03 Sep
|
blueAPACHE
|
Queensland
03 Sep
blueAPACHE
Queensland
About Us
blueAPACHE is an Australian owned award-winning Managed Service Provider, recognised for the 7th year running as Mid-Market Partner of the Year at the ARN Innovation Awards. We pride ourselves on being a genuinely outstanding place to work, with a vibrant culture, clear vision and strong leadership. When joining blueAPACHE, you are joining an organisation driven by our core values and a commitment to employee and customer experience. We are proud to be an equal opportunity employer and are committed to building a diverse and inclusive workplace where we embrace our individual talents and differences. This is a rare opportunity to join blueAPACHE as Practice Lead, GRC, at a pivotal stage in our growth journey. You will lead an established and respected practice with a strong customer base and proven market presence. Leveraging this solid foundation, you will be empowered to drive the next phase of growth, shape our service strategy, develop new offerings, and position the practice as a market leader in governance, risk, and compliance services.
Position Purpose
The Practice Lead, Governance, Risk and Compliance is responsible for leading, operating and growing blueAPACHE's GRC business unit. The practice delivers recurring, subscription-based fractional virtual Chief Information Security Officer (vCISO) and GRC advisory services to managed service customers. The role owns the practice's strategy, commercial performance, service proposition, customer outcomes, delivery quality, people capability and operational discipline. It ensures subscribed customers receive proactive and measurable security governance aligned with their business priorities, risk profile, regulatory obligations and target maturity. The Practice Lead will also act as a senior trusted advisor for selected strategic customers, engaging with executives, boards,
risk committees and technology leaders to translate cyber risk into clear decisions and prioritised improvement programs.
Essential
- Significant experience in information security governance, cyber risk, compliance or security advisory services.
- Demonstrated experience leading a GRC, cyber advisory, consulting or professional services function.
- Experience providing CISO, virtual CISO or senior security advisory services to customers.
- Strong knowledge of cyber governance, enterprise risk, security controls, compliance and assurance environments.
- Experience developing security strategies, risk registers, maturity assessments and improvement roadmaps.
- Experience advising executives, boards, risk committees or other senior stakeholders.
- Demonstrated commercial management experience, including budgeting, forecasting, scope, utilisation and practice performance.
- Experience leading, coaching and developing consultants or security professionals.
- Excellent facilitation, written communication, presentation and stakeholder management skills.
- Ability to translate complex technical and regulatory matters into clear business implications and decisions.
- Strong professional judgement, integrity and discretion, with the ability to manage competing priorities across multiple customers.
- Highly Desirable Experience delivering recurring or subscription-based security advisory services within an MSP or managed security environment.
- Experience supporting mid‑market and enterprise organisations.
- Relevant certifications such as CISM, CISSP, CRISC, CISA or equivalent.
- Experience supporting security assurance, audit readiness or certification programs.
- Experience in third‑party risk, cloud governance, privacy, data governance or operational resilience.
- Tertiary qualifications in information security, technology, risk, business or a related discipline.
- Experience in service design, solution development and go-to-market activity.
Personal Attributes
- Think strategically while maintaining strong execution discipline.
- Takes ownership of practice, commercial and customer outcomes.
- Communicates with confidence and credibility at executive level.
- Balances risk, compliance, customer experience and commercial realities.
- Constructively challenges assumptions and communicates difficult messages.
- Builds trust through consistent delivery and transparent communication.
- Develops others and creates accountability without unnecessary dependency.
- Remains curious and current in a rapidly evolving security environment.
- Demonstrates a genuine commitment to customer success and blueAPACHE's values.
Key Accountabilities
Key Accountabilities 1. Practice Strategy and Leadership Define and execute the strategic direction, operating model and growth plan for the GRC practice. Establish annual and quarterly priorities for recurring revenue, margin, customer growth, service development, delivery capacity and operational improvement. Maintain a forward‑looking roadmap that responds to customer demand, changing regulation, emerging threats and market expectations. Represent the practice in leadership, planning, forecasting, service governance and go‑to‑market f
#J-18808-Ljbffr
📌 Practice Lead - GRC (Queensland)
🏢 blueAPACHE
📍 Queensland