KEYSTONE CYBER

Home Disciplines GRC & compliance

GOVERNANCE, RISK & COMPLIANCE

Cyber GRC & compliance recruitment

GRC hiring is where the regulatory pressure lands first. POPIA made it a board conversation in South Africa, and the people who can hold both the control detail and the business argument are scarcer than the volume of applications suggests.

What we place

Security governancePolicy and standards, control frameworks, security committee and reporting structures.
Risk managementRisk assessment and registers, treatment planning, quantification, and reporting that a board can act on.
Compliance & auditISO 27001, PCI DSS, SOC 2 and internal audit response — including the people who run certification end to end.
Privacy & POPIAInformation Officer support, impact assessments, operator agreements, data subject request process.
Third-party riskVendor and supply chain assessment at volume, without becoming a questionnaire bottleneck.
Regulatory changeUK and EU work — DORA, NIS2 and UK GDPR readiness programmes.

Why GRC hiring goes wrong

Two failure modes recur. The first is hiring a framework administrator when the organisation needed someone to change behaviour: certification arrives, the controls stay theatrical, and nothing is actually safer. The second is hiring a technically excellent security person into a role that is mostly persuasion and paperwork, and losing them within the year.

We screen for the middle. The useful GRC candidate can read a control, understand what it is genuinely mitigating, and then hold the conversation that gets a business owner to accept or fix the risk. We ask for examples where they changed an outcome rather than documented one.

The South African picture

POPIA moved privacy and security governance from an audit exercise to a statutory obligation with a named accountable person, and the Information Regulator has become materially more active. That has driven steady demand from financial services, healthcare, retail and any organisation processing personal information at scale — which is to say, most of them.

The consequence for hiring is a large volume of applicants with compliance backgrounds and a much smaller pool with genuine security understanding. Filtering that gap is most of the work in a GRC search.

Where we recruit

Across South Africa, with concentrations in Johannesburg corporate head offices and Cape Town financial services, and in the United Kingdom.

Common questions

What does GRC cover in practice?

Governance, risk and compliance: policy and standards, risk assessment and registers, control assurance, audit response, regulatory work and third-party risk. Most roles emphasise two or three of these rather than all of them.

Do you place POPIA specialists?

Yes. POPIA work spans legal, privacy and security, and the useful candidates are the ones who can translate between those three. Information Officer support, impact assessments and operator agreements are the most common briefs.

Which frameworks do your candidates work with?

ISO 27001 most commonly, along with NIST CSF, PCI DSS, SOC 2, CIS Controls, and in the UK, DORA and NIS2 readiness. We match on the framework you actually report against.

Is GRC a route into technical security?

It can be, and treating it as second-tier is a hiring mistake. The strongest GRC people understand the controls they are assessing. Candidates who move from GRC into engineering or architecture usually do so because someone invested in that depth.

Do you place third-party and supply chain risk roles?

Yes, and demand has grown sharply. Vendor assessment at volume is its own skill — the pool of people who can do it without becoming a questionnaire bottleneck is smaller than clients expect.

Related disciplines

Talk to us about your search

A short conversation is usually enough to tell you whether we can help.