Produce governance roadmaps
-
Lead compliance workshops
-
Virtual CISO services
-
Develop client cyber security & governance strategies
-
Board-level security & risk reporting
-
Risk Management, Supplier Assurance & third-party risk assessment & mitigation
-
Lead client Operational Resilience, Business Continuity and Disaster Recovery programmes
-
Provide expert advice on compliance frameworks & regulatory issues
-
Develop and advise on AI governance frameworks
-
Work closely with internal technical team to align compliance requirements with security controls
-
Work closely with the sales team to support the sale of CaaS service to new and existing clients
-
Take lead role in supporting internal governance.
Ultimately, as incoming Head of GRC, the following responsibilities will be added: -
-
Establish GRC practice including fully implemented governance and compliance roadmap
-
Grow Compliance revenue in line with agreed targets
-
Increase CaaS adoption amongst client base
-
Increase compliance maturity among client base
-
Maintain and improve certification levels
-
Develop new governance and compliance services
-
Develop and deliver relevant GRC thought-leadership content
-
Develop multi-year roadmap for GRC business
-
Own the performance, development and direction of the GRC practice
-
Support the recruitment of required resources as the practice expands
GRC Specialist - moving to Head of GRC - requirements
The fundamental requirements are as follows.
-
Experience in Governance, Risk & Compliance, Information Security, Audit or Risk Management
-
Experience of conducting audits, compliance reviews, governance assessments
-
Good knowledge of Cyber Essentials/Plus, GDPR, Data Protection
-
Experience presenting to senior stakeholders
-
Excellent communication skills
-
Strong commercial awareness, with the potential to progress into a leadership role
-
A passion for helping organisations with their governance, security and resilience.
If you have any of the following, that would be a bonus: -
-
ISO 27001 Lead Auditor or Lead Implementer
-
CISSP, CRISC, CISM, CISMP or equivalent
-
Experience of delivering vCISO services
-
Knowledge of NIST CSF, CAF, DSPT
-
Knowledge of Microsoft 365 security and compliance tools
-
Experience in an MSP environment
Other info...
The salary is shown at the top of the page and represents the entry-point for someone who can come in and grow into the more senior role.
The working pattern is hybrid, with 3 days in the office per week. It's likely that you'll spend more time in the office in the early days in the interests of a thorough and supportive onboarding process.
Interested?
For more info or to apply, please contact steve@nemoresourcing.co.uk, 01438 419777