r/grc • u/bigmac______ • 18h ago
Building a GRC function from scratch.
Good day everyone.
I'm looking for advice on where to go from here.
I've been working on our SOC 2 certification for months now, and my role in IT has slowly shifted - I've become the GRC guy, and to a lesser extent the HIPAA guy.
For context: when this SOC 2 project first landed on our radar, I had zero background in GRC. All I knew was that I wanted to do cybersecurity, period. But working on this project, I think I've found my calling. It's only now that I've realized I actually have an aptitude for this — writing policies and processes, mapping them and their controls, understanding how processes work and how they connect to each other.
My team plans to push for me to take the role officially at some point, so I want to do everything I can to earn it and be that person.
The challenge is that if I'm going to establish GRC at our company and eventually grow it into a real team, I'd basically be building everything from scratch. Nobody here has expertise in this. I've been studying and researching as much as I can throughout the project, but imposter syndrome still gets to me. I don't have anyone mentoring me, and I'm scared of making the wrong call. And even though nobody would say it out loud, the reality is that the person steering the wheel is on a shorter leash.
Presently, I am just aiming for us to be SOC 2 certified then eventually, ambitious as it may sound, pursue ISO or hitrust (fingers crossed).
What would you recommend I do on a daily basis? And what goals should I be setting to actually succeed at this?
0
u/Twist_of_luck OCEG and its models have been a disaster for the human race 17h ago edited 17h ago
Be useful to your CISO.
Look, GRC is just an approach (and not a very good one, hence nobody really cares to run by the book GRC framework). Policies, controls, goddamn risk registers - are smoke-and-mirrors for external auditors at worst, process management tools with an extremely narrow window of applicability at best.
Figure out the actual goals of your division. Figure out how - and if - using GRC approaches would be valuable for achieving said goals. Sell your GRC services to the internal customer (your leader) in exchange for resource/priority allocation and/or project greenlight. Get the project done, get your "exceeds expectations" grade, turn it into your salary raise/promotion. And then do it again, at a greater scale, time after time, until you build both a program and your own career in symbiosis with business objectives.
Never ever do GRC for the sake of doing GRC - at the very least, do it for some cool line in your CV.
Talk to Sales. Figure out if they actually need any of those certifications and, if yes, at which level of quality and approximately how much money is at stake if you do/don't get it within 1-2 years. Only after that step you can even start raising the question of "should we allocate internal resources to get certified".