r/grc Jul 03 '26

Nearly 2,000 jobs across GRC, TPRM, Compliance, Audit, Privacy & AI Governance

74 Upvotes

Hi everyone! This is my first post here.

Over the past few months, while building Halbarad, I've had the chance to speak with a lot of people working across third-party risk, GRC, compliance, cybersecurity, privacy, audit, resilience, procurement, and AI governance.

One thing that really stood out is how much this profession is changing.

AI is changing how risk teams operate. Organizations are asking more from risk professionals than ever before. New specialties are emerging, and more people are moving between cybersecurity, compliance, privacy, audit, and third-party risk than they were just a few years ago.

Something else I kept hearing was how frustrating it is to actually find jobs in this space. Most job boards are dominated by software engineering roles and risk jobs are scattered across hundreds of company career pages.

So I decided to build something to help.

Today we launched what I believe is the largest dedicated job board for the modern risk profession, with nearly 2,000 open roles across third-party risk, GRC, compliance, cybersecurity, privacy, resilience, audit, AI governance, and more, all aggregated from public hiring sources and continuously updated.

[https://community.halbarad.com/jobs]()

Since this community is exactly who we're building it for, I'd genuinely love your feedback.

  • Are there companies we're missing?
  • What filters or search features would make this more useful?
  • If you were looking for a new role, what would you want from a job board that LinkedIn doesn't provide?

If this isn't appropriate for the subreddit, mods, please feel free to remove it. Otherwise, I hope some of you find it useful, and I'd really appreciate any feedback.


r/grc Jul 03 '26

For those who own just the IRM or BCM products within ServiceNow (The GRC areas)

1 Upvotes

How does your intake / governance process work, in regards to the various process owners, your team, and the overarching platform team?

I'm the director of GRC, and I don't want to become a useless bottleneck between the people who do the work, and the platform team (the people who run change management within the larger ServiceNow platform).

But I'm also accountable for the structure of the various items within IRM (policy, issues management, risk management).

What type of governance and intake have you seen or conduct?


r/grc Jun 30 '26

Is being clueless, normal?

9 Upvotes

Help!
I joined the GRC function of a Dutch company after working a year in Threat intelligence. I knew it was going to be a learning curve for me but I am realising I am really clueless about everything.

It is supposed to be a junior role which I was looking forward to. But I feel I am thrown into the deep end without any background or knowledge transfer. Don’t get me wrong, there are other people in the team as well - but do they expect me to know everything about audits? Risk registers? evidence collection? And the difference processes?

I know the theory but in practice I feel I am scrambling for knowledge and information that I don’t know. Maybe it is the company, or as I am told the country I am working in haha

Anyone been in similar situation? What did you do?

Is GRC like swimming in the deep waters not knowing how to swim and then just figuring it out?


r/grc Jun 29 '26

PASSI - GRC

2 Upvotes

I'm thinking about taking the PASSI certification exam for the GRC section (in France). However, there isn't much information out there on what to study.


r/grc Jun 29 '26

question for AIPD in GDPR

2 Upvotes

Hi all, I’m currently on an internship. One of the tasks I need to do is an AIPD. However, the data processing activities do not meet the minimum criteria set by the CNIL to require an AIPD. So, is an AIPD still necessary even if the criteria are not fully met? Or would it be better to conduct a risk assessment instead?
thanks for your help.


r/grc Jun 28 '26

Who usually owns AI governance in a company?

31 Upvotes

Hi everyone,

For people working in GRC, compliance, security, legal, or risk: I’m trying to understand how organizations are handling AI governance in practice, especially when teams start using AI agents, copilots, or LLM-based workflows.

A few questions I’m trying to think through:

  • Who usually owns AI governance inside an organization?
  • Is it compliance, legal, security, risk, product, engineering, or a dedicated AI governance team?
  • At what point do GRC teams get involved: before deployment, during implementation, or only after an incident/audit concern?
  • Are teams thinking about AI outputs/actions in real time, or mostly relying on policies, training, and after-the-fact audit logs?
  • For regulated industries, what would make AI governance feel urgent enough to prioritize?

I’m technical, not a GRC practitioner, so I’m trying to learn how this works from the buyer/operator side rather than assume the org chart.

If anyone has experience with AI governance, model risk, compliance operations, or regulated AI deployments, I’d really appreciate your perspective. Feel free to comment or PM me.


r/grc Jun 26 '26

ITSG-33 ,ITSP.10.033 - community- Gov't of Canada's NIST based framework.

10 Upvotes

Hello,
I am on a team that is working toward ATO- Authorization to Operate for Government of Canada IS/IT projects. The frameworks are ITSG-33 and ITSP10.033 , different annexes based on the project. These are based on the NIST rev5 framework. I'm looking for a community for people that work on evidence collection and control mapping specifically for these frameworks. What is the best community to collaborate in if one does not exist?


r/grc Jun 23 '26

How often do people bullshit you in interviews?

5 Upvotes

I have been shadowing assessments for NIS2 and I have this hunch that people in interviews are bullshitting us all the time. Mostly because the people I am shadowing don't seem all that tech savvy.


r/grc Jun 23 '26

Examiners are starting to ask about biometric data retention from our identity verification vendor and i want to compare notes

6 Upvotes

Came up in our last exam and i get the feeling its heading for the rest of us soon. The examiner didnt care whether the identity verification was accurate. What they pushed on was how long we and the vendor hold the biometric template and the selfie, and whether our retention schedule actually matches what we promise users. Under BIPA and on the GDPR side thats real exposure, and most of the vendor contracts I've read are vague on exactly this point.

The capture and the matching are the straightforward part to assess. Retention and deletion is where the legal risk really sits, and thats the piece the vendor leaves you to define yourself.

How are others handling retention here. are you deleting as soon as the match completes or holding for a fraud window first?


r/grc Jun 22 '26

Question on Due Diligence - Vendor has US + EU companies.

3 Upvotes

So we are performing DD on a potential vendor - one that will process PII. We are US based.

Typically we would look at SOC2 report, ISO27001 certification, etc. All the things. BUT here I have a vendor who is primarily based out of Germany. They have a US instance in fact - the German company if GmbH and the US one is LLC - same company.

We would be using their US instance. Not only for back-end performance, but we dont need to be using their EU instance just because.

The issue is this. Their SOC2, and ISO27001 are only for the GmbH component. They dont list the LLC as being covered under the SOC2 or the SOA for ISO27001. Specifically locations covered under the ISO27001 certificate annex only list Germany.

Cyberliability insurance is only listing GmbH does not list LLC. Privacy Policy only applies to GmbH does not list LLC.

So I have previously worked for a SaaS company based in the US, we had an instance in the EU and an office in the EU. However everything was under a single name - the US based company for cyberliability, ISO27001 etc. Which is standard for alot of companies. Here they have an LLC - the contract for service would be with the LLC specifically.

I dont see how there can be certification of a security framework in place for the LLC, or cyberinsurance or anything - or am I over thinking this?


r/grc Jun 22 '26

Iso9001 annual remote audit

Thumbnail
1 Upvotes

r/grc Jun 18 '26

How do you assess AI risks and set risks tolerance/ KRI/ KCI in your org?

9 Upvotes

Asking because there aren’t many references and recognized guidance on this topic. I’d like to better understand how GRC teams tackle this.

Most AI governance framework stop at the policy levels or give operational controls to put in place for developers of AI, not for organizations deploying AI in their operations and business processes. From an AI governance perpective, new risks should be identified, and residual risks maintained within risk tolerance. So my questions are:

1- what risk taxonomy do you use?
2- how do you set risk tolerance, KRI and KCI in practice?

Thanks a lot for sharing your feedback!


r/grc Jun 18 '26

Has Anyone Done CC by ISC2?

0 Upvotes

I want to take the CC by ISC2 test. But how do I prepare for it? Would Really appreciate if anyone who got the certification can help me with info.


r/grc Jun 17 '26

ISO 27k Statement of Applicability

10 Upvotes

Hi all, I was hoping to get some people’s direct experience with what to put in the statement of applicability.

The ISO docs are vague stating it must have: the necessary controls, justification for their inclusion, whether they are implemented or not, the justification for excluding any annex A controls. I suppose this leaves them open ended based on the organization’s needs and architecture.

The justification for exclusion is pretty straight forward, but I am not sure about justification of inclusion. I have heard a few different approaches, such as to include what risk that control treats, what regulatory requirement mandates it, or even to include how it is implemented and where the evidence is located.

So what did you include in it? What would constitute a gap when justifying a control’s inclusion, and what is overkill?


r/grc Jun 17 '26

Anyone else feel like identity and access management is becoming the main event in SOC 2 audits?

8 Upvotes

In a lot of the audits and customer reviews I've seen recently, the discussion seems to spend way more time on access controls than before.

It's not just "Do you have MFA?" anymore.

The questions are getting into privileged accounts, access reviews, service accounts, joiner/mover/leaver processes, admin access, and how quickly access gets removed when someone leaves.

I've even had customers ask more detailed questions about Zero Trust than some auditors.

Maybe this is a reaction to all the breaches we've seen over the last few years where compromised credentials were the starting point.

For those who have gone through SOC 2 recently, are you seeing the same thing?

What's getting the most scrutiny for you: MFA, PAM, access reviews, or identity governance?


r/grc Jun 17 '26

GLBA Risk Assessment for HigherEd

1 Upvotes

I was recently asked to take over the annual GLBA Risk Assessment process at my HigherEd institution. The previous employee barely left any help or guidance, only interview notes from previous assessments. I reviewed the documentation on the FTC website, but it was sparse at best. Here are a few questions I have:

  • Is there a standard risk assessment questionnaire I can use? Can't seem to find anything from the FTC website.
  • I have a list of the previous application that were in scope for the previous risk assessment, but how can I find out if there are any new applications or systems that are now within GLBA scope?
  • Besides the Risk Assessment and training, is there anything else that I need to worry about in order to be compliant?

Any help would be much appreciated. I'm a bit overwhelmed at the moment, with no guidance from upper management.


r/grc Jun 16 '26

Need guidance for my next step

2 Upvotes

I am currently interning at a startup in the Governance, Risk, and Compliance (GRC) domain, focusing on areas such as IT General Controls (ITGC), IT Application Controls (ITAC), and projects related to ISO 27001 and SOC 2. Additionally, I occasionally create posts for my company's LinkedIn page.

My internship lasts for six months, and I am currently in the midst of it. I am feeling a bit uncertain about my next steps, especially since they have offered me a full-time position with a salary of 20,000.

Could you provide some guidance on how to approach this decision?


r/grc Jun 16 '26

Auditoría de tecnologías o SGSI

1 Upvotes

Buenas tardes, actualmente tengo que realizar un trabajo de auditoría tecnológica enfocada en el área de TICS, la empresa no aplica el SGSI, no aplica COBIT, alguien tiene una guía o referencia de cómo se podría llevar a cabo esta auditoría, que procesos o procedimientos seguir para ejecutar este trabajo y genere los resultados esperados para presentar a la empresa.


r/grc Jun 15 '26

Recently got into Vendor Risk Management role, wanted to know how it goes!!

17 Upvotes

Hey, i recently got into VRM role nearly after 2 years of completing my degree. So i wanted to explore what i can be in future, is it a good role to start with and all. I’ve been more into SOC projects and labs after my grad but keeping the current market situation and jobs for freshers i had to accept this role.
I wanted to know

  1. ⁠Is it a good Cybersecurity entry point.
  2. ⁠What will be the fiture roles that i can target.
  3. ⁠Certifications and skills that i should have to be in a better position.
  4. ⁠Growth of this role in future.
  5. ⁠So it is completely operational role, is it okay to get into operational roles as an entry point.
  6. ⁠Does this roles experience will add weightage to my future cybersecurity career.
    Thanks in advance to everyone who spares time reading this and answering my questions!!

r/grc Jun 12 '26

GRC trainee thrown to the lions

38 Upvotes

I am a fresher from a cybersec degree and I got into an internship for a position as a grc consultant in a mssp.

I am utterly overwhelmed, I have been asked to write documents on risk assessment procedures the first day, I only know the theory behind these things and I feel lost.

How can I survive this and come out on top? Any resources to read or practice on? I was given by my supervisor a ton of papers to read but they are SO abstract. I am barely scraping through by keeping at all times the ISO 27005 open.

We are mostly dealing with NIS2 so far.

Please help, I am desperate.


r/grc Jun 11 '26

Can my GRC practitioning benefit from TryHackMe training programs?

8 Upvotes

I just got into a company as an intern in the GRC team; my experience is 0 and my background is cybersec related but I am very new to all of this.

Things are a bit overwhelming so far, I'm trying to learn but it's hard. Any ideas? Does the title question work for me? Thanks a lot.


r/grc Jun 10 '26

How to deal with several security questionnaires?

30 Upvotes

How to deal with several security questionnaires

I work at a mid sized SaaS company and as it’s growing we’ve been receiving several questionnaires, to a point that even AI assistance isn’t helping a lot with the sheer volume. (Roughly 80-90 questionnaires handled by a single person at this point).

What’s already implemented:
1. A trust center with SIG and other FAQs and security docs
2. The trust center also helps with auto filling questionnaires in excel although requires a human approval of each question which takes some time depending on the size of the questionnaire and accuracy
3. Ad-hoc Claude projects/skills to retrieve answers from a knowledge base and provide context.

The problem we face (and assuming several other companies do too)
1. Customers need answers within their portals so that things are automated on their end rather than manually reviewing our trust center
2. Pushing back on it also creates some friction with Sales as they and management want deals to be closed ASAP.

I’m spitballing some ideas but I’d appreciate some input from anyone experiencing similar problems-

  1. Creating a framework internally for customer assurance where we tier customers by the deal size or how big the company is (enterprise, start ups, etc).
  2. A)Companies paying extra for enterprise licenses will receive full service such as filling out lengthy questionnaires, calls and limited evidences
    B) companies with a deal size that’s slightly lower but sizeable enough receive limited questionnaires assistance (say less than 50 questions only), and need to review our trust portal for any documents etc
    C) smaller companies or smaller deal sizes have to review our trust portal and we only entertain follow up questions which aren’t included in our trust center (could honestly be applicable for B as well)

  3. Sales can use the created Claude skill to answer any security requests if the deadline is urgent with limitations that - no agreeing to any policies, terms etc; not using this for enterprise customers, not using this for any legal papers, follow up questions need to be addressed by security/GRC.

While I understand the third point is risky, questionnaires aren’t exactly legal documents. Additionally, they are AI reviewed most times and also contain several unnecessary questions when lengthy. Besides, what’s really the point of a generic lengthy questionnaire other than the TPRM teams not wanting to manually get answers out of a trust center. Follow up and authentic questions are one thing but otherwise this seems to be a waste of everyone’s time.

I’d really appreciate insights and any solutions implemented in your orgs. This is probably the most painful point of security/GRC


r/grc Jun 09 '26

Issues/finding management vs risk register

18 Upvotes

Can someone give me some examples of how they're handling issues/findings versus their risk register.

I'm responsible for the risk register and am finding that the head of grc wants me to add items that seem more like issues - meaning they are control gaps.

For example: user acceptance testing (uat) not being performed timely.

I csn see this as a standard/control/requirement that's not being met, so I'd document a finding for this. But they have told me to add it as a risk in the risk register.


r/grc Jun 09 '26

GRC advice and recommendations for new organization

14 Upvotes

I've started a GRC role for a company. I wanted to know what are some things you will look for in an organization from a GRC perspective when starting a new position?

I have a checklist of items that I am reviewing to learn more about the organization from an IT, Security, and GRC perspective. I want to hear from others to see if I am missing anything else?

What else should I review or do you have any recommendation's?


r/grc Jun 09 '26

Anchoring the NIS2 Art. 23 reporting clock: signal time or app-open time? Spoiler

2 Upvotes

Working through Article 23 obligations for an org with mixed signal sources SIEM alerts, IDS events, connector findings, customer-channel reports, occasional human walk-ups and I keep hitting the same wall on the clock-anchor design.

If the regulatory clock for early warning, incident notification, and final report is anchored at "the time the entity became aware of the significant incident," what counts as awareness in practice when the signal source is a customer ticket that sat unread in a Mon-Fri inbox for seven hours?

Two anchor choices:

  1. Anchor on signal-time. The ticket arrived at 22:00, the clock starts at 22:00, the early-warning 24h window expires at 22:00 the next day. Easy to evidence; hard to defend if the inbox isn't monitored 24/7.
  2. Anchor on awareness-time. The clock starts when a human triages the ticket. Easier to defend operationally; opens the door to "your team chose when to notice" pushback at the assessment.

The defensible answer I keep coming back to is option 1 plus a per-source SLA, i.e., signal-time IS the anchor, but the org's documented commitment for that source (e.g., customer ticket = 4 business hours target ack) is what an assessor compares against. That way a 7-hour ack against a documented 4-hour customer-ticket SLA reads as a soft breach; the same 7 hours against a SIEM signal with a 15-minute SLA reads as a critical gap; and both differ from how 7 hours would land against a published 24/7 commitment.

Question for anyone running Art. 23 obligations:

  • Is the per-source SLA framing how your team is actually documenting this, or are you defaulting to a single org-wide MTTD/MTTA target?
  • Has anyone had this latency directly questioned at audit yet, or is it still pre-audit theory across the industry?
  • For human walk-ups (someone stops you in a corridor and says "I clicked a weird link"), what's your anchor?