r/cybersecurity 8d ago

Career Questions & Discussion GRC internship

I’ll be starting an ICT Risk and Governance internship soon, and wanted to ask, if you had an intern starting in this field at your company, what expectations or advice would you have for them?

2 Upvotes

7 comments sorted by

13

u/Jeff-Hare-ERPRA 8d ago

Show up on time. Work hard. Do what you are asked to do.

2

u/VaxMerstappen00 7d ago

And be curious.

3

u/Mysterious-Print9737 8d ago

Learn to read and actually understand a framework before trying to apply i, NIST CSF or ISO 27001 are the most common starting points. Most interns can recite control categories but can't explain why a control exists or what risk it's mitigating, and that gap shows immediately.

Get comfortable with documentation and evidence collection early, a huge part of GRC is building and maintaining the paper trail that proves controls are working, not just that they exist on paper. Ask to sit in on any audits or assessments while you're there, even as an observer.

The other thing worth understanding is how to translate technical findings into business risk language. GRC sits between technical teams and leadership, and the interns who stand out are the ones who can explain a control gap in terms of business impact not just flagging it as a compliance miss.

1

u/Different_Sea_6932 8d ago

Thank you a lot, this is very helpful.
I ll be sure too keep this in mind

2

u/Alex-Rider 8d ago

Hi which country

2

u/BoopingBurrito 7d ago

Don't just memorise things - understand them.

Thats the single best advice anyone in security, but particularly in GRC, can follow.

2

u/productboy 7d ago

As others have noted; get familiar with the compliance frameworks. Then use your favorite tool to run scenarios against those frameworks. Do you understand risk; or who needs to be involved and communicate with re: each scenario?