Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More

Owned by Winton

Career changers and early-career cybersecurity professionals trying to land their first dedicated GRC role.

36 contributions to GRC Career Path
4 Early-Career GRC and TPRM Roles Worth Applying To This Week
Howdy y'all! Look below for some open roles. Four new roles cleared the filter. Cloud for Good is the strongest traditional GRC opening. TIAA is the best true entry-level opportunity because it requires no prior experience. Broadridge is a clean 1-3 year TPRM role. Rose International is a solid contract option for someone with about 3 years of risk experience. 1) IT GRC Analyst | Cloud for Good - Location: Remote, US or Canada | Up to 30% travel - Salary: Not listed in the verified posting - Experience: 2+ years in GRC, IT compliance, or security operations - Skills: SOC 2 Type I/II, audit evidence and auditor coordination, vendor and penetration-test management, security questionnaires and due diligence, risk registers and security policies - Why it matters: This is a strong early-career GRC role because you would own real SOC 2, customer assurance, vendor risk, policy, evidence, and remediation work instead of just supporting one narrow compliance process. - Apply: https://www.linkedin.com/jobs/view/it-grc-analyst-at-cloud-for-good-4458273622 2) 2027 Early Talent Rotational Program: Audit, Risk & Compliance | TIAA - Location: Charlotte, NC | Hybrid/in-office - Salary: $28.22-$35.53/hour - Experience: No experience required - Education: Bachelor's degree required - Start date: July 2027 - Skills: Audit program execution, risk and compliance operations, regulatory assessments, governance reporting, process and procedure documentation - Why it matters: This is one of the better genuine break-in opportunities because the 24-month program provides up to three rotations across Audit, Risk, and Compliance with no prior professional experience required. - Apply: https://careers.tiaa.org/2027-early-talent-rotational-program-audit-risk-compliance/job/74F263FAFF1ECA82A9334779057BF8B8
0
0
GRC Weekly Brief 001 | AI Threats, Vulnerability Priorities, and a NIST Resource
October 1, 2026 Starting a weekly roundup here of GRC, AI, and cybersecurity updates worth understanding. I’ll include the sources and what I’d pay attention to in the actual work. 1) CISA is changing its vulnerability updates CISA announced September 28 as the retirement date for its weekly Vulnerability Bulletin, part of a shift toward risk-based vulnerability prioritization. My takeaway: If your vulnerability process depends on a weekly email or a severity score, review it. Can you explain which affected systems matter most, who owns remediation, and what evidence supports closing a finding? Source: CISA bulletin notice https://www.cisa.gov/news-events/bulletins 2) Anthropic reports AI being used to coordinate cyberattacks Anthropic’s September threat report describes cases where attackers used AI to execute or coordinate reconnaissance, exploitation, and data theft. Humans still directed targets and reviewed results. The report covers activity from December 2025 through August 2026, rather than attacks that all happened this week. My takeaway: Give your next incident-response exercise a tighter timeline. Test how quickly the team can identify the owner, revoke compromised access, preserve evidence, and escalate. Treat these as vendor-reported case studies, not a measurement of every attacker’s capabilities. Source: Anthropic’s September report https://www.anthropic.com/threat-intelligence-report-september-2026 3) A practical NIST resource to review before October 15 NIST’s draft SP 1353 explores using AI for Cybersecurity Framework analysis and reporting. Released in August, it includes example prompts, simulated company files, and three illustrative use cases. Public comments remain open through October 15. This is draft guidance. My takeaway: This could make a useful portfolio exercise. Use the fictional company materials, generate a draft analysis, then document what you corrected and why. Show your judgment alongside the output.
0
0
5 Fresh Early-Career GRC and Security Assurance Roles Worth Applying To
Five new openings are worth reviewing today. Curana Health and Squarespace are the strongest traditional GRC roles. SNHU is strong for controls assurance. Treasure AI is a technical GRC stretch role. Robert Half has a solid contract option for candidates around the 3-year mark. 1) GRC Security Analyst | Curana Health - Location: Remote, US - Salary: Starting at $130,000 - Experience: 2-5 years in GRC, information security, risk, audit, compliance, cybersecurity, or a related function - Education: Related bachelor's degree or equivalent experience - Skills: HIPAA, SOC 2, NIST CSF, CIS Controls, HITRUST, and ISO 27001 - Skills: Risk assessments, control validation, audit evidence, and remediation tracking - Skills: Third-party risk and vendor security reviews - Skills: Risk registers, compliance metrics, and governance documentation - Skills: ServiceNow GRC, Archer, OneTrust, AuditBoard, or LogicGate preferred This is a strong early-career health-tech GRC role because candidates at the 2-3 year level can build experience across audits, risk, controls, TPRM, policies, and compliance operations. Apply: https://general-careers-curanahealth.icims.com/jobs/4229/grc-security-analyst/job 2) GRC Analyst | Squarespace - Location: New York, NY | Hybrid, 3 days per week in office - Salary: $130,000-$170,000 - Experience: 3+ years in GRC, IT audit, security compliance, or privacy compliance - Skills: SOX, SOC 1/2, PCI DSS, NIST, and ISO - Skills: Control testing, audit scoping, findings, and issue management - Skills: Third-party security and privacy assessments - Skills: Security questionnaires and customer assurance - Skills: GRC automation, continuous monitoring, and AI-enabled workflows This is one of the strongest roles today for someone around the 3-year mark because the work covers the full audit lifecycle plus TPRM, customer assurance, privacy, and compliance automation inside a technology company.
1
0
👋 Welcome to GRC Career Path!
I created this community to help people build practical GRC skills, turn those skills into credible career proof, and approach the job search with a clear plan. This won’t be a community where you collect resources and never use them. You’ll learn how GRC work is actually performed, create a simulated portfolio, practice explaining your decisions, and build a focused strategy for the roles you want. Start here: 1. Introduce yourself in the comments using the prompts below. 2. Open the Classroom and complete Module 0: Start Here. 3. Make your own copy of the Module 0 assignment template. 4. Submit your completed assignment under the Module 0 Assignment lesson. For your introduction, share: - Your name and location - Your current role or background - The GRC role you’re interested in - Your biggest career obstacle right now - What you want to accomplish in the next 90 days I’ll go first: I’m Winton. I currently work in security assurance at Airbnb, and I came into GRC through IT audit. I created this community because too many people are told to collect certifications without learning how to evaluate risk, write controls, assess evidence, or explain their judgment. My goal is to help you leave with something stronger than course-completion screenshots. You should leave with work you can honestly discuss with hiring managers. Introduce yourself below, then head to Module 0. Module 0: https://www.skool.com/grc-career-path-4325/classroom/67e52554?md=0ab31719dcbe493fbf23e9bed3e259b0
1 like • 18d
@Natashia Sibanda Welcome! Looking forward to helping you get to your goals, Natashia 😄
0 likes • 6d
@Nadia Tanyitiku Welcome to the community! 90 days is ambitious yet possible. I believe it's all in persistence, networking, and positioning. Let's work!
Great News!
55 members today. Appreciate everyone who’s joined so far. I don’t want to keep adding resources JUST to add resources (lol). I want the next thing I build here to solve an actual problem for you. So if you're serious about this, please see below. Reply with one number: 1. I need stronger GRC resume bullets and better ways to explain my experience 2. I need hands-on practice with control testing, audit evidence, and documentation 3. I need a clearer path into a GRC, IT audit, risk, or compliance role 4. I’m already in the field and want to get better at TPRM, risk assessments, or audit work 5. Something else. Tell me what you’re stuck on in one sentence I’ll use the responses to decide what GRC Lab 002 or the next practical resource should cover.
Great News!
0 likes • 6d
Sent you all direct messages! @Shakil Ahmed @Natashia Sibanda @Hakan Silitalay
1-10 of 36
Winton Fong
3
32 points to level up
@winton-fong-4622
My name is Winton! A few fun facts: I’m a cybersecurity career coach. I work at Airbnb. I’m a fitness coach, too.

Active 18h ago
Joined Jun 25, 2026
ENFJ
San Francisco, CA