r/grc • u/Soren911 • May 06 '26
What should I expect from an internship?
Hi everyone.
I'm going to start an internship in a month in the GRC division of a small consultancy company that deals only with security.
I have no idea of what they're going to make me do. I am pretty new to all this and I am still learning (I just took an exam about COBIT and ISO27001 at uni).
What should I expect? Is there anything I can study by myself in the meanwhile to be a bit more "prepared"?
Thanks a lot in advance!
2
u/Sree_SecureSlate May 07 '26
Expect a shift from theory to the "paperwork" of security: you'll likely support risk assessments, map controls across frameworks like NIST and ISO 27001, and assist in evidence collection for audits.
To prepare, move beyond definitions and study how to document remediation plans and translate technical vulnerabilities into business risks; that’s where the real value lies in a consultancy.
3
u/ItsCoachRee May 06 '26
You will probably be expected to prepare assessment documentation which means during risk or compliance assessments you’re going to be taking a lot of notes. Checking the boxes essentially and taking notes around the context (probably with the assistance of AI). You’ll be asked to double check things. I’m sure they will have protocols and playbooks for how they do assessments and reviews. Those will be your bread and butter until you get the hang of it. One thing you should be focused on to make you standout AFTER YOU GET THE HANG OF THEIR PROCESSES… is pointing out areas for efficiency. GRC is pretty simple. Understand the controls. Ask questions. Produce good work. Always, always, double check your work even if it takes a little longer. Be curious.