Haystack
← Back to Jobs
Full time
Other
BL

Practice Lead - GRC

blueAPACHESydney, Sydney🇦🇺AustraliaPosted 4 Sept 2026

Why This Role Stands Out

This hybrid Practice Lead role offers a fantastic opportunity to shape the future of GRC services at an award-winning company, empowering you to drive strategic growth and develop new offerings. You'll thrive here if you're a seasoned GRC professional eager to lead a respected practice, mentor a team, and act as a trusted advisor to executives. Apply to leverage your expertise and make a significant impact in a supportive and vibrant culture.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Sydney, Sydney, Australia
Account ManagementBudgetingComplianceContinuous ImprovementCustomer SuccessForecastingOnboardingSourcingStakeholder Management

Job Description

About Us blueAPACHE is an Australian owned award-winning Managed Service Provider, recognised for the 7th year running as Mid-Market Partner of the Year at the ARN Innovation Awards.

We pride ourselves on being a genuinely great place to work, with a vibrant culture, clear vision and strong leadership. When joining blueAPACHE, you are joining an organisation driven by our core values and a commitment to employee and customer experience.

We are proud to be an equal opportunity employer and are committed to building a diverse and inclusive workplace where we embrace our individual talents and differences.

This is a rare opportunity to join blueAPACHE as Practice Lead, GRC, at a pivotal stage in our growth journey. You will lead an established and respected practice with a strong customer base and proven market presence. Leveraging this solid foundation, you will be empowered to drive the next phase of growth, shape our service strategy, develop new offerings, and position the practice as a market leader in governance, risk, and compliance services.

Position Purpose The Practice Lead, Governance, Risk and Compliance is responsible for leading, operating and growing blueAPACHE's GRC business unit. The practice delivers recurring, subscription-based fractional virtual Chief Information Security Officer (vCISO) and GRC advisory services to managed service customers.

The role owns the practice's strategy, commercial performance, service proposition, customer outcomes, delivery quality, people capability and operational discipline. It ensures subscribed customers receive proactive and measurable security governance aligned with their business priorities, risk profile, regulatory obligations and target maturity.

The Practice Lead will also act as a senior trusted advisor for selected strategic customers, engaging with executives, boards, risk committees and technology leaders to translate cyber risk into clear decisions and prioritised improvement programs.

Essential
  • Significant experience in information security governance, cyber risk, compliance or security advisory services.
  • Demonstrated experience leading a GRC, cyber advisory, consulting or professional services function.
  • Experience providing CISO, virtual CISO or senior security advisory services to customers.
  • Strong knowledge of cyber governance, enterprise risk, security controls, compliance and assurance environments.
  • Experience developing security strategies, risk registers, maturity assessments and improvement roadmaps.
  • Experience advising executives, boards, risk committees or other senior stakeholders.
  • Demonstrated commercial management experience, including budgeting, forecasting, scope, utilisation and practice performance.
  • Experience leading, coaching and developing consultants or security professionals.
  • Excellent facilitation, written communication, presentation and stakeholder management skills.
  • Ability to translate complex technical and regulatory matters into clear business implications and decisions.
  • Strong professional judgement, integrity and discretion, with the ability to manage competing priorities across multiple customers.
Highly Desirable
  • Experience delivering recurring or subscription-based security advisory services within an MSP or managed security environment.
  • Experience supporting mid market and enterprise organisations.
  • Relevant certifications such as CISM, CISSP, CRISC, CISA or equivalent.
  • Experience supporting security assurance, audit readiness or certification programs.
  • Experience in third party risk, cloud governance, privacy, data governance or operational resilience.
  • Tertiary qualifications in information security, technology, risk, business or a related discipline.
  • Experience in service design, solution development and go to market activity.
Personal Attributes
  • Thinks strategically while maintaining strong execution discipline.
  • Takes ownership of practice, commercial and customer outcomes.
  • Communicates with confidence and credibility at executive level.
  • Balances risk, compliance, customer experience and commercial realities.
  • Constructively challenges assumptions and communicates difficult messages.
  • Builds trust through consistent delivery and transparent communication.
  • Develops others and creates accountability without unnecessary dependency.
  • Remains curious and current in a rapidly evolving security environment.
  • Demonstrates a genuine commitment to customer success and blueAPACHE's values.
Key Accountabilities 1. Practice Strategy and Leadership
  • Define and execute the strategic direction, operating model and growth plan for the GRC practice.
  • Establish annual and quarterly priorities for recurring revenue, margin, customer growth, service development, delivery capacity and operational improvement.
  • Maintain a forward looking roadmap that responds to customer demand, changing regulation, emerging threats and market expectations.
  • Represent the practice in leadership, planning, forecasting, service governance and go to market forums.
  • Align the practice with blueAPACHE's managed services, security, cloud, technology and customer strategy.
  • Model a culture of accountability, technical excellence, trust, collaboration and care.
2. Commercial and Financial Management
  • Own practice revenue, gross margin, operating costs, utilisation, recurring subscription performance and overall contribution.
  • Build and maintain the practice budget, forecast, pipeline view and capacity plan.
  • Define commercially sustainable service packaging, inclusions, pricing and scope boundaries.
  • Monitor performance and take timely corrective action where commercial, delivery or customer outcomes fall below plan.
  • Partner with Sales and Account Management to support qualification, proposals, tenders, renewals, expansion and cross sell opportunities.
  • Ensure commitments made during the sales process are deliverable, appropriately scoped and commercially responsible.
3. Fractional vCISO Service Ownership
  • Own the design, development and continuous improvement of the subscription based fractional vCISO service.
  • Define a consistent customer journey from discovery and onboarding through governance, assessment, roadmap execution, executive reporting and renewal.
  • Establish service tiers, deliverables, engagement cadences, templates, reporting standards, quality controls and service measures.
  • Ensure each subscribed customer has a current governance plan aligned to its service subscription, business context and risk profile.
  • Ensure the service remains proactive and outcome led rather than operating only as a reactive compliance or documentation function.
  • Identify opportunities to standardise and automate repeatable assessment, evidence, workflow and reporting activities.
4. Customer Security Governance and Strategy
  • Establish and maintain effective customer security governance structures, forums, accountabilities, decision rights and escalation pathways.
  • Facilitate security steering committees, executive risk discussions and recurring customer governance meetings.
  • Develop customer information security strategies, target maturity positions and prioritised multi period roadmaps.
  • Ensure roadmaps are practical, financially considered and aligned to customer budgets, operating capability and technology plans.
  • Maintain visibility of customer initiatives, risks, dependencies, decisions, overdue actions and required executive support.
  • Provide clear reporting on posture, risk, compliance, roadmap progress and decisions required.
5. Risk, Compliance and Assurance
  • Lead or oversee cyber and information security risk assessments, maturity reviews, control assessments and compliance gap analyses.
  • Establish and maintain customer security risk registers with clear ownership, treatment decisions and review cycles.
  • Translate technical vulnerabilities and control weaknesses into understandable business risk and impact statements.
  • Guide customers in applying security and risk frameworks appropriate to their industry, size, obligations and operating environment.
  • Develop practical remediation plans, policies, standards, procedures and governance artefacts.
  • Support audit readiness, certification activities, customer assurance requests and evidence management while maintaining clear professional boundaries.
  • Ensure advice is evidence based and does not represent a customer as compliant without appropriate substantiation.
6. Executive and Board Advisory
  • Act as a trusted advisor to customer executives, boards, risk committees and technology leaders.
  • Present complex security matters in concise, commercially relevant and non technical language.
  • Produce executive reporting covering material risks, security posture, compliance, incidents, roadmap progress and required decisions.
  • Support informed decisions about risk appetite, security investment, strategic priorities and formal risk acceptance.
  • Provide objective advice during material technology, sourcing, transformation and organisational change initiatives.
  • Communicate difficult findings constructively, with sound judgement, independence, integrity and discretion.
7. Incident Preparedness and Response Advisory
  • Ensure customers maintain proportionate cyber incident response, crisis management . click apply for full job details

Similar jobs