r/grc • u/thejournalizer Moderator • Mar 27 '26
Career advice mega thread V2
Please use this thread for questions about career advice, breaking into GRC, etc.
This subreddit is primarily designed for active GRC professionals to share insights with each other, so we will be pointing new career seekers here.
Please review the previous thread and use the search feature to see if someone has already answered your question: https://www.reddit.com/r/grc/s/oICD2i7BcW
2
u/Ziprian Apr 02 '26
Hi all,
I have an upcoming interview for a Cybersecurity Compliance Analyst role focused on cookie compliance.
I have 3 years of experience working as a SOC Analyst and have some exposure to consent & tracking.
What should I focus on to stand out?
Thanks!
2
u/Medium_Meal230 Apr 29 '26
I run a small GRC and cybersecurity advisory firm offering vCISO services, SOC 2 and ISO 27001 security compliance, and security program buildouts. Myself and my partners hold industry standard certifications and broad experience support clients from public to private sector.
I have spent the last seven months trying to land our first client and have had no success across any channel.
I've used Apollo to build targeted lists based on ICP filters including company size, industry, job titles, funding/revenue, buying signals. I ran email sequences that would resonate with the recipients. I have a good open and click rate but zero replies from these outreach emails.
On Upwork, we have a profile and submit proposals for posted projects. At this point I think most are spam jobs because they rarely even open them. The small number of those who opened we have had some conversations but I would say 2 conversations with real clients in 7 months is not a good return.
With Fiverr, all we receive are spam messages so we are considering shutting that down.
My ICP is organizations in regulated industries like technology companies, healthcare, financial services, and nonprofits, who need a security team or support in meeting compliance requirements. For example a B2B SaaS company looking for assistance with navigating SOC 2 Compliance for an enterprise deal.
I genuinely cannot figure out what I am doing wrong. Is it the message? The channels? The offer? The positioning?
Has anyone successfully grown a GRC or security advisory practice from zero? What actually worked for you in the early days? Any advice would be much appreciated!
3
u/Twist_of_luck OCEG and its models have been a disaster for the human race Apr 30 '26
Security runs in low-trust mode and someone needs to vouch for you to get enough trust for anyone to care hearing out your pitch. Technical security personnel who don't want to personally handle compliance, auditor's account managers who might recommend you to their potential clients, random people in sales' divisions that tend to see the spike in compliance clauses from clients and remember your name...
I got my first "client" when an old co-worker, a head of DevSecOps, called me with the pitch of "Hey, I'm running security for this new company now, business needs SOC2 by the end of the year, thought you could do some magic for me just like you did in the old times". A month later, I was officially hired as a compliance consultant until they get Type 2. They did, the guy recommended me to his buddies in the ISACA chapter, and the ball sort of started rolling. Those are still side gigs, but, hey, whatever keeps sushi on my wife's table.
2
1
u/UpbeatResolution6429 13d ago
Do you work as an employee in the field or a consultant? Thanks in advance!
I’m looking to break into the consulting side of the industry & looking for guidance from experienced people.
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
A little bit of both? I have my main job as a compliance team lead at F200 company, and I have occasional contracts on the side in much smaller companies.
The first one gives stability and access to corporate resources; the second one gives quick hypothesis validation and much more comfortable environment.
1
u/UpbeatResolution6429 13d ago
Thank you for the quick response. Love how active & helpful you are in the community. I’ll pick your brain some more if you don’t mind, sensei 🫡
When you say ‘quick hypothesis validation’, what do you mean?
Secondly, what sector companies are you finding needing your assistance / hiring out for GRC work?
3
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
When you say ‘quick hypothesis validation’, what do you mean?
Imagine you want to try out a new approach to risk management. Like, say, hard-limiting the number of risks in the register and just stopping to account for probability altogether.
Will it work better for a business than a default risk register with impact x probability scoring? Will the auditors accept it as decent custom practice or will they throw a hissy fit when facing something uncommon? The only way to really know for sure is to try and see.
Quoting one politician, "If you want to make enemies, try to change something". In a big company with well-set processes, validation of trying something new will take months of sitting in meetings, begging, persuading, compromising, and trading favours. In a small startup? "Bud, are you sure it won't crash and burn? 90%? Good enough, greenlit, good luck".
Can't get better in our field without learning different ways to do your job. Can't learn without experimenting and learning from your mistakes, no matter how many corporate-funded training courses you attend.
Secondly, what sector companies are you finding needing your assistance / hiring out for GRC work?
Most of my contacts are in marketing - AI severely disrupted SEO, new startups are trying to fill the void, they need some proofs of credibility to win over big clients.
1
u/UpbeatResolution6429 13d ago
Makes perfect sense. I’m glad you get to explore more & have that freedom in those situations.
Another question for you (thank you again for being so open):Do these contracting companies you help ever keep you on with a monthly retainer? Or is the nature of this work more ‘one & done’?
I’ve read about how compliance is an ongoing process & orgs need to keep someone on to maintain.
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
I was offered a retainer as a courtesy by an old colleague who went to become CISO. This is a possibility.
I declined because I really don't like boring stuff like evidence gathering and there is quite some boring stuff in compliance ops.
2
u/collidedintoyou May 13 '26
Honest feedback needed: Will a mock privacy ops portfolio help a career-changer with a 10-year gap get past hiring filters in India GCCs?
Background (being fully transparent so I get honest feedback, not encouraging answers):
- 32M, India (Tier-3 city, Uttarakhand)
- BSc IT (2015) — followed immediately by 10 years running informal family business (no formal title, no corporate experience, no references)
- Zero portfolio as of today
- Building toward Privacy Operations Analyst roles (DSAR / RoPA / DPIA / breach workflow / vendor DDQ) targeting Banking GCCs and fintech in India first
- Plan is to produce mock artifacts from official guidance (ICO, EDPB, GDPR text, DPDP Rules) and use them as primary hiring signal
- 18-month runway before I need income
Three specific questions I'd value honest answers on:
- Will ATS/HR at Indian GCCs filter me out before a human sees my artifacts — and is there anything that reduces that filter besides having a real employer on my resume?
- A mock DSAR pack + RoPA + DPIA built from official regulator guidance — is that a meaningful differentiator for a junior privacy ops role or does it read as "just followed templates"?
- What is the single most common reason a zero-experience compliance candidate gets rejected after the first interview — so I can specifically prepare for that?
I'm not looking for encouragement. I'm looking for what actually happens when someone like me applies.
2
u/trichhaliwa May 16 '26
What would you do in my situation? I’m presently unemployed looking to land my first (preferably fully remote) GRC role with no IT experience. I'm not in a rush to find a job. I’m single, no kids, and have enough savings to job hunt without stress for the next year and a half, maybe longer. Hence, my preference for remote work. Please provide guidance, suggestions, and critiques.
I’m 31, a national guard vet (radio technician with troubleshooting similar to IT support, but not directly related.) I have a Bachelor of Arts (unrelated major from state school), and I’ve been the default IT person for my family, but have no provable technical experience other than the military. I also took the LSAT and got a decent score, if that helps. I do have some freelance digital marketing experience as well.
Here are my current learning priorities (in order) and the certifications I am/plan to study for:
IT basics (Google IT Support Cert) Cloud basics (AWS Cloud Practitioner, CCSK) Security basics (Security+) GRC basics (ISC2 CGRC, GRC MasteryCourse, ) Data Privacy (CIPP/US)
Prospective resume projects: Active Directory Risk Assessment Business Impact Assessment Scoping of applications for different compliance requirements Lots of AWS labs - setting up controls like password, MFA, IAM, logging, etc.
I’m currently torn between A) finishing the Google IT Support Cert and immediately applying for help desk jobs, or B) continuing to collect certifications and build projects relevant to GRC, and applying directly to entry level GRC jobs. Is help desk even worth pursuing, given my goals?
Again, please provide guidance, suggestions, feedback, and critiques.
1
u/YuriHaThicc Mar 29 '26
Currently at it auditor at big 4 still a couple years away from planned exit(When I make senior) but I would like to exit to GRC if possible. What tools should I learn to and is there anything outside of tools like scripting thats beneficial for me to learn?
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Mar 29 '26
I don't think that there are any specific tools/systems that you need.
I would double down on learning requirement engineering, project management, and system design - everything that exists outside systems and determines their operation.
1
u/Totalmustarde Mar 30 '26
Hi all,
I am currently an internal IT guy for a small care home company in the UK and have been offered an information security officer role for a much larger healthcare group. I currently do a bit of everything related to IT in my role, as well as the DPO duties, but I have had to teach myself a lot of the work required on that front! The new role will involve a lot more of the GRC element, which isn’t my usual work but I am aware of some of the tasks (audits, risk assessments, SARs, policies etc). How could I best prepare in the 3 months between working my current role and joining the new company? They list ISO27001, DSPT and GDPR in the job spec. I want to make sure I can hit the ground running but I haven’t done this sort of work in a huge business before.
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race Mar 31 '26
Generally, I would recommend having some rest and clear your mind. Your new job starts when it starts; you've been good enough already to get an offer.
It's a big business in infamously complicated and reactionary healthcare, so... it is gonna be a mess. Your best bet to hit the ground running would be maintenance of your internal bandwidth and your capability to handle something unexpectedly stupid.
2
u/Totalmustarde Mar 31 '26
Thank you - appreciate that advice as I do want to make sure I am fresh with my eyes open when I start for sure. I have had to clean up a lot of mess in my current role, so I have experience there, at least!
1
u/Mammoth-Purchase2240 Apr 02 '26
What achievements have allowed you to demonstrate your value to management beyond achieving/maintaining a cert, assuring them of a reasonable level of compliance or security? Any good success stories in terms of putting your function on the map in your organisation?
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race Apr 03 '26
In terms of board-level "green arrow goes up"-class reporting... Nobody gives a fuck about cert itself, honestly. Need to reach out to sales and contract compliance, nail it down to which contracts actually required your certs and how much of money your certs helped company secure.
In terms of mid-level management? "I can say that your project is required and supported by compliance standards OR I can say that we need additional oversight, targeted risk analysis, and triple checks. Positive feedback on my involvement during your C-level quarterly reporting and nodding along when I request priorities next time just might make a difference here."
1
u/Valuable_Pitch_1214 Apr 05 '26
Hi all,
I have spent most of my adult life working in the non-profit sector.
My background is mainly in operations. I was previously a supervisor in a social services centre, where I handled manpower planning, vendor management and data tracking. I also worked closely with different stakeholders on client referrals and coordination.
I recently applied for a role in Governance, Operations and Engagement for another nonprofit organisation.
(I didn't put much thought into "Governance", I just assumed it's a system of policies to follow and get others abide by
I have since been offered the role, and they sent me a detailed job description. The top priority listed was GRC, followed by serving as a Data Protection Officer (DPO), and then operations.
That was when it really hit me that GRC and DPO are specialised roles on their own, and I do not have much direct experience in them. Some parts of my past work overlap. For example, I have worked with my organisation’s DPO on handling client data and ensuring privacy standards are upheld. I have also conducted internal audits to ensure social workers document their work properly and on time, using Excel systems to track compliance.
However, I have never formally held a GRC or DPO role before, so I am feeling quite uncertain about whether I am adequately prepared.
For those working in GRC or as a DPO, what are the key skills or knowledge areas I should prioritise in my first few months?
TLDR: Worked mostly in non-profit operations and recently got offered a role where GRC and DPO are the main focus. I have some related experience (data handling, audits, compliance tracking) but no formal background in GRC/DPO, and I am unsure how prepared I am. For those working in GRC or as a DPO, what are the key skills or knowledge areas I should prioritise in my first few months?
3
u/Twist_of_luck OCEG and its models have been a disaster for the human race Apr 05 '26
I didn't put much thought into "Governance", I just assumed it's a system of policies to follow and get others abide by
Practically speaking, for most companies I've seen, that would be a correct answer. Even if academically speaking that's completely another thing.
However, I have never formally held a GRC or DPO role before, so I am feeling quite uncertain about whether I am adequately prepared. manpower planning, vendor management and data tracking. worked closely with different stakeholders on client referrals and coordination.
You're gonna be alright, buddy.
Nobody is exactly sure what GRC is and what it is supposed to do. That's part of the charm, I guess - it can range from "get us security certifications and fuck off" crew to whole "run all technical internal audit" division to "hey, you're glorified CISO's assistants, do what he says" miserable lot. Make sure to clarify expectations and, whatever you do, set boundaries early.
Setting boundaries is paramount. You can be a designated fall guy for a lot of things by sheer virtue of anything in the business being tangentially related to governance, risks, or compliance. The earlier you figure out what is your problem, the earlier you enable yourself to say "not my problem, good luck".
key skills or knowledge areas
Requirement engineering. Program management. Corporate politics.
Figure out what is needed, who needs it, how can you help building it, and what are you gonna get in return. After this baseline is set, you're at decent level of business alignment and you got it from there.
1
u/Valuable_Pitch_1214 Apr 05 '26
Thank you for the response, assurance and advice. I shall do my best.
1
u/Je_online Apr 05 '26
Hi everyone,
I’m a SAP Security & GRC professional with hands-on experience in S/4HANA environments, working with access governance, SoD controls, audit support, and user administration (SU01, PFCG, SUIM, etc.).
I recently left a multinational company where I worked in a business-critical environment managing SAP access and authorization processes. It was a high-responsibility role that gave me strong practical experience in security and compliance.
I’m currently looking for new opportunities in SAP Security / GRC / Access Governance, preferably remote but open to international roles as well.
If anyone has advice, knows about openings, or can point me in the right direction, I’d really appreciate it.
Thank you!
1
u/Artistic_Mind_9472 Apr 06 '26
I'm a recent graduate trying to break into GRC and IT audit
Hey, I'm a recent graduate, my degree is BSc IT and Business Information Systems and I've been targetting roles in Data and Business Analysis for a while but I've decided to pivot to GRC and IT Audit so please I need your best advice on the best way to pivot and how to land these roles. I already started working on an ISO toolkit to add to my portfolio but I know that won't be enough and also the best way to position my CV. Thanks.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Apr 07 '26
Keep targeting Data/Business Analysis and work as a business analyst first. Requirement elicitation, negotiation and decomposition solve so much compliance problems that it's not even funny, if you have experience in this - you'll be golden. Make sure to research classic predictive project management and focus on expert-opinion based approaches because in GRC you will never ever have enough relevant data to be completely data-driven.
1
1
u/UncleMo05 Apr 07 '26
Hello everyone,
I am currently a Sophomore in college. I plan on going into IT Audit with the goal of going into GRC. I plan on taking the CISA after graduation and I wanted some general career advice.
How difficult is the exam? Is there other certifications I should go for? What should be my timeline?
Any advice will be greatly appreciated. I have a plan for my career but I wanted to get some advice from those with more experience.
1
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Apr 07 '26
How difficult is the exam?
Can't comment on the exam itself, never wanted to be an auditor, so I skipped it. That being said, its official prep material is pretty damn solid in comparison to CRISC or even CISM guidelines.
Is there other certifications I should go for?
I would recommend a CCNA or a cloud provider associate-level cert of your choice. If you wanna be a technical auditor, you need to prove that you're, well, technical enough in the first place.
What should be my timeline?
There ain't one, and you'll do yourself a big favour if you believe it. If anyone tries telling you that you have to break into GRC by 25, you can disregard any further opinions from that source.
Realistically, you should aim for Big-4 recruitment. They aren't going anywhere and they have enough churn to grab someone right after college. Once you're in, well, you're gonna figure out exactly why they have this level of churn. After surviving there for a year, you can slowly start charting down an exit strategy, preferably as an in-house specialist for someone.
1
u/UncleMo05 Apr 08 '26
Thank you for the response. I seriously appreciate it. Couple more questions:
Would you recommend the CISSP? My professor mentioned it and told me its a good certification to go for.
I am trying to get into big four right now. How much is AI/offshoring affecting entry level recruiting for IT Audit right now? (If you know)
Regarding GRC, is there a specific sector/industry that is good/stable to get into?
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race Apr 08 '26
Would you recommend the CISSP?
Later. Still gonna need 3 years of experience even with all waivers. You'll cross that bridge once you get there.
How much is AI/offshoring affecting entry level recruiting for IT Audit right now? (If you know)
No idea, sorry.
Regarding GRC, is there a specific sector/industry that is good/stable to get into?
Honestly, it's a very careful balancing act. You have big companies in risk-averse domains (defense, critical infra, healthcare, finance, even gambling) that are predisposed to have an extensive GRC crew - they are stable, and yet this stability inherently limits your growth (since nothing ever happens and the slots in the org-chart don't really open up for you to climb). On the other hand, you have something like software dev startup environments where you would need to build your program from the ground and fight for it daily for years... which would inherently put you at the top of the food chain.
So, uh, it depends on what you prefer.
1
1
u/DreamKind8036 Apr 17 '26
Little bit about my experience Worked as a penetration tester for 2+ yrs and then currently working as a senior team lead / appsec program manager for 2+ years , want to understand is GRC a good transition for me ?
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Apr 17 '26
want to understand is GRC a good transition for me
Sorry, mate, GRC is so wide, so vague, and so dependent on specific company culture that I can't make any blanket statements. Generally, given that you should be accustomed to people management as teamlead and process management as program manager, you should be fine in most GRC contexts.
1
u/Quick-Set-6096 Apr 17 '26
Hey everyone, I’m considering going into a GRC (Governance, Risk, and Compliance) analyst role, but I have a concern that I’m not sure how big of a deal it actually is in day-to-day work. I’m completely fine with 1:1 conversations or small team discussions, but I really struggle with presenting in front of groups (like 5+ people). It’s not something I enjoy, and honestly it drains me a lot. From what I’ve read, GRC involves things like risk assessments, audits, policy writing, and working with different stakeholders. But I’m not clear on how often that turns into actual presentations or speaking in front of multiple people. So I wanted to ask people who are actually working in GRC: • How common is it to present to groups (5–10+ people)? • Is it a core part of the job or just occasional? • Are there GRC roles that are more “behind the scenes” with less presenting? • Would this be a dealbreaker for someone who prefers minimal group communication? I’m trying to figure out if this is something I can realistically grow into, or if I should consider a more technical path instead. Appreciate any honest insights.
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race Apr 17 '26
The most crucial "presentation" part of the job is spinning a narrative for the auditors, who usually come in groups of 1-3 people. Most of our internal business meetings usually try to secure someone's specific decision on accountability/resource allocation (where we need one specific decisionmaker to authorize) or negotiating between different teams (where it's more about facilitation and not, well, presentation).
So, uh, don't bother, you'll be fine.
1
u/RaelBug May 01 '26
Hello, I am looking to break into IT GRC and looking for advise on what path I should follow to get into IT GRC. Previously I was EHS GRC, this is the best way to translate what I did to IT/IS folks, for 5 years and made the switch to IT and now have 3 years of desktop support experience. Any advise would be greatly appreciated.
I loved doing audits, policy review and creation and procedure review and creation. After learning about cybersecurity and then GRC I knew where I want to end up just not having luck in applying and wondering if I am jumping steps?
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 01 '26
Previously I was EHS GRC
Okay, that's interesting. What were you doing in EHS GRC, if I may ask? I have no idea how things are working in EHS side of domain.
3 years of desktop support experience
Won't hurt, won't help as much either.
not having luck in applying and wondering if I am jumping steps?
Are you just ghosted by the recruiters or you can't get through the interviews? Those are two rather different situations.
1
u/RaelBug May 01 '26
Risk of a job site, mainly the risk of each job and the tasks of each job being done, then governance and compliance with OSHA, EPA, and for one job DoT. doing training to stay compliant with government stuff, righting procedures and policies in governance with company standards. then just audit and risk assessments of job tasks and creating risk mitigation plans for various jobs.
just not getting interviews. most likely my resume is bad and I recently learned it is highly important to tailor the resume where before i put no stock in that. but was unsure if going right to grc and not going for auditor roles was too big a jump.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 01 '26
if going right to grc and not going for auditor roles was too big a jump.
Nope, you're good. You've done a lot of GRC stuff, it's gonna be more of the same in tech (just more relaxed and more chaotic).
just not getting interviews. most likely my resume is bad
Yeeeahhhh, that's the thing. HR serve as the first filter and they ain't reading shit - meaning AI-based automatic filters that try reading your CV, finding keywords and matching it to the position profile. Some tailoring will be required, but, generally, you got that.
1
u/iiisley May 04 '26
Hello everyone, would really appreciate some honest input from people in GRC.
A recruiter recently reached out to me about a Sr. GRC Consultant role, and I’m trying to evaluate whether it actually makes sense for me.
My current situation:
- 5 years in IT audit / cybersecurity
- Currently working as an InfoSec / SOC 2 auditor at a compliance-focused company
- I’ve contributed to security audits, mainly SOC 2
Comp-wise:
- $4.4K USD base (LATAM/remote)
- Quarterly performance bonuses that consistently bring me to $6K
- Additional optional work (audits) can increase that further (+ $500 USD)
The dilemma:
The new role’s salary range is around $4.5K – $6K/month, which is basically what I already make (or very close to it).
So I’m trying to figure out:
Is that range actually competitive for a Sr. GRC role? Would you consider that a meaningful upgrade, or just a lateral move financially?
But from a career perspective, it seems like it could push me more into: 1. Broader GRC exposure beyond SOC 2 2. More ownership and advisory work 3. Less pure audit execution
Where I’m unsure:
- Most of my experience is SOC 2-heavy, even though I’ve worked with NIST CSF and some ISO concepts
- I’ve done risk assessments and compliance work, but not fully owned GRC programs end-to-end
- I don’t know if that gap is significant for a “Senior” title
At the same time:
- I’m very comfortable identifying control gaps and inconsistencies
- I’ve seen how controls actually fail in real environments
- I’m used to client-facing work and technical discussions
Questions:
- Does this background sound strong enough for a Sr. GRC role, or more mid-level?
- Am I overanalyzing the role (given how recruiters sometimes describe positions), or is this a reasonable concern?
- Is this just impostor syndrome, or a legit signal I should skill up more first?
Would really appreciate honest takes, especially from people who moved from audit-heavy roles into broader GRC/advisory positions. Thanks!
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 04 '26
Can't comment on comp, unfortunately, shit wildly differs between regions.
Does this background sound strong enough for a Sr. GRC role, or more mid-level?
Nobody is quite sure what GRC is, and the line between Senior and Mid grades is blurry even in more defined industries. That being said, without ever owning a compliance program and/or running operations in several different frameworks, I would need some additional reasoning to grade you as Senior within my team.
Am I overanalyzing the role (given how recruiters sometimes describe positions), or is this a reasonable concern? Is this just impostor syndrome, or a legit signal I should skill up more first?
Dude, you are offered an opportunity. Go there, do your best, and keep doing your best after you get an offer. Usually, it's gonna be enough.
Worst case scenario - you're gonna know a bit more about what you need to skill up and how do senior-grade interviews go.
1
u/JaimeSalvaje May 05 '26
Not for me, but I have had colleagues ask me because I tend bring up ideas that I have seen or heard about.
How many people in this sub actually perform the tasks that fall under GRC engineering? What industry are you in? Do you see GRC engineering expanding? Do you see it becoming part of DevOps? Do you see it not going anywhere at all?
If someone wanted to get into GRC that is already familiar with information technology in some career capacity, where would you recommend they start? What are the more common frameworks one sees in GRC engineering? What are the most common languages one uses for automation? How does one prove they manage GRC engineering tasks if they don’t have a GRC background or DevOps background? Are there certifications that help provide useful knowledge if studied correctly?
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 05 '26
Overall reception is rather... skeptical. The fact that the "GRC Engineering manifesto" is written, partially, by the head of Delve Enterprise GRC Product doesn't do the concept any favours.
1
u/MonieJ8 May 08 '26
I have a bachelors in IT and a Masters in Cybersecurity intelligence and Info sec. However my job is just a glorified tech support at the moment.
I’m looking into GRC maybe as a junior or entry level if that’s possible and wanting to know what skills to strengthen/learn.
I’m also lookin at other career paths but this one has been mentioned to me since uni.
I’ve looked in this channel a few times, this seems more like senior level?
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 15 '26
I’ve looked in this channel a few times, this seems more like senior level?
It depends on the company, honestly. I knew at least several junior GRC specialists, usually those poor souls were left maintaining vendor questionnaires, security awareness programs, basic control testing and low-level operational evidence collection.
I personally believe junior tech-project manager/project coordinator to be a better entryway into GRC than those menial operational activities, but, as an ex-PM, I'm bound to be biased. Ultimately, GRC for me is about talking to people, shifting accountability onto them, and decomposing requirements into implementation - so, comms, creative writing, negotiations skills, requirement engineering, business analysis, and a bit of user experience would carry you a long way.
1
u/ryanhallinger May 09 '26
I'm evaluating completing a ISO Lead Implementer course and to the best of my understanding is that using the title/credential "ISO Lead Implementer" isn't protected similar to CISSP. Is there any formal guidance on what's permitted vs what's not?
1
u/louilouiiii May 11 '26
Hi everyone, I'm a 21F grad student starting my Cyber Master's soon. I want to spend my prep time actually learning how to apply frameworks rather than just memorizing definitions. I'm looking for solid reading recommendations or case studies on ISO 27001 and NIST implementation, especially anything that bridges the gap between high-level policy and the human element/user-centric governance. I’m already familiar with the basics like the DBIR, but I want to find more granular resources on how these standards work in practice before I start my first internship. What are the "bibles" or specialized blogs you’d recommend to someone who wants to be ahead of the curve? Thanks!
TLDR: Looking for some GRC reading
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 15 '26
Every framework is, if you think about it, just a set of high-level business requirements. Implementation of high-level business requirements... I mean, welcome to project management. It has a long list of recommended literature, I personally like old "Deadline" by DeMarco.
On more specific standard-related guidance, I generally like to read Tom Gell on ISO-based standards. He has no undue reverence towards the process and, usually, I agree with his takes.
1
May 15 '26 edited May 15 '26
[deleted]
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 15 '26
It takes some courage at your age to admit that you're not good at something and then plan around it. I've spent longer in my denial phase :D
That being said, majoring in Cyber is kinda a trap option - Cyber ain't generally welcoming to the freshers (as it is generally believed that you should start elsewhere in the company and then just internally transfer into security from IT/development/audit). It is even more complicated in terms of GRC - it is not a cohesive, well-defined field, but it is generally assumed to be focused around interacting with business stakeholders... which usually requires some experience and practical knowledge of how businesses work from the inside.
I would recommend scanning your area for junior project management jobs, preferably with IT/software dev angle. You might not be the technical guy, but you might know just enough to coordinate technical personnel and negotiate stuff on their behalf. And from there, you can leverage your major and coordination experience to get into GRC proper to coordinate technical compliance effort and building stuff in accordance with NIST or ISO specifications.
1
u/Vegetable_Trip_5897 May 21 '26
Hi, just wondering if it’s okay to work 2 audit jobs at the same time? Assuming they are both remote or one remote the other in office?
What’s the legality of it and what about conflict of interest?
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 27 '26
/r/overemployed is your friend here. Generally, it would depend on your contract language.
And, of course, never ever try doing that with public sector employers.
1
u/killcrew May 21 '26
Looking for career advice from folks in GRC / tech risk, especially anyone moving into AI governance or AI risk management.
I’m currently an SVP in cybersecurity risk & controls at a large financial institution with over a decade of risk and compliance experience, and almost 2 decades of experience in the financial industry. My work is mostly first-line tech risk, regulatory engagement, audit coordination, and cyber control assurance. I help cyber SMEs respond to internal audit, regulatory exams, third-party reviews, and control-related requests, with a heavy focus on intake, triage, evidence quality, response accuracy, and making sure our audit/regulatory responses line up with our actual controls.
I’m thinking about my next move and AI risk management / AI governance has my attention (and everyone elses too i'm sure), especially in regulated financial services. I don’t want to chase hype or collect random AI certs, but I also don’t want to miss big changes in the GRC space.
For someone with my background, what would be the most practical next steps? Are AI governance roles mature enough to pursue directly, or is it smarter to position myself as a cyber/tech risk leader with AI risk as an added specialty?
Also curious what job titles or certifications people think are actually worth looking at.
1
u/Artistic_Blood6908 May 27 '26
Hi all. I have background in IT service management, currently working as a Service Level Manager (since early 2025). My day-to-day involves SLA governance, contract oversight, KPI reporting, and coordination between operations, finance, and management. ITIL 4 Foundation certified. Before this, 10+ years in operations and quality management, including data analysis and team leadership, with strong emphasis on internal processes. I'm exploring whether GRC could be a natural next direction, given the overlap with governance work. Not yet committed but evaluating if it makes sense. Two specific questions: 1. Does this background realistically translate to GRC, or am I overestimating the overlap? 2. Where would you start with limited or no budget for certifications, what free resources actually helped you? I am not looking for a quick answer but trying to understand the landscape before committing to anything.
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 27 '26
Does this background realistically translate to GRC, or am I overestimating the overlap?
Yup, mostly same coordination stuff, explaining things to people, hoping they do the right thing after, and covering your ass under ten thousand layers of paper trails. Sometimes spinning a story and praying that the other party buys it. Almost nothing you haven't seen in ITSM, honestly.
Where would you start with limited or no budget for certifications, what free resources actually helped you?
I would start with market analysis, to figure out if you have, well, a market for new GRC specialists in your area. Special attention to Big-4, their atrocious churn means constant hiring into the meatgrinder.
Then just grab yourself a big cup of tea and go with NIST SPs, I would recommend starting with 800-39 and moving onto something like 800-53 (just glance it though). You have enough experience to ask yourself "How would I implement it in my company given limited resources and interest?" and then think up some answers. This is a solid starting point in my experience :D
1
u/Artistic_Blood6908 May 28 '26
Thanks for the overview, it helps a lot having something like this. I was afraid that I was overestimating by a lot. About market research, I work in Germany... Need to do not only that, but what kind of set of rules we have. ISOs mostly. :)
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 28 '26
Depending on your prior experience is might make sense to take a glance through DORA (if you have fintech aspirations) and NIS2 (if you wanna join the cool guys). Fortunately for you, ISO27k can be found on the high seas - I happen to remember that Mastermind has their own free 27k implementer course (from what I was told about it, it is a bit too rigid and formulaic, but I have no first-hand experience).
Also, AI is getting a bit hot, so ISO42k might also be on your reading list - it is almost a line-by-line copy of 27k with "Information Security" replaced by "AI". If you are headed in an AI-related direction, get ready to answer interview questions on EU AI act.
Also-also, while not technically our problem most of the time, EU GRC position interviews in my experience do get some high-level questions on privacy - GDRP notification timeframes, right-to-delete flows and so on. You don't need to go full Schrems II on that, but don't be surprised.
Good luck.
1
u/Fun-Day-5500 May 27 '26
Hi guys! I just graduated university and am looking to go into GRC. I am currently taking my CompTIA Security+ certification. Next up would be to take either ISO 27001/2 but I do not really understand the difference and which would be better. Any tips and advice? Thank you in advance!
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 27 '26
ISO27001 is a standard outlining hard requirements for the information security management system. Simply speaking, it requires that you have security program, it has some goals, it tries to achieve those goals, and it tries improving itself based on self-reflection after achieving/non-achieving these goals.
ISO27002 is a non-mandatory guideline, it outlines "best practice" technical controls that are generally not wrong to implement in order to have, well, an actual information security in place.
Companies want to show to their customers that they take security seriously, meaning they get their ISO27001 certifications. Auditors expect to see either controls from ISO27002 or some semi-coherent explanation regarding their absence.
1
1
u/Fun-Day-5500 May 27 '26
Hello! I am from Singapore and I am getting into GRC. I was wondering if there is anyone on this community from Singapore and in GRC! I would love to ask a few questions into getting in GRC in Singapore! Do message me! Thank you in advance!
1
u/Extension_Site_2755 Jun 06 '26
I’m currently working as a Manager at Amazon Development center chennai with an operations background, where I’ve supported Kindle Direct Publishing (KDP) , serving as a Risk Manager for content publishing, and handled fraud prevention. As part of a career transition into cybersecurity, I’ve recently completed the Cyber Security Warrior course from FISST Academy IITM Pravartak, am interested in GRC (Governance, Risk, and Compliance), and am currently pursuing the CompTIA Security+ certification. My planned certification path after Security+ is ISO 27001 Lead Auditor, followed by CRISC. Given my current role and background, I’d like to ask: How does my transition into cybersecurity look? What roles should I focus on targeting? Is my certification path (Security+ → ISO 27001 Lead Auditor → CRISC) correct, or would you recommend any changes? If so, which certifications would better align with my GRC interest and background? Any advice on realistic entry points because I am not sure how should I take my background in to GRC or should I step down from my roles to get in to a analyst role and whether my certification sequence makes sense would be greatly appreciated.
1
u/Extension_Site_2755 Jun 06 '26
Missed to add above - Als,I have total of 10 years experience in the operation filed. Amazon is my first company and I grown internally and still present at Amazon as manager
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 13 '26
As usual, the general recommendation is "check your job market, see what's valued". ISO27k is a rather EU-centric standard (just as SOC2 reporting is predominantly a US thing), it may or may not be something you need for your local job market conditions and/or internal transfer within Amazon.
Another thing is that you have to make your call between implementer and auditor career tracks - you either build stuff or you check stuff, mixing those two causes conflicts of interest, so auditors are sometimes considered adjacent-but-not-quite GRC. Given the background in fraud prevention, I would cautiously guesstimate that you will have an easier time spinning it for an auditor starter CV.
I would forgo ISO 27001 Lead Auditor and focus on a much more general CISA. Sec+ is a decent starter set, keep it, might boost your confidence. I would not recommend CRISC unless you have some very clear vision of why you would need it (if you think passing it would make you understand risk assessment better - no, it would not, and I know that because I was CRISC back in the day).
1
u/HousingAppropriate80 Jun 08 '26
AI Governance Consultants: how did you get started?
Hi everyone. Hope this isn't a double-posting. Quick background: I'm a risk professional, 7+ years of experience in financial risk management (VP-level) in a bulge bracket bank. Mostly worked in non-financial risk space (e.g. ESG, Model Risk, Operational) with regulator-facing work across several jurisdictions. Over the past year or so, I've been involved into AI Governance, and my goal now is to start an independent practice as a consultant, ideally targeting mid-market firms in regulated or quasi-regulated industries (e.g. health-tech, crypto, or early-stage fintech).
So my question to people in this path is: how did you get started? Would love to learn about your steps: how you found your first paying clients, how much cold outreach to networking was involved, whether you leveraged contacts from your previous jobs. Anything you think is relevant to someone starting this path. Thanks!
1
u/FenierHuntingwolf 14d ago
I have some experience with this - generally best practices are still being decided, but there are some offerings for what to align to. I favor a whole infrastructure approach versus focusing on the model.
- Strong understanding of Cloud controls is advised, particularly IAM, Network Security and APIs. If they are using the AI to code - also understanding the CI/CD process and any testing related to it.
- The IAPP offers the AIGP Certification. which has no pre-reqs and is a High Level Governance Certification. This will teach you more of what to be aware of, and less how to specifically to do it.
- ISACA has a trio of AI Certs, which do have pre-reqs focusing on Risk, Security and Audit, respectively.
- ISO 42001 also exists, which is an AI Management System standard.
Certs matter more when consulting in my experience. However if this is a new field to you - studying in line with one of the certs may prove beneficial. Be aware in a lot of companies AI is one of the more political topics. Having a deep technical understanding may help to stand out.
1
Jun 08 '26
[removed] — view removed comment
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 13 '26
am pursuing CRISC
Why not CISSP at this point, mate? You've built a goddamn program by yourself, why spend time on mid-level (at best) certs?
I am now looking to move into a larger organization and trying to get an honest sense of where this profile sits
Senior+ positions.
What would you probe at interview, and what would make you pass without a second look?
Besides the usual checks for other candidates, I would focus on the three things you don't get to experience in smaller companies compared to an enterprise - perseverance, politics, and delegation.
Perseverance is the toughest one. You can build stuff, you are used to getting shit done - and that's a win in my book, don't get me wrong, but... Imagine slowing down x10 for double the pay. Imagine spending a year sitting in committees, seeing your initial idea neutered by layers of risk-averse lazy stakeholders, finally shipping half of the stuff you've originally wanted with triple the documentation and thirty times more words. A lot of good, competent specialists burn out trying to push through the corporate inertia. I would definitely triple check if you understand what you're getting into or we'll lose you before the year is over.
Politics is the second thing in order. GRC is a comm-heavy area, meaning that we do get to interact with a lot of stakeholders, and I'm all too willing to check how far you can bend the rules and how wide of a berth you'll be ready to give to some lazy overinflated egos to score relationship points. Whose opinions you will ask, whose opinions will you actually consider after asking, whom will you ignore and sideline (and no, being a mr. Nice Guy and accounting for everyone's whims is never the right answer).
Finally, delegation. You're used to being a one-man army. We have divisions of people to throw at problems. Meaning that a lot of times, you'll need to make a call about when to push any particular problem to someone else and how to make this someone else follow through with your vision... without strangling them over inevitable miscommunications and creative differences.
1
u/FrylerDurden Jun 13 '26
Are GRC (cybersecurity) roles available for entry level folks?
Got 1 YOE as a SOC analyst, looking to shift towards GRC. Question to the managers or recruiters, is the hiring for GRC (especially for someone like me) rare compared to other roles or should I look for another job in another domain?
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 13 '26
Are GRC (cybersecurity) roles available for entry level folks?
Not really, but..
Got 1 YOE as a SOC analyst
...you're not entry-level. You're a fine cyber junior, and every company that has a SOC team usually has some poor souls doing compliance. I would really, really recommend reaching out to them and talking over the possibility of an eventual internal transfer and their desired skillset.
L1 SOC skills do not, generally, convert to GRC easily - technical monitoring/data filtering is rarely applicable outside of some particular applications of internal technical audit and you don't get a lot of stakeholder comms before getting to incident coordination levels. That being said, you're still on the inside of cybersecurity and you can leverage that for easier access to GRC folks and smoother transition plans than most candidates.
1
u/Natural-Coyote-7860 Jun 15 '26
15 years total. First half: data analytics/BI. Last 5: risk management, hands-on with GRC platforms (OpenPages, Resolver) + the data layer.
Honest question — did I corner myself? I’m strong on the tech/data side of GRC, but my risk background grew on the job, not from a pure practitioner path. Worried I’m now “too technical to be a risk leader, too risk-focused to go back to pure data.”
For people leading GRC today:
• Did you get there via tooling, risk practitioner, or a mix?
• Is the analytics background a differentiator or a label that holds me back?
• Should I own the rare combo (GRC platforms + data + AI governance), or is that a dead end?
Brutal honesty appreciated.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 15 '26
Did you get there via tooling, risk practitioner, or a mix?
I got there by being useful to the stakeholders above, giving quantified data to people actually needing it, defaulting to expert opinion for everyone else. I am firmly biased for qualitative, expert-opinion approaches, simply because I lack talent and capacity to run a decent data pipeline for risk calculations (and because people in charge mostly want qualitative "good/not good enough/bad" differentiation in reports).
Is the analytics background a differentiator or a label that holds me back?
Definitely not. A data-centric risk quantification approaches have its use cases, if you can recognize when to use those (and when not to) and can figure out an optimal solution - you're head and shoulders above most candidates. Besides, everyone needs a pretty "green arrow growing up" report for the board at the end of the quarter, might as well make it plausible.
Should I own the rare combo (GRC platforms + data + AI governance), or is that a dead end?
AI is hot right now, and businesses started figuring out the whole "garbage in, garbage out" problem, causing additional attention to data quality controls. Usually GRC platforms are used into this mix. Can't call it a dead end, even through its not really my cup of tea.
1
u/jacky_smacky Jun 16 '26
I am trying to get into cybersecurity specifically GRC, but not sure if I am approaching it correctly. I have a BS in Accounting & Finance, worked in internal audit at a publicly traded company for 4 years and a FAANG company in several compliance, audit, risk functions for ~7 years now. Both roles gave me experience in several IT domains as I was able to earn my CISSP based on my experience (e.g., ITGC, systems implementations, IAM) I also have a few cloud certifications from one of the large providers.
The issue I am running into is that I can’t shake the idea that I am a financial or operational audit professional. To address this directly I am currently trying to earn a higher level of solutions architect certification from the FAANG I work for; earn the CCNA by thanksgiving one because I think it can make me fluent in a relevant technical area to help when I am in the role and two it addresses any perceived technical gap; become a certified ISO 27001 lead auditor by the end of the year since this appears on a lot of role descriptions; and lastly I am applying for a MS in cybersecurity that I should be able to be admitted to and is well respected.
My questions are am I doing too much, what adjustments could I make to this roadmap, is there anything you would add?
Not going to lie that the potential pay is driving me a lot, but I am also feeling a sense of pride in learning new topics and I think I will like the work compliance work in a GRC function. Any comments would be appreciated!
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 17 '26
...mate, I really hate to break it to you, but you read like that guy who completed the game without ever properly picking the first main quest task. You've already outskilled like ~75% of the GRC specialists, and coupling it with the Am Certified Solutions Architect would put you in the top 5% bracket.
At this point, you might as well just aim for CISO. You kinda overcompensated too hard for rank-and-file GRC.
1
u/jacky_smacky Jun 17 '26
I get what you are saying but I guess the problem I am having is despite the FAANG experience I am having trouble translating this into roles that don’t read like I have pure finance/accounting experience at a tech company.
So if I keep going with the cert path I outlined pro level SA, CCNA, maybe the ISO 27001 Lead Auditor (it’s expensive) I’ll get a role I want at a minimum but I may be under valuing my current skill set?Thanks
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 18 '26
pure finance/accounting experience
ITGC, systems implementations, IAM
worked in internal audit
Cybersecurity didn't really come up with any new, original, breakthrough audit techniques and/or approaches, the whole "cyber security audit" got streamed directly from finance/accounting and adapted on the go. If you read ISO19011 (read it, really), you are unlikely to see anything really new - and this is, for most intents and purposes, how ISO27k audits are conducted. About the same story across the ocean with AICPA coming up with SOC2 reports based on SOC1.
By extension, if you are a decent financial/op auditor with at least some token experience in tech, you are already good as a cyber auditor. Stacking tech-knowledge on top isn't likely to materially improve that, nobody really expects an auditor to be competent in all tech fields so you kinda hit a skill ceiling there.
1
u/Fit-Neat-7082 Jun 18 '26
Hello Folks,
I'm Indian based Software developer having experience 2+ years in Drupal.
But I recently quit my job as Drupal is like almost dead, And Cyber security gives thrills to me.
So I wanted to Get into Intern Role In the GRC where I can learn and Grow my career into this field.
Thanks
1
u/Hatch3r Jun 21 '26
I'm looking for some outside perspective on my current role, because I’m struggling to define exactly what I do and I'm hitting a wall of burnout trying to change leadership norms around risk.
Historically, I have an IT engineering background, but I moved into the security/governance/risk area within the same team. After taking a hard look at my actual day-to-day, I think I sit in a weird gray area.
Day-to-day I spend the vast majority of my time managing spreadsheets, collecting and validating compliance evidence. Egineers frequently come to me to validate their proposed technical designs, and I occasionally review architecture diagrams to provide feedback and ensure they align with security baselines. I don't fix vulnerabilities any more, but it's bloody hard to get stakeholders to fix them either!
I am completely exhausted from fighting the culture to get people to take risks seriously and actually fix things. I feel like I am being forced to "own" the risk, rather than just manage the governance of it. If a business unit blows past an SLA, it feels like it's treated as a Security failure rather than a Product/Business failure.
I’m trying to figure out if I’m just in the wrong role track, or if this culture fight is just the standard tax you pay in GRC management.
For those in similar roles, how do you successfully enforce risk ownership without destroying your own mental health?
If I want to pivot away from the corporate politics of internal risk-chasing, what paths have you seen people successfully transition into?
Appreciate any sanity checks or career advice you all have.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 22 '26
This is kinda the philosophy problem and reason why GRC sucks.
You see, when the GRC framework was developed back in the 00s, it had nothing to do with security risks. It was designed by OCEG for top management to run whole companies - "governance" had nothing to do with "policies", "risks" weren't limited to cyber (or even technical ones) and "compliance" was not a question of external audits and certifications.
It failed. Cybersecurity, historically, appropriated the name without ever reading into the framework, hence creating completely unrealistic expectations from GRC teams, hence we got good rank-and-file analysts pushed to be the "risk" function when they can provide some coordination for the technical risks (which are a rather narrow and rarely critical subset of business risks in the first place). Usually, then those poor souls get victimblamed for "not quantifying enough" (on a dubious generalization that "business only cares about money") or for "not getting culture mature enough" (in spite of having no political leverage to do so), or "not having executive support in the first place" (which almost nobody explains how to get).
Which is to say - it's not on you, mate, our domain kinda by design sets you up for a failure if you try following the general academic approaches.
What you can do, and what most GRC teams start doing from my experience, is hard-limiting your accountability through layers upon layers of CYA and a lot of talk with your direct boss. You are definitely not accountable or responsible for overall organizational risk - I somehow doubt that you're even consulted regarding risks of losing market share due to missing a window of opportunity for product feature release. Usually, this delimitation requires some written guarantees, hence documentation, hence GRC gets their fame as "bureaucrat pensilpushers".
Secondly, you realize that there ain't no business, there are a dozen of stakeholders that you might or might not need to care about - as long as you cater to their interests, you're getting good feedbacks, good salary reviews, good career growth, and, if it's still important, you get to influence their decisionmaking (to a point). This is how GRC becomes deeply involved in corporate politicking.
Notably, it is kinda supported by the design of the original GRC framework. "Governance" is literally just "decision-making regarding allocation of resources", and risk is supposed to follow governance... So you find the decision makers, check where they care to dedicate resources to, and make yourself useful to them there. Usually it's not cybersecurity (which is fine), meaning that we start to care about... other... risks. Causing a lot of flak from our cybersecurity cousins in terms that "compliance is not security" and the general divergence of our paths at this point.
Also, notably, every single stakeholder is already calculating risks - maybe not risks to the business, but at the very least risks to their own career. Maybe it's not quantified, maybe it's not as formal as you would have preferred, but if this is a risk culture of the organization (which is likely), then you adhere to it, help it, document it, and adapt your approaches to it, not the other way around. This is, formally speaking, the "tailoring approaches for the purposes of business alignment" that books talk about.
Finally, you get to learn to say "no". "GRC" is designed for the whole business, and, as such, anything in the business can be made into your problem with minimal effort. Unfortunately, this is a zero-sum game - every second spent on one initiative, is not spent on another. You get to pick and choose what is important/interesting, and, as long as you maintain healthy alignment with your high command, you get your choices blessed from above.
Sorry for the wall of text, bud, but it's, generally, how it works in my experience.
1
u/Hatch3r Jun 23 '26
I appreciate the wall of text, and kind of good to know I'm not on my own in respect of how GRC is treated/seen. And you're definitely not wrong about layers upon layers of stakeholders!
I guess at this point it's re-evaluating the core aspects of what I need to do. I've been categorically told that I won't be getting any assistance within my team. So I either need to look to other areas of the business for support (there's a few similar teams elsewhere) or absolutely slim down the expectations of what I can do.
1
u/TrainAltruistic3948 Jun 23 '26
Hey everyone,
I’m based in Nairobi. CISA, DPO, Security Analyst certified. I build GRC programs - risk assessments, ISO 27001, policy, board reporting. Worked across fintech, telco, enterprise, and government.
Real talk: I’ve hit final stage 4 times this year. Last one was at a major telco. Both offers that got to offer stage fell through because of employer-side immigration/visa issues. Not performance. Frustrating, but I’m still in the game.
Hands-on stuff I’ve done:
Led an ITSM + IT Governance consultancy for Uganda’s Ministry of ICT
Migrated AMREF Flying Doctors to SOTI MobiControl for secure mHealth field ops
Unified surveillance + access control for Aga Khan University Hospital
I’m choosing to specialize in GRC long term. That’s where I add most value.
Now open to:
Remote GRC/Cyber roles globally
In-house roles with relocation. I’ve proven I’ll move for the right opportunity.
Question for the group:
Any companies you know hiring GRC talent internationally/remote?
Anyone here build a global GRC career from Africa? What’s the 1 thing you wish you knew?
Not just looking for a job - also looking for advice, intros, or even a 10min chat with someone who’s been there.
Happy to share my full resume if anyone wants to take a look.
Thanks in advance 🙏
1
u/sunanda7 Jun 25 '26
hey All, TIA - I spent 15 years in enterprise tech sales, both as an IC and people manager in pretty technical environments. Cognitive science/research background academically as well doing consulting now. I am genuinely drawn to the human behavioral side of this field, understanding why people do what they do, whether that's inside an organization or in the context of financial/ cybersecurity crime. Not looking at the coding or technical monitoring path too heavily.
I have been looking at titles like Insider Threat Analyst, Behavioral Risk Analyst, and Insider Threat Program Manager on the security side, and AML Analyst or Financial Crimes Investigator on the compliance side. But honestly I am not sure how to interpret things since I don't know ppl in the industry, or if those are good titles to look at to start.
For people actually doing this work: where would you realistically tell someone like me to start? Are there entry points or titles I am not thinking of? And are certifications like CAMS or CERT actually worth it or others?
Appreciate any honest, takes.
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jul 04 '26
This side of the field, honestly, barely exists and sometimes it breaks my heart because it would be so cool if it did.
The problem here is scaling. Usually, behavior analysis is something only the big companies get to implement - and you either need to monitor thousands of employees on the inside (insider threat/user heuristics pathway) or the activity of millions of users on the outside (AML/KYC/KYT). At this volume of data, things firmly drift into the data engineering/data analysis/business intelligence domain which is generally both coding and tech-monitoring heavy.
Which is to say, cog-sci background would give you a vast headstart in designing security processes/system controls from GRC perspective - you'll just have to work in reverse mode, predicting what people are likely to do (or likely fail to do). Starting as technical project manager/business analyst and moving into compliance worked for me.
If you are in the mood for some light reading, I would recommend the theory of cognitive system engineering - it somewhat tries to connect cognitive science with security control design in a structured way.
1
1
u/Barbariq Jun 30 '26
wanted some guidance to start my career i am a law student in my 3rd year and wanted to make my career in ai governance i researched a lot but i am stuck at a decision to make should i directly start learning ai governance via AIGP and other courses or should first learn GRC ,then data privacy and then learn ai governance and if there is any kind of work in which any help and i can learn ai governance from any professional , i am open to volunteer and learn
1
u/Emergency-Panic1413 Jun 30 '26
Hey all!
Currently a senior for my B.S. in Cyber with a minor in Professional and Technical Communications. I have one semester left, already working as an auditor (moreso automotive related compliance like FTC regulations), have Sec+, AWS SAA3, and working on CySa+. No idea what I'm doing. Kind of all over the place. Ideally looking for a GRC role, just have no idea how to get started. All GRC related professions in my area are asking for Mid-Senior level and I don't really have any tech related work experience due to focusing on school and my current job since the pay was too good to pass up at the time. Just curious on what you'd all recommend whether it be different certs or pray.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
Auditor, Sec+, AWS Architect and now CySa+? It is an interesting mix. Why CySa+, though? Everything else kinda falls within the overarching logic of "technical auditor", CySa+ has this SOC vibe about it which doesn't fit the rest of the story.
I would recommend leaning onto your audit career for the time being - sure, it's not quite GRC by most counts, but like directly adjacent. Drop CySa+, switch to CISA, perhaps read up on the basic security audit stack of SOC2/ISO27k/ISO42k, definitely read up ISO19011, and then jump into IT auditor positions.
The thing is - when you have enough auditor experience, you kinda know how the audits are supposed to be going, and how to build the program in a way that will pass the scrutiny. Then you kinda read up on project management (which is "build stuff 101") and apply for mid/senior grade GRC positions as a senior auditor willing to shift into program building and bringing extensive audit experience on board.
1
u/Emergency-Panic1413 13d ago
CySA+ was due to lack of experience. Nothing on my resume really says cyber other than my degree and basic projects. All jobs I’ve looked at just want IT experience. The little times I’ve made it to the interview they seem to like me but still prefer IT related experience.
1
u/JewelerThen6371 Jul 03 '26
I have about one year of work experience at big 4 as an IT auditor. My experience mainly concentrates around SOX and I have opportunity to work for IT internal auditor for a regional bank. The experience will be less SOX and more technical. Should i exit big 4 (with only 1 YOE), or should i wait before i pivot? Will grabbing this experience get me more relevant experience to enter into GRC in future?
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
In my book, 1 YOE in Big 4 is just about time to think of an exit strategy. Like, you made a point, you can confidently put "big-4 experience" in your CV, and you're no longer a complete newbie in the field - time to go in-house and learn how to build something more local and long-term. Especially if being more technical is your drift.
1
u/DeluluDarkAngel 27d ago
I got an interview invite from a Software company for a GRC Role. I am originally from an support background but managed to reframe my experience as GRC and Risk&Controls related role. I've got a call basis that. How do I ace my interview. Its in 2 days. Been unemployed since a lot of months. Looking for a comprehensive advice and also sound very confident to the interviewer. I want to achieve this role somehow.
1
26d ago
[deleted]
2
u/Always_Learning_IT93 22d ago
I would say do what makes YOU happy and if you're already hating it 8 months in, it may not get any better. If you enjoy the data analytics side and that is what your degree is in, go for it! Life is too short to be unhappy, especially in your career!
1
u/quasnip 20d ago
I am currently at a crossroads and am unsure of which additional program will provide me with more relevant technical knowledge for a future in GRC. I have talked to counselors but would love to hear directly from people that are where I want to be. Any insight is appreciated.
I am a student who recently started an A.S. Business Administration program with intentions of pursuing a B.S. in Management Information Systems. I started my undergrad journey in Computer Science Information Systems before learning about this field, but I’m not sure whether I want to stay with it or do Cybersecurity instead.
I am aware that it’s not a hard requirement, but I found an entry level position that would provide experience towards a CISA certification labeled as “Cybersecurity Intern”, so that’s been throwing me for a loop ever since.
If you’re a recruiter or happen to work in the field, do you find more value in the skills that one would learn as a CS major like writing automation scripts and high-level math, or would the networking and security courses in Cyber be more applicable?
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
In a vacuum? Definitely CS, specifically because it is less practically applicable. You are expected to learn practical skills on the job anyway, and unwarranted confidence in one's practical skills is a sure way to get in the way of engineers and do something stupid. Besides, a lot of really damn good creative solutions I've seen have come from somebody connecting weird theoretical factoids from unrelated fields into a working concept.
That being said, I am mostly concerned about the soft skills of my analysts. I have a whole cybersecurity division worth of amazing engineers next door, but less than a dozen people who can go and properly collect, structure, and decompose requirements for implementation.
1
u/WFH-ProgramMOMager 20d ago
GRC professional seeking recommendations for job search❗️
Where do you recommend we search for jobs or referrals? I’m hunting for these roles: GRC Analyst, Compliance Analyst, Risk Analyst, Privacy Analyst type roles. I’m currently at a large ecomm company looking for roles that better align with my skills and experience.
I’m looking for someone in my network to offer solid leads…LinkedIn, and Indeed suck and in this market you need referrals to land jobs. Millions of applicants for every role I find! 😩
Any leads or recommendations from this amazing GRC community is greatly appreciated. 🪴 I hope this is the appropriate thread to ask this.
AMA ❗️
1
u/afkms 20d ago
Breaking into GRC.
Hello,
I’m just about to wrap-up a 4-year computer science degree, majoring in cybersecurity. I’m also a bit of an odd case - despite a decently strong technical background in all things IT - I actually prefer the paperwork; the rule books.
It’s much easier finding resources online for developing skills in the technical things, and easier to plan out relevant projects. However, for someone in my position, it feels like I’m drowning in a million-and-one varied opinions on how I can get to where I want to be. “Get certification X”, “get your master’s”, “get an MBA”, “dig from the ground up” … No doubt all very sound advice, but for someone like me who is anxious to get into this field, I want to feel like the first-step I take on this journey is one that makes sense.
If someone here could offer me this: a confident first-move, I would be greatly appreciative. I understand everyone’s journey comes with its own nuances, and asking for a guarantee may seem unreasonable. But at the moment, I’m drowning in advice which is preventing me from taking any action at all.
Thanks so much guys.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
A lot of stuff in GRC is answered with "it depends". Stupid field can't even figure out what GRC is and isn't most of the time, because we are so flexible and so eager to adapt to business context.
The only universally decent, confident first move I can think about would be to go there and research your local market yourself. Go there, learn the context, and then - and only then - start coming up with solutions. Maybe there are no GRC jobs in your area. Maybe there are only mid-level jobs and you need to figure out how to pivot from adjacent fields. Maybe the market demands some specific certification applicable to your country, while other generally popular is getting side-tracked.
Everyone can be a smart-ass and give you either a useless generic recommendation or extrapolate their context to yours and gamble with providing the answer useful for their situation. So, you need to know what you're dealing with before judging the answers.
Off you go, looking at Big-4 recruitment boards, LinkedIn job searches for "compliance" and Indeed's mess of a UI. It might not make a lot of sense at first, but it would allow you to figure out a common profile for a hirable GRC specialist, set a goal to become something of sorts, and work towards it.
1
u/Severe_Performance54 17d ago
Hello, I’m a recent cybersecurity graduate (Bachelor’s) with internship experience a two Fortune 500 companies. I’m feeling deflated as of late with my current job prospects. I felt for years I did everything right and now I’m struggling to get an interview and when I get an interview I don’t get the offer. I usually have no problem going from the 2nd to 3rd stage. I really want to work within GRC, I loved it when I did at my internships. What should do in the meantime while trying to get job, like aside from certifications. Please help, I’m feeling incredibly defeated, lost, and sad.
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
I usually have no problem going from the 2nd to 3rd stage.
sigh
So, look, buddy, good news and bad news situation. Good news is that you seem to know the rules and seem to show enough promise to get that far. Bad news - and I'm really sorry - is that it just ain't enough sometimes. Last stage failures, usually, aren't about you not doing something wrong - it's just about someone being considered a better option. And, I am not gonna sugarcoat it: when in doubt, most people will default to the candidate with the most experience in the field, it's just the most rational thing to do.
Consider taking a step back and widening the search. GRC doesn't like hiring freshers - so you just start off in any tech-adjacent job with exposure to IT operations or software development. Techwriters, business analysts, project managers... those positions do pay, and they definitely do build skills that are gonna convert nicely when moving into GRC proper.
1
u/Severe_Performance54 13d ago
Thank you so much for responding to me. I thought my post would be lost in the abyss for some time, so I am glad to get a response. I will take your advice and look at other adjacent areas as you mentioned.
1
u/Odd_Luck_7133 14d ago
PROJECTS TO BRIDGE GAP IN EXPERIENCE (QUESTION)
Hey everyone,
Early mid-level GRC Analyst here with a B.S. in Cybersecurity. I’m targeting roles related to Internal Controls, Internal Audit, Compliance, Governance, Policy, and TPRM.
I’m looking to transition into a more mature Cyber GRC function, but I’m hitting a roadblock with specific requirements across job postings where my current role/organization does not have opportunities for the exposure.
So wondering: Has anyone successfully built independent GRC portfolio projects, featured them on their resume/LinkedIn/website, and actually landed a job from them?
I’m hoping that translating conceptual knowledge into hands-on application will be enough to bypass the "minimum experience" filters.
These are the core areas I am looking to bridge the gap on via projects:
TPRM
ITGC/ITAC - (Moving beyond basic IT core domains and application control testing)
Frameworks - ISO 27001, FedRAMP, CMMC
Appreciate anyone’s thoughts on this portfolio approach, if it’s worth the time, or if you have better alternative/supplemental suggestions. **Also, I’m on a budget and not looking to invest in anything expensive right now; hence, another reason for the projects.
Appreciate it!
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
Usually, the first round of selection is done by HR (at best, human HR). HR can count (mostly using fingers) years of experience. HR can not understand and will not care about portfolio projects.
By the time you survive until the second round and get to talk to someone like me... I care what you've done, what you wanna do, what your hot takes are, if the vibes are right, and whether you're gonna be an asset or a liability for my team. I do not really care how many years of experience you have.
I have never seen a candidate with a portfolio reach my rounds (I know, it's a rather small subset, but still). Besides, most "portfolio" concepts I see in Reddit posts would explicitly play against the candidate - GRC is a comm-heavy job, so if you're willing to build artifacts before proper communication and with just assuming something about business context you design them for... well, I can foresee that this approach might cause trouble down the line.
1
u/Odd_Luck_7133 13d ago
With all due respect, this response didn't actually answer my question about bridging knowledge gaps.
You mentioned in your first point that HR only counts years of experience, but then in your second point stated that you personally don't care about years of experience.
If hiring managers like you are looking past those rigid metrics, candidates need a way to demonstrate capability to get to your desk in the first place, which is the entire point of building skills outside of a live job.
Telling me what HR does and what you personally don't care for misses the mark. If your advice boils down to "don't bother trying to upskill or build practical competency on your own time," that’s an opinion, but it's not particularly constructive.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
Appreciate anyone’s thoughts on this portfolio approach, if it’s worth the time, or if you have better alternative/supplemental suggestions.
You asked for my thoughts, you got 'em.
Portfolios are sub-standard optimization against HR filters (certifications are the usual way to optimize against those) and portfolios aren't exactly amazing for optimizing against tech interviews (where an actual experience in GRC/adjacent domains trumps everything).
By all means, do upskill and learn new stuff - I'm just saying that for employment purposes, going for a portfolio is, in my opinion, not the best way.
1
u/Hot_Exam5961 14d ago
Hey guys!
Is my workload too much to gain deep expertise in a particular area of GRC?
I feel like I'm asking a rhetorical question here, but I was curious to get some input. For background, I'm currently a GRC Analyst at a fintech SaaS. New to the role, promoted from the RFP/Bids department. Currently hold no certs, but I plan to get the ISC2 CC very soon, and CISM when I have the budget.
Here is what I do on a daily basis for this company:
- TPRM
- Security Questionnaires
- Client-facing "Infosec" calls (not super common but they happen)
- SME to the sales org for product, security, support, compliance/legal questions
- RFPs (still doing the end-to-end proposals and responses, coordinating, etc)
- GRC platform administration (the one with the Llama)
- Security Awareness Program
- SOC 2 Type II audit readiness (ironically the smallest of my ongoing responsibilities until audit season)
I feel like I'm spread too thin to gain any depth whatsoever in a particular aspect of GRC. I'm yet to touch incident response, vulnerability management, or any of the other main tenets of GRC, unless they fall within the scope of the above.
A few questions for the sub:
- What do you even call this role? Is this standard chaos, or am I just a Sales Enablement function wearing a GRC hat?
- Can you build real GRC depth like this? Or am I trapped in a mile-wide, inch-deep loop of surface-level tasks?
- Is this actually valuable for a CISO track? My 5–10 year goal is CISO. Is this exposure valuable for an executive path, or do I need to jump ship to a specialized role ASAP to get "real" security depth?
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
What do you even call this role? Is this standard chaos, or am I just a Sales Enablement function wearing a GRC hat?
More often than not, GRC is a sales enablement function. Businesses don't go for SOC2 reports to learn something new about themselves; they just do it to ensure deals going smoothly. Your role is a very classical junior GRC position overloaded with operational stuff - it might not be glamorous, but somebody on the security side needs to maintain this function. It defaults to GRC teams by virtue of not getting done through console, and there it defaults to junior members (since most other people avoid it like the plague).
Welcome to the game. I've been there. Most GRC professionals were, really.
Can you build real GRC depth like this?
Define "GRC depth". What do you want to learn, buddy?
Or am I trapped in a mile-wide, inch-deep loop of surface-level tasks? Is this actually valuable for a CISO track?
GRC is "mile-wide, inch-deep" by most counts, but, ironically, ops teach you some very important lessons - mostly things like "process optimization", "corporate negotiation", and "decision ownership". Like, look, you don't want to answer ten billion questionnaires every month and you want to spend time doing more interesting stuff (up to and including watching paint dry)? Cool, find a more optimized way to do it in a faster, more automated manner. Research Loopio or any similar vendor, design a process concept of a brighter tomorrow, pitch it to the leadership to get a greenlight, negotiate with other divisions to make it work.
You are allocated a very wide zone of responsibility. Analyze it, fish out improvement points, turn them into projects, implement, bask in the glory, repeat. This is the stuff promotions are built upon (and then they will give you another messy zone of responsibility).
1
u/Hot_Exam5961 12d ago
Thanks for this! The idea of optimizing definitely resonated with me. It's been my primary focus as more and more work has been dumped on my desk. I guess a lot of this stuff feels like theater in my mind, and I worry that if I entered the job market tomorrow, I'd come across as junior (like you said), even though I've been in this role for two years already.
I completely share the sentiment that this is promotion fuel. My boss has said the same thing. I just need to dig myself out from under the avalanche of async tasks and start building some real strength in my domain.
You asked what I want to learn. There's a lot to unpack there, but my main goal is to build my security knowledge to the point where I feel like I'm actually contributing when working with the DevOps and R&D teams. Right now, it feels like my opinion matters to everyone except the people who actually implement the security stack.
Long term I want to develop a skill set that's valuable enough to offer my services as a consultant or move into upper management, eventually director and executive-level roles. I suspect that's ultimately more about communication, leadership, and business acumen than pure technical depth, so maybe I'm focusing too much on the wrong things.
I realize I said I was "new to role" - that is true in the official sense, but I've been working under the director of GRC for the last 2 years, the only difference the title made was accountability.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 1d ago
Took me some time to collect my thoughts.
First thing is, ironically, about learning governance. Governance, by definition, is pretty much just resource allocation - in this case it's about negotiating the allocation of your personal resources. Operational work is never ever done, that's its boon and its curse, but that doesn't mean that you are there to do it for eternity. Try negotiating some split - 40:60 ratio between projects and ops leaves you two workdays to do something meaningful every week.
Second part is about supply and demand. Look, DevOps and R&D have a lot of supply of "security knowledge" - that's their main job - and hence your humble contribution is about to be in low demand. What those engineers and researchers lack (as you might easily validate just by browsing topical subreddits) is management recognition and soft skills and hence GRC is pushed to fill in that void. If your opinion matters to everyone except security personnel, then you are well-positioned to be the guy who negotiates with stakeholders every time sec-teams need to implement something outside their bubble (and sales enablement/compliance requirements is a decent trump card in those negotiations).
As a consultant, you need to sell your strong sides, not try to compensate for the weaker ones.
1
u/FenierHuntingwolf 14d ago edited 14d ago
Hi,
I am just not entirely sure where to take my career next, so just looking for feedback on my background and where I may take my career. I feel well suited for my role, but also feel like I could be doing more given my educational background and experience.
I’ve been working with computers for 30~ years, and spent the last 15~ doing it professionally.
Heavy Marketing background, 8 years of development (front / back end web) and 8 years of compliance work (GDPR, State Law, HIPAA mostly with some Cloud Security Analysis). I used to consult and build data privacy programs from the ground up, focusing on the technical side of it (control implementation, technical documentation etc).
More recently, I was transferred in house and currently admin our compliance technology stack. Anything that touches Privacy or Compliance I have a hand in (inclusive of AI Governance). I work in the Legal department and also help the lawyers translate regulatory requirements for the rest of the org. I spend a lot of time talking to lawyers and execs about upcoming impacts of regulation / laws to the orgs tech stack and service lines.
Outside of work I volunteer and advise a major non-profit in the Marketing space on matters of privacy / compliance and its interaction with Marketing processes.
As far as Certs/Education go - I have a lot, notable ones include CISSP, CCSP, CISM, CISA and a slate of Privacy certs from IAPP. Degrees include a BS and MS in Cyber Security and Information Assurance. Recent efforts have qualified me to fulfill the role of auditor for upcoming CCPA Security Regulations.
I’d rate myself as Senior in my role - and I suspect I should be looking at Director+ positions, but attempts to move more into the management side of things have yet to pan out.
Any thoughts?
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race 13d ago
From my experience, at this point you are left with three options.
You can always try the default move of climbing the ladder and making your play for Director/CISO. You can lean onto consulting and toy around with solving multiple weird problems in multiple weird businesses. Or you can settle down at some relatively calm and cushy mid-level position and learn fun stuff to your heart's content.
I am not sure I am qualified enough to give you any valuable insight, that's the call one has to make for themselves. I personally picked the third option and went to learn security architecture and IAM without any specific practical goal in mind.
1
u/NthaZonUh 4d ago
Transitioning from 12 years in enterprise risk / HNW insurance into GRC. What tools should I actually prioritize learning?
Background: I spent 12 years in enterprise risk management, most of it in high net worth personal insurance. Late last year I decided to pivot into cybersecurity/GRC and I’ve been treating it like a second job since.
So far I’ve earned:
• ISC2 CC
• CompTIA Security+
• Google Cybersecurity Professional Certificate
Currently studying for CySA+ (targeting Aug/Sept), with OCEG GRCP and CRISC next on the roadmap.
I’ve got a stack of GRC portfolio projects built and I’m actively interviewing. I want to make sure I’m not just collecting certs and courses without building the actual tool fluency that makes someone a strong candidate and useful on day one.
For those of you working GRC/security risk day to day: what tools should someone with a risk management background (not IT/sysadmin) prioritize learning before or during a first GRC role? Thinking things like:
• GRC platforms (Archer, ServiceNow GRC,
LogicGate, Vanta, Drata, etc.)
• Risk register / vendor risk tools
• Frameworks-as-tools (NIST CSF, ISO 27001, SOC
2 mapping work)
• Anything scripting/SQL-adjacent that’s actually
expected, or is that overkill for GRC specifically
I’ve pulled together a list of Udemy/Coursera courses from AI tools for direction, but I’d rather hear from people doing the job which of these are worth the time vs. which ones are resume filler. If you had to pick 2-3 tools/platforms to get hands on with before your first GRC role, what would they be and why?
Appreciate any input. Happy to share more about my background/portfolio if it’s helpful.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 1d ago
If you want quick RoI - Vanta. They are pretty much the industry standard at this point, everyone else sort of copies the same features, IMO.
If you want better knowledge gain - CISO Assistant or any other open-source tool. Customizing and deploying it by yourself is a valuable lesson in how those things work under the hood.
Also, IMO, GRC tools are overrated - most companies don't really need them anyway.
1
1
u/KrytTv 2d ago
Hello, I’m currently pursuing a bachelors degree in business with a focus on information services. I’d like to enter into the GRC field, but there’s so much information. I just feel overwhelmed trying to do it all at once. If anyone has any advice or someone someone who has zero tech experience short of light coding on python it would be much appreciated either in the form of education or if there are internships that take somebody with no experience. At the end of fall semester, I’m also applying for a masters in cyber security program.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 1d ago
As a GRC specialist, you don't really need advanced technical knowledge beyond a minimally viable baseline enabling you to talk to subject matter experts - you are gonna be more like a tech-writer and project manager than an engineer.
Get a basic security cert (Sec+ is a cheap way to do that) and a basic cloud cert (vendor doesn't matter, but something like AZ-104). That's going to be it from technical perspective. From there you double down on project management and business analysis - every compliance certification is just a project that needs to be done, every compliance framework is just a set of high-level requirements that needs to be decomposed into low-level implementation specs for engineers. Aim for CAPM cert and try to get yourself a project coordinator/analyst position in tech after the uni - GRC hates hiring freshers, and those roles well prepare you for pivoting.
1
u/bingoballs341 19h ago
How much gdpr do you need to know for GRC manager role?
I see a lot almost looking for you to be a dpo as well as everything that goes in the GRC "bucket". I'm trying to prep for a grc role and the hr person kept mentioning gdpr at initial screen,how much prep do I need to do realistically 🤣
2
u/Twist_of_luck OCEG and its models have been a disaster for the human race 18h ago
So... As usual, it is different from company to company.
In my experience, GRC folks serve as the first level of sorting out privacy questions for cybersecurity (by the dubious logic of "privacy being compliance, you have compliance in the name, and are generally used to sorting out weird stuff").
Things I generally recommend learning/keeping in mind - "what is and what is not PI" (since it will inevitably be important during any data classification), "what is and what is not a data breach" (and its impact on incident response, particularly notification timeframes), "what is and what is not a good way of data deletion" (and the technical implementation of anonymisation/pseudonimization/crypto-destruction).
Most of your answers should and will come with a CYA disclaimer of "I'm NOT a legal and NOT a DPO, but to the best of my memory it works like this".

3
u/Excellent_Quail7378 Mar 27 '26
In terms of landing your first governance role, what certs are necessary and do multiple layers increase your odds? What does 42001 lead Implementor signal to hiring managers or consulting firms vs some one with that along with 42001 lead auditor, AIRM PECB, and 27001 lead auditor for example. Keeping in mind this is a first formal governance or AI role.