Cyber Security · Head of GRC
Head of Cyber GRC executive search.
Retained Head of Cyber Governance, Risk and Compliance search for regulated financial services, enterprise and government-adjacent organisations.
What the role is
A short definition.
A Head of Cyber GRC leads the governance, risk and compliance side of the cyber function — frameworks, policy, third-party risk, regulatory engagement and audit response. In regulated financial services the role has widened materially post-DORA and post the FCA/PRA operational-resilience regime. The Head of GRC typically reports to the CISO but interfaces directly with the CRO, Head of Compliance and Audit Committee.
Core responsibilities
What we assess candidates against.
- Cyber governance and framework — NIST CSF, ISO 27001, or equivalent
- Cyber risk assessment and reporting
- Third-party and supply-chain risk management
- Regulatory engagement — DORA, PRA/FCA operational resilience, comparable international frameworks
- Audit response — internal audit, external audit, regulator inspections
- Policy development and enforcement
When to run this search
Typical triggers.
On a regulatory intervention or audit finding; on entry into DORA or comparable regulatory perimeter; on a maturity uplift of the cyber function; on the departure of an incumbent Head of GRC.
How we search
The specific approach we take.
Retained. Candidate pools include sitting Heads of GRC at comparable regulated firms, Deputy CISOs with GRC-leaning backgrounds, and senior IT audit leaders from Big Four practices moving into industry. Every mandate is led by a partner with cyber sector fluency.
FAQ
Frequently asked questions
Do you handle Head of GRC searches for DORA-in-scope firms?
Yes. DORA-in-scope UK financial services entities are a specific specialism — the role requires familiarity with the EU technical standards and their UK-entity implications.
Can you support Head of Third-Party Risk searches as a distinct role?
Yes. In larger regulated firms Third-Party Risk is often a distinct executive role. We handle it either within GRC or as a standalone search.
How do you assess candidates on regulatory experience?
We probe candidates on specific regulator interactions, audit responses and framework implementations they have led. We do not accept surface-level answers.
How long does a Head of GRC search take?
Twelve to fourteen weeks brief to accepted offer is typical.
How is compensation structured?
Base, cash bonus, and (in larger firms) LTIP. Regulated financial services cyber GRC leadership has seen 15-25% compensation inflation in the last two years.
Related practice