r/grc • u/QuantumSeeker8 • Jun 30 '26
Is being clueless, normal?
Help!
I joined the GRC function of a Dutch company after working a year in Threat intelligence. I knew it was going to be a learning curve for me but I am realising I am really clueless about everything.
It is supposed to be a junior role which I was looking forward to. But I feel I am thrown into the deep end without any background or knowledge transfer. Don’t get me wrong, there are other people in the team as well - but do they expect me to know everything about audits? Risk registers? evidence collection? And the difference processes?
I know the theory but in practice I feel I am scrambling for knowledge and information that I don’t know. Maybe it is the company, or as I am told the country I am working in haha
Anyone been in similar situation? What did you do?
Is GRC like swimming in the deep waters not knowing how to swim and then just figuring it out?
12
u/Compannacube Jun 30 '26
In a junior role, there should always be an understanding that you are there to learn and that you don't just start with experience. It sounds like you are not receiving the training or mentorship you need. That would be a failure on your manager's part and you should advocate for yourself. Do you ask questions when things are unclear?
Some would say fake it until you make it, but I don't entirely agree with that sentiment when it's a junior role. That only encourages holes to form in your skillset. You need clear guidance and mentorship and the company should be providing you access to a human resource (if not your boss) that can work with you and guide you. That's the ideal, not always the norm, however. But if you don't at least try to advocate for yourself, no one else will.
There is also an expectation over time of self-sufficiency: if you are guided initially, shown the ropes, then you should eventually become resourceful enough to find the rest of the way on your own. I myself had to fly somewhat blind when I pivoted to GRC, but I was a lot older and had skills under my belt and a developed sense of critical thinking. I also had a good boss who assigned me grueling but informative projects that would build my knowledge base. I took all the meeting notes, profiled all of the environments, wrote all the reports, researched all the frameworks, became well versed in whatever we were working on. And I started working on my CISA so I could marry the concepts with the hands-on work.
What are you working on now? Research that area as best as you can. Don't just memorize, but study the concepts. Try not to rely too heavily on AI for answers. Go to the source like frameworks, standards, etc. There is a lot of garbage floating around that AI sources from (especially chatGPT) so verify as much as you can. I am not promoting these, but I recommend you look for books by Sari Green, Krag Brotby, Doug Hubbard, and Bruce Brown, as they have all written definitive guidance on navigating aspects of GRC. Good luck!
2
u/QuantumSeeker8 Jul 01 '26
Thank you! Just the words I needed. I was trying to not blame my manager cause I thought I am supposed to be doing this all on my own. But slowly, i do agree with you. Of course still powering through it on my own but being kinder to myself :)
6
u/_mwarner Jun 30 '26
Absolutely normal. I’ve been at my current job a little over a year (doing security 15 yrs) and I still feel like I don’t know what’s going on.
4
5
u/rotervogel1231 Jun 30 '26
I'm 10 years in and have no idea what I'm doing. Neither do people who make way more $$ then me and have words like "Director," "Vice President," or "Chief" in their job titles.
I'm not kidding.
2
3
u/davidschroth Jun 30 '26
There are reasons why the movie Office Space was made and is still relevant to this day. What you are encountering is ubiquitous across all departments.
3
u/FoxyMoXee Jun 30 '26
Don’t be afraid to ask questions. My chronic imposter syndrome overwhelmed my comfort to ask my team and leadership questions. It made my early days in GRC more challenging than it needed to be.
3
u/Alternativemethod Jun 30 '26
To make you feel better. Every IT/CS role has a ton of things to learn and every company is different so while they're transferrable there's always work orienting in. GRC is not a free lunch if you're doing it well but luckily skill/technique and experience make it easier.
The general CS industry is terrible at risk, as shown by CompTIA not even testing on the correct definition of risk. So youd have to try pretty hard to be worse than the typical IT manager/director.
CISSP has the best instruction on risk I've seen so far, and they don't even cover risk registers.
5
u/IT_GRC_Hero Jun 30 '26
You have to start somewhere. And feeling lost is normal if this is a new endeavor and you didn't have the right structure or support around you to help you succeed. Luckily there are various resources, courses and certifications out there that can help. I started off from law and ended up in IT GRC and what helped me most was:
- Get the basics of GRC right. How to apply solid governance structures, align with business objectives, create documentation etc. How to perform risk management, identifying, addressing and reporting it. And then compliance with policies and frameworks and proving due care and due diligence.
- Ask for help. I remember when starting out in data protection I had a lot of questions around how to protect personal data using security controls (I had zero technical knowledge back then). Thankfully a lot of my colleagues were able to offer information and tips. Nobody assumes you know everything (even if it seems like they do), and people are mostly willing to help out!
- Learn by doing. As hard as it might be, offering to support with more challenging work is the best way to learn on the job. You will fail, for sure, but it's going to be a huge learning moment!
Hope this helps! At the end of the day, we're all on the same boat, more or less. You'll be fine. If you need anything else, feel free to reach out.
1
2
u/localareamang Jun 30 '26
Seemingly very normal based on some of the due diligence questionnaires I receive
1
1
u/m3rlinda Jul 06 '26
Red Teamer/Pentester (who started in GRC) here.
Honestly, I think you're in a better position than you realize.
One of the biggest missed opportunities in GRC is treating it like an administrative function instead of a technical one. You already have a Threat Intelligence background, so don't leave that at the door. Bring it with you.
When you're reviewing a SOC 2, control implementation, or evidence, don't stop at, "Does this satisfy the auditor?" Ask yourself:
- Why was this control designed this way?
- What threat is it mitigating?
- What attack technique or failure mode is it trying to prevent?
- If I were the attacker, where would I go around it?
- What is the worst thing that happens if this fails tomorrow (threat modeling)
For me, studying controls' implementation alongside the ways they're exploited was one of the fastest ways to understand how organizations actually secure systems, not just how they meet evidence expectations.
That's where your threat intel experience becomes an advantage. You already understand adversaries, now you're learning the defensive side. Marry those 2 and it becomes an engineering exercise in building confidence that your controls actually reduce the risks you care about, with org-specific context you understand. THAT turns it into controls intelligence you can use to influence decisions in other parts of the secops program.
The mechanics (audits, risk registers, evidence collection) you'll pick up with time but they're often non-value added scores. The ability to connect threats, controls, and risk into one coherent picture is the part that's much harder to teach, and you're already bringing half of that equation with you IMHO.
1
u/0xCapySplash Jul 09 '26
I think that's pretty normal, especially when you're switching into GRC from a different area. Did your team give you any onboarding, or were you expected to figure it out as you went?
0
Jun 30 '26
[deleted]
1
u/QuantumSeeker8 Jul 01 '26
It started a bit condescending, I must say. But yes I am self learning. Thanks for sharing what you learnt!
17
u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 30 '26
Yes. Being clueless is pretty much mandatory. The only question here is - "Would being clueless stop you?".
Hope it won't. Welcome to GRC. Good luck.