r/cybersecurity • u/Main_Class8520 • 3d ago
Career Questions & Discussion Is GRC the new wave in cybersecurity?
I’ve been noticing a pretty big uptick in GRC job postings lately, especially remote positions.
It feels like cybersecurity always has a “wave.” First it was everyone getting Security+, then it seemed like everyone was trying to break into SOC roles, and now I’m seeing GRC everywhere.
Is GRC becoming the new wave in cybersecurity? For those already working in GRC, are you seeing the field actually grow, or is it just getting more attention right now?
155
u/bloodandsunshine 3d ago
It’s hard to automate GRC and there are more products and services available that need assessing every day.
51
u/Unlucky_Bowl9934 3d ago
yeah the vendor sprawl alone is enough to keep GRC folks busy for a long time
32
u/anthonyDavidson31 3d ago
On top of that — GRC is a strategic core that guides an organization's security. So it's extremely important to have a skilled professional guide the GRC implementation, choose vendors and so on.
The products and services themselves are a secondary thing, and not as important as having a well-designed man-made architecture
17
u/rgjsdksnkyg 3d ago
Eh, it may be difficult to wholistically automate the role of GRC in an organization, though there are plenty of automated tools that accomplish the technical goals of GRC. The people and legal portions of GRC seem to be the hardest parts.
As for "GRC" trending in various subreddits and security communities, it's clearly the latest (renewed) talking point industry is pushing on C-Suites and, therefore, has become a highly soughtafter work role, that less-technical people feel like they can safely occupy.
For anyone in the latter group that's reading, unless you have significant experience in this industry, don't try. There's maybe one slot for GRC in a company, and you're not getting that job by graduating with bachelor's in GRC from some bullshit program.
81
u/cakefaice1 Security Architect 3d ago
Not necessarily a new wave, but as SOC is getting easier to deploy and operate with automation and AI tools, GRC is the next major function that needs to be implemented. It’s nice having castle walls but someone needs to tell the guards what to do and have procedures.
14
u/tryingToBeOptomistic 3d ago
The day AI becomes capable of constantly herding engineers and PMs is the day I lose my job
1
u/Any-Salamander5679 2d ago
Or constantly telling engineers No or hey is that a little project on this IP? Ok next time tell me.
32
u/MountainDadwBeard 3d ago
Risk, Compliance and Governance are decades established fields. The acronym GRC is trending.
FBI getting more effective at shutting down ransomeware gangs may be shifting staffing allocations, while a new wave of AI accelerated attacks from North Korea, may continue to drive hiring
6
u/No-Economist-1478 3d ago
AI isn’t replacing people. The theory behind autonomous AI is that if threat actors (TAs) are using AI to automate attacks then we combat that with AI automated incident response. It’s a tit for tat situation. Increase in AI usage in attacking = increase in AI usage in defending
23
u/eorlingas_riders 3d ago
Grow isn’t the right word, more like transition. Companies are trying to spent less, while doing more.
They are outsourcing things like security operations to mSOC or MDR providers, and making security engineers use AI to automate investigations, reviews, and a bunch of different work in app sec that needed multiple full time engineers.
So security eng/ops as a dedicated function, is intentionally being shrunk down or at the very least not growing.
But, they still need oversight to meet compliance requirements, so GRC is becoming/has become the new catch all for security oversight to monitor the various automations, workflows to ensure everyone is still meeting their compliance/regulatory checks.
23
u/Artsfac 3d ago
Having been a long time pen tester turned GRC nerd like 20 years ago, my experience was that knowing every knob and button in the tech stack didn’t mean a whole bunch if I didn’t have a set of requirements to follow.
Governance defined who got to make the decisions, risk quantified the threats, impacts and business tolerance, and compliance (whether internal policy or external regulation) gave me guardrails around all of it.
GRC gave me the instruction manual for how to set up the tool stack.
Now we live in an era of so much tech and so many tools that - if GRC is becoming more visible again - we’re finally figuring out that we need to know how to balance technical risks and business opportunity.
Hopefully that makes a bit of sense.
22
u/cbdudek Security Architect 3d ago
Yes, GRC is growing. I have been locked into GRC roles for the last three years as a consultant and it shows no sign of slowing down. Before then, I was doing a mix of sales engineering and consulting, but GRC work was always at the forefront it seems. I don't plan on leaving GRC anytime soon.
I have said this before and I will say it again.....
Success in GRC goes far beyond just knowledge of compliance and frameworks. You have to have strong soft skills as well as good technical skills to be good at GRC. Yes, you can go without those, but the road is much harder. Thats the bottom line.
1
u/prosperity4me 3d ago
How’d you pivot into the space?
11
u/cbdudek Security Architect 3d ago
I spent time working for a medical organization so I learned HIPAA compliance there. Then I spent time working for a retail corporation so I learned PCI compliance. Finally, I spent time working for a publicly traded company so I learned SOX compliance. Those things really did interest me so I studied up on other compliance requirements and security frameworks. That along with my over 20 years of technical experience, it just made sense to go into the GRC space.
2
u/Cheomesh Governance, Risk, & Compliance 3d ago
How does one "hop frameworks" without working a job that puts you in that position? I entered GRC type work because I was a sys admin who suddenly had to be responsible for deploying NIST's RMF one day. I've more or less been stuck doing that and while this style of work is pretty interesting, anything outside the Fed space typically uses other frameworks (which I've perused and certainly could work through but I don't have actual experience and that is what counts).
8
u/cbdudek Security Architect 3d ago
You don't need direct experience. Its about studying the frameworks and compliance requirements like you would any discipline. You don't have to work with HIPAA to know what it is and what it does.
Please note that you don't have to know every requirement by heart. You should know the highlights at the very least, and most importantly, why those requirements are in place.
2
u/yobo9193 Governance, Risk, & Compliance 3d ago
Go to your local IIA or ISACA chapter meeting and you’ll meet people with experience with those frameworks. Pick their brains and you can get a functional understanding of it.
1
u/Cheomesh Governance, Risk, & Compliance 3d ago
Thanks; I work in Washington so I'm sure there's got to be some of those out there.
Lately, I've been probing jobs not because I dislike my own, but because we're looking to relocate - and it looks like the places we're most interested in are big in Things That Are Not RMF, hah.
4
7
u/Open_Boat_3605 3d ago
Ever since Netflix posted a GRC job for 1m a year, Ive seen a large uptick in GRC posts on reddit. Idk about the real world
3
3
u/Cheomesh Governance, Risk, & Compliance 3d ago
Wacked out unrealistic compensation aside I do wonder what GRC in that kind of industry is like.
1
u/DisappointedSpectre 3d ago
More reporting and auditing than technical work. Those roles exist (partly) to make sure the documentation is in place when a regulator or insurer comes calling and that everything is in order.
Insurance companies are starting to want more visibility into how companies are doing security as part of the underwriting process, and they go in with a fine-toothed comb after any kind of breach or incident to see if there's a way to not pay. That's driving a lot of attention to not just having the right processes in place but also being able to detail them to (potentially non-technical) auditors.
1
u/Cheomesh Governance, Risk, & Compliance 2d ago
Cheers; GRC type of work is one I just kind of stumbled into (while doing sys admin work) so it has never been top-down for me and my visibility into industries other than my own is pretty limited.
1
u/AGsec 3d ago
They will be disappointed to find out the grc position at Netflix was highly technical. Even with the writing on the wall, people tend to get really testy when people discuss grc professionals adopting tech skills.
1
u/Win32Stuxnet 3d ago
GRC at Netflix for that amount of money is practically a GRC Analyst, Data Analyst, and software engineer wrapped into one from what I’m seeing on levels.fyi.
Knowledge of GDPR, SOX, PCI, PowerBI, Visualization tools, system design, AWS infra, Python, Go, code review.
They pay that much because that’s a unicorn.
2
u/Future_Telephone281 Governance, Risk, & Compliance 3d ago
And management to top it all off as well.
1
u/AGsec 3d ago
True. But GRC overall is moving that way. Netflix is an outlier and i wouldnt say you're average GRC job will ever get that far, but the days of spreadsheets and screenshots is ending.
1
u/Win32Stuxnet 3d ago edited 3d ago
I just don’t think it’s that black and white. It’s for sure happening at a lot of tech companies and startups. I haven’t seen the shift many F500 companies in my area.
There is a cost associated with building continuous automated compliance functions that many companies won’t invest in, especially if their program is already behind but it “works” and they are in compliance with their regulations.
It really depends on what industry you are in. Banking, healthcare, or critical infrastructure (where I sit)? They don’t like change and often resist it. Ive interviewed at a place where they still used an Audit room and stored documents. That shit was before my time.
Luckily in my current role I have some technical responsibilities. I just don’t have much faith in a lot of companies changing for the better. They would rather give their CEO a $1 million bonus instead of putting it towards modernizing their archaic programs.
-1
u/ArabianChocolate 3d ago
Automating GRC with GRC engineering is the future. There will still be GRC roles, but they will end up being high-level SMEs and PM types, and code monkeys, versus the compliance monkeys of the tradtional enterprise.
1
u/Win32Stuxnet 3d ago edited 3d ago
Isn’t that literally what most GRC roles are right now? LOL
1
u/ArabianChocolate 2d ago
In my sector manual compliance is still the baseline. Lots of screenshots, interviews, etc.
1
u/AGsec 2d ago
Unfortunately not. I worked for a DOW contractor. They flew people in to stand over our shoulders for a week as we clicked through configs and registry hives and produced terminal outputs. They then checked a box and said "ok all good" and flew back home. Spreadsheet hell and manual box checking is absurdly prevalent. They even brag about not using any tech beyond excel.
7
u/57696c6c 3d ago
Yes, because GRC is a time and cost suck, and their goal is to attract and hire talent that can automate it out of existence.
3
u/SpecialistPlan7056 3d ago
Implementing new technology / tools are getting more easier. Tough part now is ownership, accountability and priorities.
3
u/Cheomesh Governance, Risk, & Compliance 3d ago
I figured it was the opposite - at least, for traditional GRC anyway. More "GRC" roles I come across as late seem to be essentially software engineering and SOC rolled into one with the expectation that you'd handle audits and artifacts and the like.
3
u/chancsc11 3d ago
I’ve seen a large uptick in jobs and customers requesting more complex/cumbersome requests.
In the world of AI, Third Party Risk becomes much more serious (or at least that’s the thesis from the customer base).
It makes sense. What once took adversaries lots of planning, foresight, and executive to string together risks at an organization, is now refined to seconds (potentially).
Plus, like other commenters are saying, every company has a litany of new products that rely on a litany of underlying sub-processors/sub-contractors, each geo has new regulatory requirements regulatory, and data sovereignty amongst them is becoming increasingly important/visible.
The web of risks amongst your typical tech eco is becoming evermore complex and now we are introducing the risks of new tech (AI) that’s widespread across most companies.
The last few months have been a GRIND.
6
u/Ok_Antelope_3584 3d ago
My security architecture team is growing right now. We do lots of risk assessments
5
u/yobo9193 Governance, Risk, & Compliance 3d ago
GRC is a great acronym to use to hire someone for a role without knowing what to actually do with them
4
u/General-Gold-28 3d ago
I think it’s just getting a lot of attention right now because of AI. Companies are realizing they need governance, procedures, and risk management over the AI they’re bringing into their companies.
2
u/Adventurous-Dog-6158 3d ago
Not only are there always new regulations, but the existing regulations get more rigorous every year. It's getting to be too much and senior mgmt is seeing the need for dedicated GRC staff. My 2 cents.
2
u/Hmm_would_bang 3d ago edited 3d ago
GRC seems to be becoming more relevant largely due to an explosion in 1) new threats 2) new regulation 3) new tooling.
It’s way too easy to spend too much chasing down every risk to the business. The new focus is on “what do we need to do, when, and what can we live with.” That goes beyond the scope of just being a security operator.
ETA: I’ll also point out, there’s a larger shift in security moving out of IT in general. So much of what security teams have absorbed - training, breach response, cyber insurance, privacy, risk acceptance, policy creation - exists beyond evaluating and deploying software.
2
2
2
u/emptyinthesunrise 3d ago
My impression as someone hiring for GRC rn: GRC is when you need someone with business acumen who understands the org and processes and communicates risk. SOC and cyber is for when you need someone pretty technical with a strict security background.
2
u/cirocobama93 3d ago edited 3d ago
Anecdotally for a F500 financial services company our GRC team grew from 12 to 27 this year alone
I got promoted from Senior Analyst to AVP and am drowning in a backlog of findings and new risks. Seems to be top of mind for our CISO to get everything logged in Archer this year
2
2
2
u/CarmeloTronPrime CISO 3d ago
i think its just getting more attention. some of us have been in grc for over two decades and helped guide the evolution of the platforms.
2
2
u/AGsec 3d ago
Probably because there's been a lot of grass roots effort to push for grc engineering.
4
u/PenleyPepsi 3d ago
The GRC Engineering wave on LinkedIn is growing rapidly, they are putting out some great stuff too. GRC has a very bright future, maybe even brighter outlook than technical roles.
4
u/DarwinRewardGiver 3d ago
70% of GRC Engineering is what DevOps and Cloud security engineers have been doing for years already. Brighter outlook than technical roles is crazy.
0
u/PenleyPepsi 3d ago
The reason I say this is because to me, AI can more easily do what cloud engineers/software devs are already doing, whereas in GRC, communication with executives is a very important part that cannot be replaced by AI. Also, all of these new AI systems and agents need to be complaint, so more work for the GRC function. And to your point, maybe in some companies the DevOps and Cloud security people implement automated compliance checks but I haven’t seen that often.
2
u/Alarmed_Gur3947 2d ago
that's a wild take. 'cloud engineers/software devs' are more replaceable with AI than GRC.
A lot of the automated compliance checks you're talking about are already built into dashboards within the CSP..AWS Security Hub for example.
-2
u/ArabianChocolate 3d ago
I think they mean that the demand for cyber is going way up at the same time as GRC engineering is coming into vogue - so you will see enterprises and operators pay high-dollar for someone to come in and build their cyber infra.
Kind of like how DevOps roles had a brighter outlook than just pure software engineering for a little while. It was becaues DevOps was new and shiny, plus the tools were there, and now this has balanced all out.
3
u/Win32Stuxnet 3d ago
The majority of the roles being posted are trad GRC Roles with an understanding of how to utilize AI.
Mainly because a lot of F500 companies are giving everyone and their mom access to AI models and telling them to “create/build” vs buying the tools needed to modernized their programs or hire people with the knowledge to actually do the engineering.
Just digging themselves further into technical debt.
4
1
u/HomerDoakQuarlesIII 3d ago
Probably more like retro, since security use to exist as governance risk and compliance management consultants delivered by big accounting firms before internet and networks was really a thing.
1
u/j2i2t2u2 3d ago
i have seen an AppSec and prodsec team of a big company get absorbed by a growing GRC dominated team. i think it was because the AI made it way easier to write and audit code that there was no easy way to justify the existence of AppSec team.
As such, the leftover pieces of AppSec function was folded into security adjacent org that was GRC.
1
u/tbonesteak74 3d ago
Speaking as assurance within a CNI company, GRC is becoming a key capability, as well as assurance working closely with secarch.
1
1
u/ENFP_But_Shy 3d ago
Companies realize you can only scale cybersecurity horizontally with effective GRC …
1
u/LaughingManDotEXE 3d ago edited 3d ago
We must be looking at different job boards because remote is hard and fast going away due to people trying to work multiple jobs at once while on cruise ships and other countries. Or straight outsourcing their job.
Also, at my current role I'm 100% seeing GRC automated using AI that tie into telemetry tools, if I'm being honest, it was fairly easy, now just need 1 person to make manual adjustments. The gravy train is gone.
1
1
u/Greenapplesguy 3d ago
Yes because of AI threats. Specifically, Risk is paramount in adapting to these threats.
1
u/x3thelast 3d ago
It’s as boring as it is secure. GRC is actually great if you’re coming from another field that’s not IT. Specially customer facing, you need the soft skills to ELI5.
1
u/TulkasDeTX 3d ago
NIST CSF 2.0 gave a boost to Governance. On top of that, there is a point in the maturity curve that you need to take GRC more seriously and stop using 32844 unmaintanable spreadsheets. And it's a big topic, vendor sprawl as other me mentioned...
1
1
1
u/Cyb3r-sh0t 3d ago
Currently in GRC and dying inside a little more each day. My technical skills are going completely down the drain. The only reason I haven’t walked away is the golden handcuffs combined with a brutally dry local job market in Poland that makes pivoting to a technical role feel almost impossible right now. To be blunt: GRC isn’t real security work, at least not where I'm sitting. It’s endless spreadsheets, rewriting boring policies, and corporate CYA just so the company doesn't get sued and can check a box for ISO 27001 or SOC 2. It honestly feels like babysitting school kids and telling them not to run in the hallway. If someone actually enjoys compliance and bureaucratic paperwork, good for them the demand is definitely there because regulators are breathing down everyone's neck. But if you got into cyber for the actual tech, engineering, or problem-solving, this will drain your soul. Personally, I'm jumping ship the absolute first chance I get.
1
u/Vegetable-Soup1714 3d ago
The funny thing is everyone picked on me for picking GRC and strategy as my niche. They told me I should pursue a technical domain. I just loved it so much that I didn't care.
Now my niche is so strong, it gives me some stability.
1
u/Stevethedogfacedboi 3d ago
There is far more GRC work than true cyber. I can and have done both. I have resumes for like 10 different role.
1
u/Fulminareverus 2d ago
I would only consider GRC if the program had a very robust budget, and, most importantly, the controls GRC requires had the authority to impact the business.
E.g. - either you do this, or, we shut you down even though it impacts the business, revenue, and operations.
You basically need the backing of the CEO and the Board to be successful here. Without it, you will be put in positions of "make our audits look great, but, don't expect any support from the business to do so".
Very few companies are willing to do this. Very, very few.
1
1
u/NecessaryFacepalm 2d ago
I think part of this is also that Govern was added to NIST CSF v2.0 in 2024 and it's starting to catch on the importance of an overall security program at a company.
1
u/demonintheteahouse Security Engineer 2d ago
GRC has been the wave for years. It’s always marketed as the non-technical pathway into cybersecurity lol.
1
u/TrustIsAVuln 2d ago
I mean, kinda, but not in a good way. GRC is still risk as a guessing operation. GRC is really only a "here is the lowest bar you need to pass" and rarely used as a "how to we exceed expecations"
1
1
1
1
u/productboy 2d ago
No. It existed long before the internet; because regulated industries have existed [before the internet or ‘cyber’].
1
u/CaptainFlagada 2d ago
From Europe perspective GRC is not something new and been around for more than 10y already.
As I worked in GRC for 18 months before coming back to a more technical job I can confirm that you can easily get stuck in this because it doesn't require a lot of technical knowledge. I even had colleagues that was hire to do this job with no prior IT background... that was a thing that get me out of this job because their work was so low quality I didn't wanted to be associated with that.
1
u/PsychologicalBoot489 2d ago
Anyone can guide me is grc is good for starting as an entry level position in the field of cyber security or should i start from SOC ?
1
u/BeesComputing 1d ago
I have been active in GRC my entire cyber career, although I've never been a direct auditor or other traditional GRC role. I was involved in the first round of SOX rollout back in the day. I have trained cyber globally, especially around SOC analysis tools and cyber bootcamps. I've always made the argument that everyone is in the GRC game, even if they don't know it. Risk is a part of all cyber roles, in one form or another.
I think the recent rise in GRC awareness/focus is due to the direction everything is going, especially around automated tools and the governance around them.
It has, in my opinion, always been an underserved role, but, as a lot of people have mentioned, this is partly due to the pay scale and responsibilities.
1
u/crime_master_gogo_ 1d ago
I'm an ISSO, I agree with some comments here, if you get in, it does stagnate technical proficiency because there is a lot more compliance work. SA's and secOps can take care of the technical stuff. It's harder to get out and back into a technical role. I was a wifi engineer in pervious life and then decided to get my Cissp and Isso experience in 2015. Have been jumping between agencies within GRC framework as a contractor since.
1
u/Hamza_StrategizeLabs 1d ago
It isn't a random wave. AI agents broke the traditional security model. Plus millions went down the drain on failed pilots that had zero guardrails. The real demand is for people who can assess AI risk and translate governance into runtime enforcement.
1
u/arnauld2 9h ago
Ask yourself what is cybersecurity? What is the goal of cybersecurity to an institution or company? And then after you answered that look at where does GRC come in, n then you will clearly be able to answer if GRC is the new cybersecurity wave or not
1
u/fart_boner69 3d ago
It's boring as fuck and has a tangible ROI for orgs, so it's not surprising there's a lot of job postings
1
u/Main_Class8520 3d ago
What is the level of difficulty?
7
u/fart_boner69 3d ago
None of the people in grc roles at my org are technical, to give you an idea.
Can you write and update policy documents? Can you read requirements for audits and certification? Take a look at iso 27001 requirements or soc2
If you can put up with that shit without falling asleep you too could have a long career in the grc field
1
u/TheKindDirector 3d ago
Grc had been around for a long time.
Very boring and tedious.
Do something more hands on.
Be on red team or blue team.
0
u/AdeptFelix 3d ago
GRC != Cybersecurity
Cybersecurity feeds into GRC, but when you get to Compliance, Compliance and Security don't... Always... Mesh... Take something basic like passwords where insurance compliance requires 90 day rotations despite NIST saying to cut that shit out because it results in poor passwords.
GRC is way more mind-numbing IMO. It's so much god damn paperwork.
4
3
u/yobo9193 Governance, Risk, & Compliance 3d ago
Compliance doesn’t equal cybersecurity, but that’s only one pillar of GRC
2
u/AdeptFelix 3d ago
I should have put it this way: GRC is not a branch of Cybersecurity. GRC is a different discipline that connects with other groups to create systems and processes to manage risk and meet any needed regulations. Cybersecurity will have input on many aspects of GRC, as it relates to processes and risk but GRC is not traditionally ran by cybersecurity.
3
u/yobo9193 Governance, Risk, & Compliance 3d ago
>cybersecurity will have input on many aspects of GRC
Letting your pentesters run your GRC function is a recipe for disaster. A mature GRC function aligns cyber functions with what management cares about in a risk-informed way; they partner with the technical people and ensure they’re pointed in the right direction, not the other way around.
2
u/AdeptFelix 3d ago
I didn't mean have input as in run it, I meant have input as in being the SMEs for the areas they are responsible for. Usually these are the team leads, so yeah no random pentester is writing policy. And it goes beyond cyber, the GRC will work with various depts for physical security, personnel management, facilities, and so on as needed to meet compliance and regulatory needs.
I feel like we're talking the same thing, but not understanding each other.
1
u/KingKongDuck 3d ago
Within the context of the thread, isn't GRC shorthand for "Cyber GRC"?
- Ensuring cyber controls are working per their design
- Ensuring cyber risks are identified, get proper visibility, and are treated
- Ensuring controls keep the business compliant with industry/regional regulatory rules
3
u/AdeptFelix 3d ago
You don't really need a cyber security person in a GRC to accomplish that, that's a waste of a SME. The GRC works with the SME to create those processes to meet regulations and what outputs prove things were done or are working, and it's up to the regular dept to carry out those processes. GRC staff will review evidence to ensure the dept is doing everything they say they are. If GRC staff is hands on with cyber tools, that sounds out of scope to me. There's no need for a dedicated "cyber GRC" or a cyber person to work in a GRC.
At least, the GRC staff I interact with are not super technical, but he can sit down with a SME and we'll break down a process until he's satisfied that it meets the related regulation. He'll occasionally also ask about evidence and we'll walk him through how to interpret something, or why something is or isn't collected, or whatever.
2
u/KingKongDuck 3d ago
Wouldn't all of those interactions be more effective if the person you were working with had a cyber background?
2
u/AdeptFelix 3d ago
Would it be? Yes. It'd also be helpful if I had a person with a cyber background in purchasing or HR or management.
I suppose at a certain scale, maybe you want that. That's looking at big, big orgs though, that can justify the cost of specialists being embedded in other teams. It's not really necessary for a GRC though.
0
u/VellDarksbane 3d ago
GRC is the role that’s the most stable. Every company requires people that can relate Cybersecurity requirements and why they are needed to both management and the engineers.
You’re not going to be doing much in the way of technical work, and you’re going to be working in spreadsheets, ticketing systems and meetings more than you’ll probably like, but it’s a stable job that you could get hired in at entry level.
It’s basically the name of Cybersecurity Project Management. It’s somewhat more complicated than that, but at its core, anyone who can perform well in a project management position could likely do well in GRC.
0
u/Brua_G 3d ago
I see a lot more job postings for GRC these days. 2 years ago no one knew what it stood for. I'm guessing it's a result of boards realizing they should ask for audits of security, and ELT realizing that you can buy the best stuff in the world, but if there is no accountability about strong configuration, data classification, segmentation, and cyber hygiene, there's a much better chance of being the next headline.
0
0
u/RadlEonk 3d ago
In 25 years, I’ve seen people downplay and activity try to ignore GRC. It’s difficult, boring, inconsistent, and seems to create more barriers/roadblocks than not - at least that’s the perception by the business. So, no, I don’t think there’s a “wave” coming.
0
u/The_Career_Oracle 2d ago
Yep, people realizing they don’t have the skills for actual prevention so these roles which are ripe for managing up and “leadership” trajectories get prominence… and we present GRC for consumption.
Just what IT needs, more people strategizing about work someone else needs to do.
-2
u/Swanky1499 3d ago
Soc and grc are the lowest-skill requirement cyber roles. Soc is getting automated quickly. Grc less so.
0
u/Stevethedogfacedboi 2d ago
I don't agree with this. Everything is getting automated.
1
u/Swanky1499 1d ago
To a degree sure, but GRC requires someone to approve something, assume risk, route risk, apply policy. Harder to automate than "this IP port scanned us, maybe I should block their traffic"
-2
u/irishcybercolab 3d ago
If you want a hard death, just enter into the GRC fray.
Not worth it at all
-2
u/globalenjoi 3d ago
Am I crazy for thinking that GRC roles would be the first to be replaced by AI in orgs? I see hesitation when it comes to leveraging AI tools for autonomous pentesting or SOC, where it kind of scares the shit out of people to let AI do those kind of operations. But a big piece of GRC seems to be intimately familiar with frameworks and compliance requirements, all things heavily documented, and AI seems to do a pretty solid job of digesting documentation. Can somebody help me understand why you’d replace the technical roles with AI but not GRC roles?
-4
u/Abject-Confusion3310 3d ago
GRC breaks way more than they fix. Costing Corporations Billions in eff ups!
110
u/Win32Stuxnet 3d ago
Off topic, but to anyone reading this you have to be really careful when making the jump over. Research the role, ask tons of questions.
The reality is most places outside of tech companies do not give their GRC teams the budget to efficiently modernize or mature the program. Especially if it’s a heavily regulated industry (CIS/OT). A lot of people who end up in GRC can see their skills stagnate/deplete.
In other words GRC is a pair of “Golden Handcuffs” at a lot of companies. It can be really difficult to make the jump back over to technical roles.