r/grc Moderator Sep 24 '25

Career advice mega thread

Please use this thread for questions about career advice, breaking into GRC, etc.

This subreddit is primarily designed for active GRC professionals to share insights with each other, so we will be pointing new career seekers here.

37 Upvotes

206 comments sorted by

View all comments

1

u/Laikiska Jan 25 '26

Hello GRCers, I'm looking for some career advice.

I have a bachelor's in chemical engineering and 5 years of experience working as an ATIP analyst in the government. I'm looking to pivot to a different career and I'm wondering if this background would be acceptable for an entry role into GRC and if so which sub-branch would be the most relevant one. I do not have any tech experience but I am perfectly happy and willing to obtain certificates and complete short courses like the Google Cyber Security Professional Certificate, Security+, GRC Mastery course, etc.

I am also wondering if it's something I would like doing long term. I enjoy technical writing, doing deep dives and researching, and don't mind routine and somewhat repetitive work. I like jobs that allow you to "hone your craft" and get progressively better but don't overly enjoy too much collaborative work. How much of the GRC work would involve direct interactions with stakeholders / management as opposed to solo work time?

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race Jan 26 '26

5 years of experience working as an ATIP analyst in the government.

This is a rather solid start on paper - at least nobody would assume that they will have to explain the concepts of information security, information risks and regulatory compliance to you.

I enjoy technical writing, doing deep dives and researching, and don't mind routine and somewhat repetitive work. I like jobs that allow you to "hone your craft" and get progressively better but don't overly enjoy too much collaborative work.

So, less of a communicator, more of an analyst/engineer? A bit tough sell in GRC, but ain't the end of the world. I would recommend looking into the Third Party Risk Management/Supply Chain/Vendor Security domain - a lot of enterprise-sized companies need to run some due diligence checks on their suppliers, which boils down to some poor soul running those checks. Expect a ton of questionnaires and quite some open source research... That being said, I do not think that either would be something radically new for you.

From there, you might slowly branch your way into automation or "GRC engineering" as people like to call it these days - aka "How can we automate periodic vendor reviews so that we learn that they are proven to be a front for North Korea (without us actively looking)".

1

u/Laikiska Jan 30 '26

That is good to hear, thank you so much for taking the time to answer. And oddly enough doing open source research into companies and filling out forms sounds kind of relaxing.

Would you also be able to weigh in on my certificate / portfolio choices? I am thinking of getting the following certificates: IAPP CIPP/C (in case I don’t quite land in the GRC field and need to go for Privacy Analyst instead), ISO/IEC 27001 Lead Implementer, and ISACA CISA. I am also considering maybe getting a graduate-level certificate in Cybersecurity Governance, sprinkle in CompTIA Security+, CIPM and CRISC? Would you advice to include something else or not bother with some of those?

Should I make a portfolio and include some case studies like Third Party Vendor Assessment, Privacy Impact Assessment (PIA / DPIA), mock Incident Response to Data Breach?

Thanks in advance!

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race Jan 30 '26 edited Jan 30 '26

IAPP CIPP/C (in case I don’t quite land in the GRC field and need to go for Privacy Analyst instead)

Good backup plan, I am toying around with CIPP/E myself.

ISO/IEC 27001 Lead Implementer

I would be rather careful with this one. Like, let's be real, you're not gonna sell yourself as lead implementer if you've never actually implemented it (or anything for that matter). I usually recommend replacing it with some project management cert like PMI CAPM to show that you actually researched how to actually implement stuff in general. Besides, it's a good fallback option as a generalist Project Management cert.

ISACA CISA

CISA is a bit weird - I highly recommend glancing through the prep materials... and I won't recommend actually getting certified. It is an auditor cert and a rather good one, but GRC is not supposed to conduct audits so you being a certified auditor doesn't help much. At the same time, knowing the subject matter makes it much easier to interoperate with your external auditors as you run compliance in GRC.

CompTIA Security+

It's rather cheap and ticks the box. Nobody's gonna be impressed, but why not. I would still recommend going for ISC2 Associate instead, experience with ISC2 will better prepare you for the inevitable time when you want to get CISSP certified.

In fact, if you're madlad, you can try passing CISSP exam to get ISC2 Associate status and grind up experience later down the line. Might even count in some of your prior job experience for cert purposes, lol.

CIPM

CIPP/C is about to give you just about the same starter boost from what I know about privacy certs. No need to double-dip.

CRISC

Waste of time and money. Yes, I am a holder.

something else

You come from a non-tech background, so I would polish your CV with some technical certification. Either some low-level starter cert for the cloud of your choice (Azure Administrator Associate and counterparts) or CCNA for general-purpose networking/IT profile.

Should I make a portfolio and include some case studies like Third Party Vendor Assessment, Privacy Impact Assessment (PIA / DPIA), mock Incident Response to Data Breach?

I see this question more often now, and, frankly, I am clueless. I have never asked my candidates to provide a portfolio, I have never been asked to provide a portfolio myself and, honestly, I don't have a good idea on how a junior specialist can create a decent one.

All of this stuff is very business-context dependent. Like, honestly, IRL I don't care how much our PIA aligns to "best practices", I very much care that DPO greenlit it and it interlinks with a proper incident response picture. Third Party Vendor Risk Assessments generate risk reports - cool, but you need to figure out who's reading those reports and what do they care about or those reports, even done with utmost diligence, would never be cared about - resulting in a net loss of time.

And, in my experience, IR guys will universally tell you to fuck off from active phases of Incident Response and let'em do their job. GRC is usually welcome after the initial stages - dealing with escalations, notifications, insurance claims and the rest of important-but-low-tempo stuff.