Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
5 contributions to GRC Career Path
Great News!
55 members today. Appreciate everyone who’s joined so far. I don’t want to keep adding resources JUST to add resources (lol). I want the next thing I build here to solve an actual problem for you. So if you're serious about this, please see below. Reply with one number: 1. I need stronger GRC resume bullets and better ways to explain my experience 2. I need hands-on practice with control testing, audit evidence, and documentation 3. I need a clearer path into a GRC, IT audit, risk, or compliance role 4. I’m already in the field and want to get better at TPRM, risk assessments, or audit work 5. Something else. Tell me what you’re stuck on in one sentence I’ll use the responses to decide what GRC Lab 002 or the next practical resource should cover.
Great News!
1 like • 6d
3
Where are you at with your GRC career right now?
About 10 new members joined today. Welcome to GRC Career Path. I’ve been sharing job opportunities, and there’s a free GRC resume template pinned for anyone who hasn’t seen it. But I’d like to hear from everyone here, whether you joined today or have been around for a while. Which one sounds most like you? 1. Trying to get into GRC, but not sure which roles I’m qualified for. 2. Applying to jobs, but not getting interviews. 3. Getting interviews, but struggling to turn them into offers. 4. Already working in GRC, and figuring out how to move up or make my next move. Drop your number in the comments. A sentence about what’s been difficult would help too, but no need for a full introduction. I’ll use your answers to help decide what to share next, rather than guessing what everyone needs.
1 like • 14d
I’m trying to get into GRC, but I’m still figuring out which roles I’m qualified for. I’m especially interested in risk, governance, compliance and cybersecurity, but I’m finding it difficult to know which entry-level roles to focus on.
Which of these GRC roles would you apply to?
What's up y'all! I went through today's new postings and these are the 3 I'd actually pay attention to: 1. Entry Level GRC Analyst | Hotman Group Remote Experience: 1-2 years of professional experience, and it does NOT have to be cybersecurity. NIST, ISO 27001, SOC 2, risk assessments, control testing. This is the one I'd target if you're genuinely trying to break into GRC from another field. 2. Information Security Compliance Analyst | Vestwell NYC / Austin $90K-$105K SOC 1/2, ISO, NIST, audits, vendor risk, security questionnaires. Better fit if you already have some audit, compliance, or security experience and want to move deeper into GRC. 3. IT Security & Risk Analyst I | Oceaneering Hanover, MD $80.6K-$121K 1+ year experience ISO 27001, NIST RMF, 800-53, security assessments, cloud security. I'd look at this one if you're coming from IT or technical security and want to move toward GRC. What I'm noticing from current postings: Knowing framework names isn't enough. Employers keep asking for people who can: - Collect evidence - Test controls - Perform risk assessments - Document findings - Track remediation If you're trying to get your first GRC role, those are the skills I'd practice. Drop your current experience level below: 0 years, <1 year, 1-2 years, or 3+ years.
1 like • 14d
For me, I would go for #1 Entry Level GRC Analyst. I’m still trying to break into GRC so the focus on NIST, ISO 27001, risk assessments and control testing really caught my attention.I’m also working on building practical GRC skills, especially around evidence collection, controls, risk assessments and documentation. Currently: 0 years of formal GRC experience, but actively learning and building my portfolio. 🔐📚
📥 Free GRC Resume Template (Grab yours inside the Classroom!)
Hey everyone, the free resume template is available in the Classroom, along with tips for presenting your experience and portfolio projects for GRC, IT audit, and security assurance roles. Grab your template here. If you’re stuck on a resume bullet, share it below with the role you’re targeting. Remove any personal or confidential information, and we can work through it together.
1 like • 20d
Nice, thank you for this! I'll grab a copy and compare it against my current CV format —always good to make sure it's hitting what GRC/audit recruiters actually expect. Might take you up on the feedback offer once I've run it through
👋 Welcome to GRC Career Path!
I created this community to help people build practical GRC skills, turn those skills into credible career proof, and approach the job search with a clear plan. This won’t be a community where you collect resources and never use them. You’ll learn how GRC work is actually performed, create a simulated portfolio, practice explaining your decisions, and build a focused strategy for the roles you want. Start here: 1. Introduce yourself in the comments using the prompts below. 2. Open the Classroom and complete Module 0: Start Here. 3. Make your own copy of the Module 0 assignment template. 4. Submit your completed assignment under the Module 0 Assignment lesson. For your introduction, share: - Your name and location - Your current role or background - The GRC role you’re interested in - Your biggest career obstacle right now - What you want to accomplish in the next 90 days I’ll go first: I’m Winton. I currently work in security assurance at Airbnb, and I came into GRC through IT audit. I created this community because too many people are told to collect certifications without learning how to evaluate risk, write controls, assess evidence, or explain their judgment. My goal is to help you leave with something stronger than course-completion screenshots. You should leave with work you can honestly discuss with hiring managers. Introduce yourself below, then head to Module 0. Module 0: https://www.skool.com/grc-career-path-4325/classroom/67e52554?md=0ab31719dcbe493fbf23e9bed3e259b0
1 like • 20d
Hi everyone, Im Natashia, based in Johannesburg, South Africa. I'm early-career in cybersecurity/IT, with certs like Security+, CySA+, and SC-900, plus a couple of hands-on GRC-adjacent projects under my belt. I'm aiming for an entry-level GRC/risk analyst role.My biggest obstacle right now: most postings want 1-3+ years of GRC experience, and I don't have that formal experience yet. In the next 90 days, I want to close that gap and start landing interviews. Excited to be here!
1-5 of 5
Natashia Sibanda
2
15 points to level up
@natashia-sibanda-3775
Business Admin graduate with networking & cybersecurity certs (CompTIA, Microsoft, Cisco as well AWS). Passionate about GRC and tech-driven business.

Active 3d ago
Joined Sep 11, 2026