Home Disciplines GRC & compliance
GOVERNANCE, RISK & COMPLIANCE
Cyber GRC & compliance recruitment
GRC hiring is where the regulatory pressure lands first. POPIA made it a board conversation in South Africa, and the people who can hold both the control detail and the business argument are scarcer than the volume of applications suggests.
What we place
Why GRC hiring goes wrong
Two failure modes recur. The first is hiring a framework administrator when the organisation needed someone to change behaviour: certification arrives, the controls stay theatrical, and nothing is actually safer. The second is hiring a technically excellent security person into a role that is mostly persuasion and paperwork, and losing them within the year.
We screen for the middle. The useful GRC candidate can read a control, understand what it is genuinely mitigating, and then hold the conversation that gets a business owner to accept or fix the risk. We ask for examples where they changed an outcome rather than documented one.
The South African picture
POPIA moved privacy and security governance from an audit exercise to a statutory obligation with a named accountable person, and the Information Regulator has become materially more active. That has driven steady demand from financial services, healthcare, retail and any organisation processing personal information at scale — which is to say, most of them.
The consequence for hiring is a large volume of applicants with compliance backgrounds and a much smaller pool with genuine security understanding. Filtering that gap is most of the work in a GRC search.
Where we recruit
Across South Africa, with concentrations in Johannesburg corporate head offices and Cape Town financial services, and in the United Kingdom.
Common questions
What does GRC cover in practice?
Governance, risk and compliance: policy and standards, risk assessment and registers, control assurance, audit response, regulatory work and third-party risk. Most roles emphasise two or three of these rather than all of them.
Do you place POPIA specialists?
Yes. POPIA work spans legal, privacy and security, and the useful candidates are the ones who can translate between those three. Information Officer support, impact assessments and operator agreements are the most common briefs.
Which frameworks do your candidates work with?
ISO 27001 most commonly, along with NIST CSF, PCI DSS, SOC 2, CIS Controls, and in the UK, DORA and NIS2 readiness. We match on the framework you actually report against.
Is GRC a route into technical security?
It can be, and treating it as second-tier is a hiring mistake. The strongest GRC people understand the controls they are assessing. Candidates who move from GRC into engineering or architecture usually do so because someone invested in that depth.
Do you place third-party and supply chain risk roles?
Yes, and demand has grown sharply. Vendor assessment at volume is its own skill — the pool of people who can do it without becoming a questionnaire bottleneck is smaller than clients expect.
Related disciplines
Talk to us about your search
A short conversation is usually enough to tell you whether we can help.