What's up y'all! I went through today's new postings and these are the 3 I'd actually pay attention to: 1. Entry Level GRC Analyst | Hotman Group Remote Experience: 1-2 years of professional experience, and it does NOT have to be cybersecurity. NIST, ISO 27001, SOC 2, risk assessments, control testing. This is the one I'd target if you're genuinely trying to break into GRC from another field. 2. Information Security Compliance Analyst | Vestwell NYC / Austin $90K-$105K SOC 1/2, ISO, NIST, audits, vendor risk, security questionnaires. Better fit if you already have some audit, compliance, or security experience and want to move deeper into GRC. 3. IT Security & Risk Analyst I | Oceaneering Hanover, MD $80.6K-$121K 1+ year experience ISO 27001, NIST RMF, 800-53, security assessments, cloud security. I'd look at this one if you're coming from IT or technical security and want to move toward GRC. What I'm noticing from current postings: Knowing framework names isn't enough. Employers keep asking for people who can: - Collect evidence - Test controls - Perform risk assessments - Document findings - Track remediation If you're trying to get your first GRC role, those are the skills I'd practice. Drop your current experience level below: 0 years, <1 year, 1-2 years, or 3+ years.