Head of GRC
Job Description
Job Title: Head of Governance, Risk & Compliance (GRC) – MSP Practice Lead
\nLocation: London Hybrid (3 Days Onsite, 2 Remote)
\nJob Type: Full-time, Permanent
\nThe Opportunity
\nAre you a senior GRC expert ready to step out of a corporate cost-center and run your own practice?
\nA top-10 European Managed Service Provider (MSP) is hiring an entrepreneurial Head of GRC to take full strategic and commercial ownership of its fast-growing Compliance as a Service (CaaS) business line. This role perfectly balances internal corporate governance with high-level client advisory and Virtual CISO (vCISO) delivery.
\nKey Responsibilities
\nPractice Growth: Scale and productize the CaaS roadmap, driving revenue, pricing strategies, and service design.
\nvCISO Delivery: Act as the trusted boardroom advisor to mid-market clients across cyber security, risk, and resilience.
\nCore Frameworks: Lead client assessments and certifications across Cyber Essentials/CE+, ISO 27001, and UK GDPR.
\nInnovation: Build next-generation AI Governance and operational resilience (BC/DR) frameworks.
\nInternal Audit: Maintain the firm’s elite internal ISO certifications and audit readiness.
\nWhat We Need
\nSenior GRC, InfoSec, or IT Audit experience, ideally within an MSP or tech consultancy.
\nStrong practical knowledge of Cyber Essentials, UK GDPR, and ISO 27001.
\nExceptional executive presence—confident presenting risk and strategies to C-suite/board levels.
\nCommercial acumen to partner with sales teams and expand client adoption.
\nDesirable: CISSP, CISM, CRISC, or ISO 27001 Lead Auditor credentials.
\nWhy Join Us?
\nAutonomy: Run this practice like your own business unit with full SLT backing.
\nInvestment: Heavy funding for your ongoing professional development and elite certifications.
\nScale: Join an ambitious firm growing rapidly through organic expansion and acquisitions.
\nApply today to lead the future of Compliance as a Service.
\n