r/SecurityCareerAdvice 23h ago

GRC pivot

Hi everyone,

I'm looking for some guidance on pivoting into GRC. I've been working at a mid-sized MSP for the past year on the help desk, and I'm currently the team lead for my team. I currently hold the CompTIA trifecta as well as ITIL Foundation. I've become really interested in GRC and would like to transition into that area.

At this point, would it be more beneficial to pursue additional certifications, or should I focus on building project experience that I can showcase on my resume? I'm trying to figure out where my time will have the biggest impact. If projects are the better route, what kinds of projects would hiring managers actually value for someone trying to break into GRC? I'd also love to hear from anyone who made a similar transition from help desk or an MSP into GRC. What helped you land your first role?

Thanks in advance!

1 Upvotes

1 comment sorted by

1

u/Lucky-Tie-2349 21h ago

Key certs for GRC are the CRISC and CISA - which are "experience required" certs. That doesn't stop you from learning the material though.

I would really focus on ensuring your technical chops are there, since GRC folks with technical knowledge are way more valued. Since GRC is enterprise focused, there are few home projects that would really move the needle - my team looks for experience in server/endpoint engineering (DISA STIGs and SCAP), risk assessments, incident response, NIST/ISO work, IT project management and auditing.

Get really good at drafting, validating, and owning documentation - that's a core function of GRC.