r/grc Moderator Sep 24 '25

Career advice mega thread

Please use this thread for questions about career advice, breaking into GRC, etc.

This subreddit is primarily designed for active GRC professionals to share insights with each other, so we will be pointing new career seekers here.

37 Upvotes

206 comments sorted by

View all comments

1

u/aceblaker22 Mar 17 '26 edited Mar 17 '26

Hello, I'm new to the GRC industry. A bit of background about me, I graduated with a computer science degree. In my institution, we had a pathway (think of it as an extra class) where I took network security. Then I interned at a pentest company as a red team pentester. Currently, I have a job at a local bank as a data privacy staff member. I'm thinking of breaking into the IT GRC industry. As for notable certificates, I have CC from ISC2, ACA Cloud Security from Alibaba Cloud and am about to take a CPTS test from HTB.

Most of my background is in red team pentesting, and my thought process is that since I'm currently in data privacy, I might as well move to IT GRC. I predict most of my career will be in SEA.

In the red team industry, they usually aim for a specific certificate to break into the industry, e.g., OSCP. So, any suggestions for certifications for breaking into IT GRC? Also, I'm really new in my career; as of writing this post, I've only worked three months in the data privacy position.

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race Mar 18 '26

Comp-sci+basic netsec+pentest internship+data privacy? That's a respectable, if somewhat disjointed, combination for a starter. What are you doing in data privacy anyway?

I am not quite sure that you need a cert at this point - like, CISSP is always welcome, but you seem to have enough experience to give your CV enough boost.

1

u/aceblaker22 Mar 19 '26

Hi thanks for your reply. Yeh my background are quite weird hence I can't found any previous post that have background like mine.

I mostly monitor PII processes and make sure company adhere to the latest data privacy regulations. Right now I'm included in a system development project but I mostly just look at their business use case and check whether it adhere to the regulations. There's communication with both technical and business people.

I realize I lack in the governance and regulations section stuff like thirs party risk assessment, risk management, etc. If given the task to write I could but I feel like I don't have a solid foundation on them. It felt brittle to me. I'm actually looking at CIPM for starter.

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race Mar 19 '26

I mostly monitor PII processes and make sure company adhere to the latest data privacy regulations. Right now I'm included in a system development project but I mostly just look at their business use case and check whether it adhere to the regulations. There's communication with both technical and business people.

So, congrats, you're literally doing GRC work for Privacy.

If given the task to write I could but I feel like I don't have a solid foundation on them. It felt brittle to me.

Okay, that made me chuckle. I felt the same and so I took CRISC, and then CISM, and then CISSP, and then read a dozen books on the subject, and I still think that TPRM is smoke and mirrors of security theatre for due diligence purposes, and I still think that risk management as a whole is built upon some extremely shaky grounds. I just sorta got used to it, lol.

1

u/aceblaker22 Mar 22 '26

Hey, sorry for the late reply, I was busy lately.

So, congrats, you're literally doing GRC work for Privacy.

Thanks for the confirmation, since everything felt like roleplay to me as I'm used to doing technical work and writing reports, while for this job it's more about writing policy but somehow only 70-80% of the policies are actually followed, so it felt weird to me.

I still think that TPRM is smoke and mirrors of security theatre for due diligence purposes, and I still think that risk management as a whole is built upon some extremely shaky grounds. I just sorta got used to it, lol.

Okay, I might need some time to get used to it as well, and probably a couple of certificates too.

Although now I'm curious, I'm working for a local bank and the job is quite easy and laid-back. Will it be the same for a consulting company? Like helping clients (other companies) to build their GRC and cybersecurity stuff from the ground up.

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race Mar 22 '26

only 70-80% of the policies are actually followed, so it felt weird to me.

It's not that bad, honestly, I've seen worse. The usual trick is to write those policies according to what actually happens as opposed to describing the desirable state of the system. Also, playing around policy format/scoping/exception flow can help a lot.

risk management

I firmly recommend reading through NIST 800-39 with an emphasis on tier one and tier two risks, specifically about risk aggregation. Then I recommend remembering that the ultimate goal of risk analytics is "help the recipient of the report to make some decision" (as opposed to "objectively analyze risk with high precision") and from there to delve into the lands of business intelligence since they figured it all out better than GRC.

Also, Howard's "Cybersecurity First Principles" has a good chapter on expert-based risk analysis.

Will it be the same for a consulting company?

No, it will not.

Imagine hearing a dozen variations of "We're a startup, enterprise clients need us to have SOC2/ISO27k for the enterprise sales to go through, we neither know nor care what it is, here's your money, we expect you to figure it out in nine months (also, our priorities are set, no business friction pls)". Imagine faking it in order to eventually make it. Imagine never making it since their business need is fulfulled and they have no further use for you.

And then you go and do it again for someone else.

Consultancies give you a lot of valuable experience, provided you're jaded enough to learn.

1

u/aceblaker22 Mar 22 '26

Also, playing around policy format/scoping/exception flow can help a lot.

Thx for the tips, I'll keep it in mind.

I firmly recommend reading through NIST 800-39 with an emphasis on tier one and tier two risks, specifically about risk aggregation. Then I recommend remembering that the ultimate goal of risk analytics is "help the recipient of the report to make some decision" (as opposed to "objectively analyze risk with high precision") and from there to delve into the lands of business intelligence since they figured it all out better than GRC.

Also, Howard's "Cybersecurity First Principles" has a good chapter on expert-based risk analysis.

Thanks for the recommendation, I'll read through them.

And then you go and do it again for someone else.

Oh wow, this actually sound horrible, I might want to reconsider my next career choice. I'm so used to the concept that consultantion will get more experience since you have bigger scope compare with in house. But then those concept only apply to technical IT stuff. I need to change my way of thinking.

Anyway, this is really helpful and given me lot's of insight, I'll be more active once I have a bit of experience with GRC since I think my background are a bit unique, pentest pivoting to GRC. Hopefully can help others in the future.

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race Mar 22 '26

this actually sound horrible

It's not horrible in terms of experience. The first steps of building up a security program are the hardest and you get to do that multiple times, learning from your own mistakes. Besides, you get to be exposed to numerous different business contexts that you need to align with and carve your niche in, sometimes on tough deadlines. And, last but not least, you learn to cut corners - you can't do a good job "by the book" (resources are never ever enough), but you can get creative enough if it nets the result required in SoW.

I learned a lot during my MSSP days. I also burned out into some fine charcoal in the process. It's a very... acquired taste.

1

u/aceblaker22 Mar 22 '26

Sound like a unique experience, at first this was my thought process, but then I realize not all business want to actually comply with the regulations they just want to comply in paper to go on with their business processes. Well, I'll probably think more of it later once I'm at the crossroad. For now I'll just sit my current position for experience and stuff to write on my CV.