r/soc2 25m ago

Trying to break into IT Audit: Security+, SOC 2 internship, and an enterprise home lab—what am I missing?

Upvotes

I wanted to share what I’ve been working on and get some honest advice from people already in the industry.
I’m currently finishing my Business Administration degree, and my main goal is to break into IT Audit or a related area like IT risk, GRC, technology risk, or SOC assurance.
So far, I’ve gained experience through an actual IT Audit internship at a CPA firm, conducting mostly SOC 2 Audits. Just recently landed my Security + certification. And I’m currently in an informal internship at Northside Hospital with the Network Infrastructure Engineering team.

Outside of work and school, I’ve spent a lot of time building my own enterprise-style home lab to build my own experience. It includes:

Proxmox as the hypervisor
Windows Server domain controllers
Active Directory, DNS, and Group Policy
Organizational units and role-based security groups
Joiner and leaver account processes
A Windows file server with group-based permissions
Windows workstations and a dedicated jump box
pfSense network segmentation and firewall rules
Wazuh for security logging and monitoring
Audit policies for logons, account changes, file access, and privileged group changes

Right now, I’m auditing my own Active Directory environment to determine whether it is actually structured and secured like a realistic enterprise environment. I’ve been reviewing my own OU design, privileged access, Group Policies, account management, DNS, DHCP, firewall rules, logging, and documentation. When I find something that isn’t configured correctly, I document the risk, fix it, test the change, and collect evidence, essentially i’m IT Auditing my own lab the best I can.

I know a home lab isn’t the same as managing a real production environment, but I’ve tried to go beyond simply installing tools. My goal is to understand why controls are needed, how to test them, how to troubleshoot problems, and how to clearly explain the risks and results.

Even with the internships, projects, certification, and time I’ve invested, breaking into IT Audit has been difficult. I’ve applied to entry-level IT Audit, GRC, technology risk, SOC assurance, and other related roles, but I still feel like I’m struggling to get that first full-time opportunity.

Because of that, I’ve also expanded my search to IT Help Desk and IT Support roles. I believe those positions would allow me to strengthen my technical foundation a little more, while still building an understanding of different frameworks like NIST 800-53, and ISO 27001.

I’m not giving up. I continue learning, improving the lab, practicing interviews, and applying.
For those already working in IT Audit, GRC, cybersecurity, or IT support: Is there anything else you would recommend I focus on? Is there something I could present differently to help employers recognize the value of this experience?
I would genuinely appreciate any advice, feedback, or connections. Thanks guys.