01Two demands, one budget
The directive requires demonstrable governance: risk management, supplier oversight, incident reporting within tight deadlines. That is GRC work. But reporting an incident within 24 hours assumes you can detect it, which is detection engineering. Organisations that hire only for the first requirement discover the gap during their first real incident.
02Where the scarcity actually sits
GRC specialists who can write a policy exist. GRC specialists who can translate a technical control into an auditable statement and back are rare. On the technical side, the shortage is not in tooling knowledge but in people who can tune detection so an on-call team is not drowning in false positives.
- Governance specialists with technical literacy
- Detection and response engineers
- OT security profiles in industry and energy
- Supplier and third-party risk
03Practical advice
Split the role before you post it. Decide whether you need evidence for the auditor or capability against an attacker, then hire deliberately for each. And check availability early: in this niche, a good candidate is usually in a conversation with two other organisations already.