Practice Lead - GRC
About Us
blueAPACHE is an Australian owned award-winning Managed Service Provider, recognised for the 7th year running as Mid-Market Partner of the Year at the ARN Innovation Awards.
We pride ourselves on being a genuinely great place to work, with a vibrant culture, clear vision and strong leadership. When joining blueAPACHE, you are joining an organisation driven by our core values and a commitment to employee and customer experience.
We are proud to be an equal opportunity employer and are committed to building a diverse and inclusive workplace where we embrace our individual talents and differences.
This is a rare opportunity to join blueAPACHE as Practice Lead, GRC, at a pivotal stage in our growth journey. You will lead an established and respected practice with a strong customer base and proven market presence. Leveraging this solid foundation, you will be empowered to drive the next phase of growth, shape our service strategy, develop new offerings, and position the practice as a market leader in governance, risk, and compliance services.
Position Purpose
The Practice Lead, Governance, Risk and Compliance is responsible for leading, operating and growing blueAPACHE’s GRC business unit. The practice delivers recurring, subscription-based fractional virtual Chief Information Security Officer (vCISO) and GRC advisory services to managed service customers.
The role owns the practice’s strategy, commercial performance, service proposition, customer outcomes, delivery quality, people capability and operational discipline. It ensures subscribed customers receive proactive and measurable security governance aligned with their business priorities, risk profile, regulatory obligations and target maturity.
The Practice Lead will also act as a senior trusted advisor for selected strategic customers, engaging with executives, boards, risk committees and technology leaders to translate cyber risk into clear decisions and prioritised improvement programs.
Essential
- Significant experience in information security governance, cyber risk, compliance or security advisory services.
- Demonstrated experience leading a GRC, cyber advisory, consulting or professional services function.
- Experience providing CISO, virtual CISO or senior security advisory services to customers.
- Strong knowledge of cyber governance, enterprise risk, security controls, compliance and assurance environments.
- Experience developing security strategies, risk registers, maturity assessments and improvement roadmaps.
- Experience advising executives, boards, risk committees or other senior stakeholders.
- Demonstrated commercial management experience, including budgeting, forecasting, scope, utilisation and practice performance.
- Experience leading, coaching and developing consultants or security professionals.
- Excellent facilitation, written communication, presentation and stakeholder management skills.
- Ability to translate complex technical and regulatory matters into clear business implications and decisions.
- Strong professional judgement, integrity and discretion, with the ability to manage competing priorities across multiple customers.
Highly Desirable
- Experience delivering recurring or subscription-based security advisory services within an MSP or managed security environment.
- Experience supporting mid-market and enterprise organisations.
- Relevant certifications such as CISM, CISSP, CRISC, CISA or equivalent.
- Experience supporting security assurance, audit readiness or certification programs.
- Experience in third-party risk, cloud governance, privacy, data governance or operational resilience.
- Tertiary qualifications in information security, technology, risk, business or a related discipline.
- Experience in service design, solution development and go-to-market activity.
Personal Attributes
- Thinks strategically while maintaining strong execution discipline.
- Takes ownership of practice, commercial and customer outcomes.
- Communicates with confidence and credibility at executive level.
- Balances risk, compliance, customer experience and commercial realities.
- Constructively challenges assumptions and communicates difficult messages.
- Builds trust through consistent delivery and transparent communication.
- Develops others and creates accountability without unnecessary dependency.
- Remains curious and current in a rapidly evolving security environment.
- Demonstrates a genuine commitment to customer success and blueAPACHE’s values.
Key Accountabilities
1. Practice Strategy and Leadership
- Define and execute the strategic direction, operating model and growth plan for the GRC practice.
- Establish annual and quarterly priorities for recurring revenue, margin, customer growth, service development, delivery capacity and operational improvement.
- Maintain a forward-looking roadmap that responds to customer demand, changing regulation, emerging threats and market expectations.
- Represent the practice in leadership, planning, forecasting, service governance and go-to-market forums.
- Align the practice with blueAPACHE’s managed services, security, cloud, technology and customer strategy.
- Model a culture of accountability, technical excellence, trust, collaboration and care.
2. Commercial and Financial Management
- Own practice revenue, gross margin, operating costs, utilisation, recurring subscription performance and overall contribution.
- Build and maintain the practice budget, forecast, pipeline view and capacity plan.
- Define commercially sustainable service packaging, inclusions, pricing and scope boundaries.
- Monitor performance and take timely corrective action where commercial, delivery or customer outcomes fall below plan.
- Partner with Sales and Account Management to support qualification, proposals, tenders, renewals, expansion and cross-sell opportunities.
- Ensure commitments made during the sales process are deliverable, appropriately scoped and commercially responsible.
3. Fractional vCISO Service Ownership
- Own the design, development and continuous improvement of the subscription-based fractional vCISO service.
- Define a consistent customer journey from discovery and onboarding through governance, assessment, roadmap execution, executive reporting and renewal.
- Establish service tiers, deliverables, engagement cadences, templates, reporting standards, quality controls and service measures.
- Ensure each subscribed customer has a current governance plan aligned to its service subscription, business context and risk profile.
- Ensure the service remains proactive and outcome-led rather than operating only as a reactive compliance or documentation function.
- Identify opportunities to standardise and automate repeatable assessment, evidence, workflow and reporting activities.
4. Customer Security Governance and Strategy
- Establish and maintain effective customer security governance structures, forums, accountabilities, decision rights and escalation pathways.
- Facilitate security steering committees, executive risk discussions and recurring customer governance meetings.
- Develop customer information security strategies, target maturity positions and prioritised multi-period roadmaps.
- Ensure roadmaps are practical, financially considered and aligned to customer budgets, operating capability and technology plans.
- Maintain visibility of customer initiatives, risks, dependencies, decisions, overdue actions and required executive support.
- Provide clear reporting on posture, risk, compliance, roadmap progress and decisions required.
5. Risk, Compliance and Assurance
- Lead or oversee cyber and information security risk assessments, maturity reviews, control assessments and compliance gap analyses.
- Establish and maintain customer security risk registers with clear ownership, treatment decisions and review cycles.
- Translate technical vulnerabilities and control weaknesses into understandable business risk and impact statements.
- Guide customers in applying security and risk frameworks appropriate to their industry, size, obligations and operating environment.
- Develop practical remediation plans, policies, standards, procedures and governance artefacts.
- Support audit readiness, certification activities, customer assurance requests and evidence management while maintaining clear professional boundaries.
- Ensure advice is evidence-based and does not represent a customer as compliant without appropriate substantiation.
6. Executive and Board Advisory
- Act as a trusted advisor to customer executives, boards, risk committees and technology leaders.
- Present complex security matters in concise, commercially relevant and non-technical language.
- Produce executive reporting covering material risks, security posture, compliance, incidents, roadmap progress and required decisions.
- Support informed decisions about risk appetite, security investment, strategic priorities and formal risk acceptance.
- Provide objective advice during material technology, sourcing, transformation and organisational change initiatives.
- Communicate difficult findings constructively, with sound judgement, independence, integrity and discretion.
7. Incident Preparedness and Response Advisory
- Ensure customers maintain proportionate cyber incident response, crisis management, escalation and communication arrangements.
- Coordinate or oversee incident simulations, executive exercises and post-incident reviews.
- Provide governance and executive advisory support during significant security incidents.
- Help coordinate relevant customer stakeholders and technical, legal, insurance, communications or specialist providers.
- Ensure lessons and agreed actions are incorporated into risk registers, policies, roadmaps and awareness programs.
- Maintain a clear division between governance advice and the technical teams accountable for containment, investigation and remediation.
8. Third-Party and Supply Chain Risk
- Develop and oversee proportionate third-party security risk management approaches for customers.
- Help customers classify suppliers according to criticality, data access and potential business impact.
- Review material suppliers, cloud services and outsourced providers against defined security requirements.
- Support security questionnaires, control assessments, risk findings, remediation discussions and supplier governance.
- Ensure material third-party risks are documented, assigned, treated and reported through the customer’s governance structure.
9. Customer Experience and Relationship Management
- Take executive ownership of the customer experience delivered by the practice.
- Build trusted relationships with customer executives and senior stakeholders.
- Ensure engagements are proactive, structured, responsive and focused on measurable outcomes.
- Monitor customer satisfaction, service adoption, renewal risk, expansion opportunities and unresolved concerns.
- Address escalations promptly and demonstrate ongoing subscription value through outcomes rather than activity reporting alone.
- Partner with Account Management and Service Delivery to provide an integrated blueAPACHE customer experience.
10. Delivery Management and Quality Assurance
- Own the consistency, quality, timeliness and professional standard of all practice deliverables.
- Establish delivery methodologies, templates, review processes, approval thresholds and record-keeping standards.
- Allocate customer portfolios and project work based on capability, capacity, continuity and customer requirements.
- Maintain visibility of utilisation, workload, recurring obligations, delivery risk and forward demand.
- Review material strategies, assessments, risk reports and executive recommendations before release.
- Ensure consultants operate within their authority, competence and professional remit.
11. People Leadership and Capability
- Lead, coach and mentor GRC consultants, vCISO advisors, governance analysts and specialist resources.
- Set clear performance expectations, accountabilities, customer standards and development objectives.
- Build capability across governance, risk, compliance, consulting, executive communication and commercial awareness.
- Maintain workforce, succession, recruitment and certification plans aligned to the service roadmap and customer demand.
- Promote peer review, knowledge sharing, reusable intellectual property and sustainable portfolio management.
- Address performance or capability concerns promptly, fairly and constructively.
12. Market Development and Continuous Improvement
- Act as the senior GRC subject matter expert for customer, partner and market engagements.
- Develop clear propositions, outcome-based messaging, use cases, thought leadership and customer education content.
- Participate in strategic discovery sessions, presentations, events, webinars and relevant industry forums.
- Maintain awareness of competitor offerings, regulatory developments, customer expectations and adjacent service opportunities.
- Build and maintain the practice methodology, playbooks, templates and reusable intellectual property.
- Use service data, customer feedback and lessons learned to improve quality, efficiency, scalability and customer value.
Role Boundaries
The Practice Lead provides security governance, risk and strategic advisory services. The role does not independently provide legal opinions, regulatory determinations, audit certification or insurance advice unless appropriately qualified and expressly engaged to do so. Where specialist advice is required, the Practice Lead must identify the limitation and coordinate with the appropriate customer or external specialist.
blueAPACHE continues to grow alongside some of Australia’s leading midmarket businesses, our valued clients. We continue to stay abreast of current technologies to maintain our competitive advantage, offering the opportunity to continually expand your technical expertise and provide an uncompromising offering to our clients. We recognise our people are our most significant differentiator.
- An environment where you can make a real difference and develop your career within a supportive and rewarding team.
- Flexibility to work in a way aligned with our values of employee and customer experience, including a hybrid work-from-home model.
- Regular social events and the opportunity to work with experts in their field.
- Health insurance discount with Medibank.
- Discounts on thousands of products.
- Employee Assistance Program through The Mind Room.
- Ongoing training and development, including paid certifications.
- Quality hardware and laptop provided.
- Employee referral program.
- Amazing destinations for our annual blueSTAR experience.
Employment Conditions
- All offers of employment are subject to National Police Checking Service requirements.
- The position may require travel to customer sites and blueAPACHE locations.
- Participation in significant customer incidents or executive escalations may occasionally be required outside standard operating hours.
- Continued professional development and maintenance of relevant industry knowledge are expected.
*** Please note, all offers of employment at blueAPACHE are subject to National Police Checking Service.
Similar roles
GTM Compensation Lead, Commercial Operations
Notion·San Francisco, United States
WHO WE ARE Notion is the collaborative AI workspace where teams and agents think together https://www.youtube.com/watch?v=vkpYpWfEK5s. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion. Notinos (our employees) are customer zero in…
- Hybrid
- Full-time
Practice Lead - GRC
blueAPACHE·Melbourne, Australia
ABOUT US blueAPACHE is an Australian owned award-winning Managed Service Provider, recognised for the 7th year running as Mid-Market Partner of the Year at the ARN Innovation Awards. We pride ourselves on being a genuinely great place to work, with a vibrant culture, clear vision and strong leadership. When joining blueAPACHE, you are joining an organisation driven by our core…
- Hybrid
- Full-time
- Skilled Independent 189 — PR, no sponsor
Practice Lead - GRC
blueAPACHE·Sydney, Australia
ABOUT US blueAPACHE is an Australian owned award-winning Managed Service Provider, recognised for the 7th year running as Mid-Market Partner of the Year at the ARN Innovation Awards. We pride ourselves on being a genuinely great place to work, with a vibrant culture, clear vision and strong leadership. When joining blueAPACHE, you are joining an organisation driven by our core…
- Hybrid
- Full-time
- Skilled Independent 189 — PR, no sponsor
Senior Professional Services Project Manager (EMEA)
gitlab·Worldwide
<div class="content-intro"><p>GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.</p> <p>The same principles built into our products are reflected…
- On-site
- Full-time
Director of Strategy
Evolving Web·Montréal, Canada
We are a dynamic web agency committed to delivering innovative digital solutions that drive client success. Our team thrives on creativity, collaboration, and a passion for excellence. We are seeking an experienced Director of Strategy to lead our strategy team, guiding clients through transformative web and marketing initiatives. The Director of Strategy will spearhead the development and execution of comprehensive…
- Hybrid
- Full-time
- Express Entry — PR day one, no employer
Founders Associate (m/f/d) - start in September 2026
RobCo·Munich, Germany
About the Role at RobCo RobCo is building the category of Autonomous Industrial Robotics and we're doing it fast. We believe that automating the ordinary frees humans to do the extraordinary, and we're building the end-to-end robotics infrastructure to make that possible - hardware, software, and AI in one stack that just works. At RobCo, we automate the ordinary, so…
- On-site
- Full-time
- Blue Card — tied; settle 21–33mo
Praxis Onboarding Manager (m/w/d) - Startup AI Healthcare - Hybrid
Mediform GmbH·Karlsruhe, Germany
Hast du Lust, Teil eines ambitionierten Startups zu sein, das die Zukunft der Patientenkommunikation neu definiert? Dann bist du bei Mediform genau richtig! Wir sind Pionier in der autonomen Bearbeitung von Patientenanliegen – per Telefon und per Chat über die Praxis-Webseite. Unsere Technologie ermöglicht beispielsweise die automatische Terminvergabe, ohne dass das Praxispersonal eingreifen muss - das spart wertvolle Zeit und…
- On-site
- Full-time
- Blue Card — tied; settle 21–33mo
Enterprise Account Manager - Rokt Ads
Rokt·Sydney, Australia
We are Rokt. We are the global leader in ecommerce, on a mission to make every transaction more relevant. We've built our business around the Transaction Moment™, the span from cart to confirmation where customer attention and intent peak, and where more than 90% of ecommerce companies' ancillary revenue potential sits. The Rokt Brain leverages advanced machine learning to determine…
- Full-time
- Skilled Independent 189 — PR, no sponsor