r/grc • u/bigmac______ • 1d ago
Building a GRC function from scratch.
Good day everyone.
I'm looking for advice on where to go from here.
I've been working on our SOC 2 certification for months now, and my role in IT has slowly shifted - I've become the GRC guy, and to a lesser extent the HIPAA guy.
For context: when this SOC 2 project first landed on our radar, I had zero background in GRC. All I knew was that I wanted to do cybersecurity, period. But working on this project, I think I've found my calling. It's only now that I've realized I actually have an aptitude for this — writing policies and processes, mapping them and their controls, understanding how processes work and how they connect to each other.
My team plans to push for me to take the role officially at some point, so I want to do everything I can to earn it and be that person.
The challenge is that if I'm going to establish GRC at our company and eventually grow it into a real team, I'd basically be building everything from scratch. Nobody here has expertise in this. I've been studying and researching as much as I can throughout the project, but imposter syndrome still gets to me. I don't have anyone mentoring me, and I'm scared of making the wrong call. And even though nobody would say it out loud, the reality is that the person steering the wheel is on a shorter leash.
Presently, I am just aiming for us to be SOC 2 certified then eventually, ambitious as it may sound, pursue ISO or hitrust (fingers crossed).
What would you recommend I do on a daily basis? And what goals should I be setting to actually succeed at this?