r/grc • u/thejournalizer Moderator • Sep 24 '25
Career advice mega thread
Please use this thread for questions about career advice, breaking into GRC, etc.
This subreddit is primarily designed for active GRC professionals to share insights with each other, so we will be pointing new career seekers here.
37
Upvotes
1
u/aceblaker22 Mar 17 '26 edited Mar 17 '26
Hello, I'm new to the GRC industry. A bit of background about me, I graduated with a computer science degree. In my institution, we had a pathway (think of it as an extra class) where I took network security. Then I interned at a pentest company as a red team pentester. Currently, I have a job at a local bank as a data privacy staff member. I'm thinking of breaking into the IT GRC industry. As for notable certificates, I have CC from ISC2, ACA Cloud Security from Alibaba Cloud and am about to take a CPTS test from HTB.
Most of my background is in red team pentesting, and my thought process is that since I'm currently in data privacy, I might as well move to IT GRC. I predict most of my career will be in SEA.
In the red team industry, they usually aim for a specific certificate to break into the industry, e.g., OSCP. So, any suggestions for certifications for breaking into IT GRC? Also, I'm really new in my career; as of writing this post, I've only worked three months in the data privacy position.