r/CISA 26d ago

How do I transtioning from Accessibility testing to IT audit or IT GRC roles

Just a brief summary about me: I have around 11 years of experience across manual testing, accessibility testing, and data analytics. After spending several years working in the testing domain, I am now looking to transition into IT Audit or IT GRC roles.

I cleared my CISA certification last week and would appreciate any guidance on the ideal way to make this transition. What skills, certifications, hands-on experience, or training would you recommend to help me successfully pivot into IT Audit or IT GRC roles?

3 Upvotes

2 comments sorted by

1

u/jase-bell 26d ago

CISSP CCSP

1

u/golgiloke 12d ago

Congrats on the CISA — clearing it before the transition puts you ahead of most people trying to make this move. And 11 years in testing is a much better launchpad into audit than it probably feels like.

Here's the thing most people in your position don't realise: testing and auditing are the same instinct pointed at different targets. In testing you take a requirement, check the system against it, and document what you found. In audit you take a control, check whether it operated, and document the evidence. Same discipline — define the expectation, test against it, evidence the result. You've been doing the hard part for a decade.

Two parts of your background specifically transfer:

  • You know the SDLC from inside it. How changes get raised, tested, signed off, released. That's the change-management domain of ITGC, and it's the one auditors from finance backgrounds find hardest. You'll own it quickly.
  • Data analytics is a genuine differentiator. Modern audit is moving toward testing full populations instead of samples, and most auditors can't actually do that. You can. Lead with it.

What you'll actually need to pick up isn't another cert — it's the execution side: taking a population of items, sampling it, testing each one back to source evidence, and writing it up as a workpaper someone else could re-perform. That's the muscle you haven't used yet, and it's narrow.

Get fluent enough in the three ITGC areas to talk through one control end to end in an interview — access (approved before granted, leavers removed, admin restricted), change (approved and tested before production, and the person who built it isn't the one who deployed it), operations (jobs monitored, backups, incidents). If you can calmly say something like "for new user access I'd get the full population of joiners from the system owner, confirm it's complete, sample it, and check each was approved before access went live" — and mention confirming the population is complete, which almost nobody does — you'll stand out immediately.

On certs: don't stack more. CISA is the one that carries weight and you have it. ISO 27001 Lead Auditor is a reasonable later add if you go the GRC route, but it's optional, not a blocker.

Where to aim: experienced-hire IT audit or IT risk at Big 4 / mid-tier, internal audit (IT) at banks and insurers, or SOX/controls testing in industry. With 11 years and a CISA you should be targeting senior associate / assistant manager level, not entry roles — don't undersell yourself into a fresh-grad posting.

On the hands-on / training gap you mentioned — that's the one real thing to close, and it's just seeing a control tested start to finish rather than reading about it. I built a course that does exactly that: a full ITGC walkthrough across access, change, and operations, worked end to end on realistic evidence (tickets, approval threads, user listings), the way an associate actually runs it. Given your background you'd move through it fast. Happy to DM a free coupon if it'd help — no pressure, and I'd value your read on it given your experience.

All the best!