Updated by
Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

To become a GRC analyst, learn how security controls work, practise assessing evidence, and apply for roles where you can support risk, compliance or audit work. You’ll need to explain what you found, why it matters and what should happen next.
Your starting point matters. IT support experience can help you understand access controls; an audit background can help you test them. If you’re new to both, a small, well-explained project gives you something concrete to discuss while you build the foundations.
This guide covers the skills to learn, qualifications to consider and ways to find suitable first roles. You can also work through a fictional access-removal review and use its structure for your own portfolio.
What does a GRC analyst do?
GRC means governance, risk and compliance. In cybersecurity, governance establishes responsibilities and decision-making; risk work examines what could go wrong and how to respond; compliance work checks relevant requirements and the evidence supporting them. ISACA’s GRC analyst profile places IT risk, governance and organizational compliance at the center of the role.
The work produces things people can use. You might update a risk register after reviewing a supplier, gather records for an auditor, or follow up with an engineering team on an overdue security improvement. You could also help revise a policy when the written process no longer matches how the business operates.
A junior analyst usually needs clear scope and someone to review their conclusions. A role that asks you to own every audit, approve risk exceptions and build the whole program calls for different experience, whatever its title says.
Cyber GRC is also more specific than general compliance. A financial compliance job focused on transaction monitoring may have little involvement with information security. Read the responsibilities before treating every “risk analyst” or “compliance analyst” vacancy as part of this career path.
Decide whether you enjoy the work
GRC suits people who enjoy following an issue from a vague concern to a documented decision. You’ll spend time asking for evidence, comparing it with requirements and explaining gaps to people with competing priorities.
Technical understanding helps you ask better questions. If an engineer says access is removed through single sign-on, you should be curious about accounts outside that system and how the team checks them.
If you’d prefer investigating security alerts and responding to incidents, explore the SOC analyst career guide too. The teams collaborate, but their daily work differs.
Start from the experience you already have
Choose a route that lets you build on work you can already explain.
If you work in IT support or systems administration, look at your experience with account approvals, departures, patching or backup checks. You may already understand how a control operates. Your next step is learning to document its purpose, test its operation and report exceptions.
For example, you could ask your manager to let you support an access review within your existing permissions. Keep the business records in the approved workplace systems. A public portfolio should use fictional data unless you have explicit permission to share the real material.
An audit, quality or compliance background can give you practice with evidence, sampling, findings and follow-up. Build enough security knowledge to understand the systems behind those records. Reviewing a password policy is easier when you can distinguish the policy from the settings that enforce it.
If your experience is in operations, project coordination or customer support, start with the parts that transfer: maintaining accurate records, investigating discrepancies and coordinating a process through completion. Describe those responsibilities honestly. Tracking a project’s overdue actions is relevant experience, but it doesn’t become a cybersecurity audit because you change the wording on your resume.
If you have no related work experience, look for supervised opportunities such as internships, graduate programs, audit-support positions and junior security or compliance coordination. A project can demonstrate your reasoning, but it doesn’t replace a job’s mandatory work-experience requirement.
Read “junior” requirements carefully
One employer example shows why this matters. In the Engine by Starling junior information-security GRC posting reviewed on 8 September 2026, the employer welcomed early-career applicants but also specified at least one year in an information-security role. ISC2 CC and ISO 27001 Foundation training appeared among desired qualifications; GRC software experience was a plus. The employer link was checked again on 12 September 2026 and the vacancy was no longer available; this is a historical requirements example, not an opening to apply for.
That is one dated example, not a rule for the market. It shows why you should separate minimum experience, preferred qualifications and optional tools rather than treating an entry-level label as a promise of no experience.
Learn security controls and one framework
Start with concepts you can connect to observable evidence. A useful learning question is: “If someone told me this control works, what would I need to see?”
For access management, understand how accounts are created, approved, reviewed and removed. Learn what privileged access means and why an account list alone doesn’t prove every user still needs access.
For backups, distinguish a successful backup job from evidence that information can be restored. For logging, understand which system generated a record, what period it covers and who can change it. For cloud services, learn which security tasks belong to the provider and which remain with the customer.
You don’t need to become an expert in every system before applying. You do need enough context to recognize when a screenshot or policy leaves your question unanswered.
Choose a starting reference that fits your target jobs
The names in job descriptions refer to different kinds of material:
| Reference | What it is | A useful first learning task |
|---|---|---|
| NIST Cybersecurity Framework 2.0 | A set of cybersecurity outcomes organized into Govern, Identify, Protect, Detect, Respond and Recover | Describe a small organization’s current practices and one improvement it needs |
| ISO/IEC 27001:2022 | A standard specifying requirements for an information security management system, or ISMS | Explain the purpose of an ISMS, its scope and how the organization manages improvement |
| SOC 2 | An examination and reporting service concerning controls at a service organization | Learn what a report covers and why its scope matters when reviewing a supplier |
NIST’s small-business CSF resources are a manageable place to begin. ISO explains ISO/IEC 27001 and the ISMS, while the AICPA provides the authoritative introduction to SOC services.
These aren’t interchangeable labels. Avoid describing a SOC 2 report as an ISO certification or treating a framework as a law. When a role involves regulatory obligations, learn the employer’s sector and jurisdiction before studying detailed requirements.
Pick one reference from the roles you’re targeting, then use it to ask better questions about a small process. Memorizing a long list of frameworks gives you less to discuss than explaining one control and its evidence.
Get comfortable organizing the work
A spreadsheet, document editor and clear folder structure are enough for a first project. Practise filtering records, comparing dates, recording owners and keeping evidence linked to findings.
Commercial GRC tools can organize that work at scale. Learn a specific platform when your target roles call for it, but don’t buy access simply to put its name on your resume. You should be able to explain the underlying workflow without the tool.
Build a small GRC portfolio project
Create a review of employee access removal for a fictional organization. The following exercise uses invented people, records and rules. It is a practice assessment, not a real audit or evidence that any organization complies with a standard.
Our fictional business, Harbour Learning, runs short training courses. Staff use a central identity provider and a separate course-booking application. The booking application has its own local accounts.
For this exercise, its approved internal rule says both accounts must be disabled by 17:00 on the person’s last working day. That deadline is an invented company rule, not a universal framework requirement.
1. Define the scope and evidence
Review all three departures recorded in the fictional HR departure list for 1–7 June. All times below are in the same fictional local timezone.
Assume the HR list is complete for this exercise. In a real review, you’d need to establish that completeness before relying on it as the population.
| Person and last day | Central account disabled | Booking account evidence |
|---|---|---|
| Alex, 2 June | 2 June, 16:45 | Disabled 2 June, 16:50 |
| Blair, 4 June | 4 June, 16:40 | Disabled 5 June, 09:10 |
| Casey, 5 June | 5 June, 16:30 | No disable record supplied |
Create a spreadsheet with these rows and identify the evidence you would request: departure dates, account identifiers and disable records from each system. Note the source and capture date for each record so another person could follow your work.
2. Write conclusions that match the evidence
Alex’s supplied records meet the invented deadline for both systems.
Blair’s booking account was disabled after the deadline. That supports a finding about late removal. The record alone does not establish whether Blair used the account after leaving.
Casey’s booking-account result is unverified. A missing record does not prove the account remained active. Request account-status history or other reliable evidence before changing that conclusion.
You have reviewed all three departures in this exercise. Don’t claim the organization’s access-removal process works across the whole year, other applications or contractors outside your scope.
3. Turn the exception into a useful finding
Write the finding in a short paragraph:
In the review of three employee departures from 1–7 June, one booking account was disabled after the organization’s 17:00 last-day deadline. A second booking account lacked evidence sufficient to verify timely removal. Central identity-provider records met the deadline for all three departures. The booking-application process needs follow-up with its owner.
That paragraph distinguishes a demonstrated exception from missing evidence. It also states what you checked, so a reader can judge the limits.
Your next question is why the late removal happened. Perhaps HR notified IT late, the booking application was missing from the checklist, or a manual step failed. These are possible explanations to investigate, not findings you can assert from the supplied records.
4. Add a risk entry and follow-up
A risk register is a place to record an identified risk and how it will be managed. For this exercise, write an entry along these lines:
Former staff could retain access to the booking application after departure, allowing unauthorized viewing or changes to course records. The application owner will investigate the late removal and resolve the missing evidence. The proposed improvement is to add an explicit booking-account task to the departure workflow, with an assigned owner and completion evidence.
Leave the likelihood and impact rating provisional until you’ve stated your assumptions about access, information sensitivity and existing safeguards. A colored “high risk” cell without a reason doesn’t explain much.
Propose a target date for the fictional owner to investigate, and a later check of new departures after any process change. Record who would approve the response. A junior analyst can recommend action and track it; authority to accept the remaining risk belongs to the role designated by the organization.
Don’t close the finding just because someone promises to update the checklist. State what evidence you would need to confirm the change and whether it worked for subsequent departures.
5. Package the project so someone can review it
Keep the finished work small enough to read in one sitting. Include:
- A one-page description of the fictional business, systems, rule and review scope.
- The invented evidence table and your assessment of each row.
- The finding, open questions and proposed follow-up.
- A short note explaining the limits and what you would test next.
You can copy this structure into your own document:
Process reviewed:
Purpose of the control:
Rule used and where it comes from:
Systems and review period:
Population and how completeness was established:
Evidence requested and received:
Result, exceptions and unknowns:
Proposed action, owner and target date:
Evidence needed before closure:
Limitations and next review:
Change the scenario and work through it yourself. You could review supplier-access approvals or a backup-restoration process instead. Keep everything fictional and label the project clearly when sharing it.
Choose certifications that fit your next role
Use certification study to address a learning gap or a requirement you’ve seen in suitable vacancies. There is no universal sequence that every GRC applicant needs to buy.
For foundational study, ISC2 Certified in Cybersecurity (CC) is designed for people entering the field and has no work-experience requirement. Check the current ISC2 CC page for the exam and certification process rather than relying on an old free-exam promotion.
CompTIA Security+ covers broader security knowledge, including threats and risk management. CompTIA’s official badge description describes its scope and recommended experience. Consider it when that foundation would help you or your target employers request it; studying it is a different decision from assuming every GRC job requires it.
The specialist credentials below involve professional experience:
| Credential | Experience distinction to understand |
|---|---|
| ISC2 CGRC | Requires two years of relevant experience. Someone who passes the exam before meeting the requirement can pursue the Associate of ISC2 route |
| ISACA CISA | Has a five-year relevant-experience baseline, with specified waivers available. Passing the exam alone does not make you CISA certified |
| ISACA CRISC | Requires three years of relevant work across at least two of its four domains. Exam eligibility and certification eligibility are separate |
Check the official requirements for CGRC, CISA and CRISC. CISA’s application guidance explains its waivers. Apply the current rules to your own background before paying for a path.
Training completion, an exam pass and an awarded professional certification are different achievements. Describe the one you hold accurately. Budget for the whole process, including any application, membership or renewal requirements, as well as training and the exam.
Apply for work you can support
Search beyond the exact title “GRC analyst.” Look at junior IT risk, security compliance, third-party security risk, IT audit associate and information-security governance roles. Then check whether their responsibilities match the cyber work you want.
Start with the GRC analyst jobs on Cybersecurity Jobs List, and read each employer’s full description. Compare the role’s scope, required experience, location and work authorization with your circumstances. Remote arrangements can still restrict where you may work.
For a first role, look for a team that can review your work. Useful interview questions include who approves findings, who owns remediation and how a new analyst learns the organization’s systems. Ask how much of the role involves evidence collection, control testing, supplier reviews or program ownership.
Make your resume specific and truthful
Connect each relevant responsibility to something you did or produced. These are illustrative bullets, not achievements to copy as your own:
Supported employee departures by checking account-removal tickets against the departure list and escalating missing completion records to the IT lead.
Built a fictional access-removal review covering two systems; distinguished a late removal from an unverified result and documented the evidence needed for follow-up.
The first belongs under employment only if it describes your real work. The second belongs under projects and should remain labeled as a simulation. Add quantities or outcomes only when you can substantiate them.
Keep a link to the project beside its description. Make sure the file opens without requesting access and that it contains no workplace records, account details or confidential screenshots.
Practise explaining your judgment
Use your project to answer three questions in your own words:
- What evidence would change your conclusion?
- How would you explain the concern to the process owner?
- What would you check before reporting that the issue is resolved?
For Casey’s missing record, a useful answer explains what remains unknown and which additional evidence could resolve it. For Blair’s late removal, explain why you would investigate the cause before recommending a particular tool or automation.
You can also practise a short manager update: what you reviewed, what needs attention and which decision or action you need. Avoid claiming a breach occurred when the evidence only shows an access-removal exception.
Compare the conditions as well as the title
Ask about audit deadlines, travel, working hours and support during busy periods. GRC doesn’t guarantee a particular work-life balance.
For pay, compare advertised ranges for similar responsibilities in your own location. Check currency, annual salary versus contract rate, and whether bonuses or equity are separate. A senior risk-management salary from another country is a poor benchmark for your first analyst offer.
A four-week plan for your first work sample
This is a suggested study schedule for producing a project, not a prediction of when you’ll get hired. Adjust it around your existing knowledge and available time.
Week 1: Read a small set of suitable job descriptions. Note recurring responsibilities, required qualifications and preferred skills. Choose one process to study and read the relevant introductory material.
Week 2: Build your fictional scenario. Define the system boundaries, control purpose and rule, then create a small evidence set with both a clear result and an unresolved question.
Week 3: Write your assessment, finding and follow-up plan. Ask a knowledgeable reviewer for feedback if one is available. Revise anything you can’t support with the evidence.
Week 4: Prepare the final project and a truthful resume description. Practise walking through your decisions, then apply to suitable roles while continuing to learn.
You’re ready to share the project when another person can follow the evidence to your conclusion, see what remains uncertain and understand your proposed next step.
When you turn that experience into an application, use our annotated GRC resume example to describe the evidence you reviewed, your contribution and the decisions that belonged to someone else.
Questions about starting in GRC
Can you become a GRC analyst without a degree?
A degree requirement depends on the employer and role. Some vacancies accept other education or relevant experience; others specify a degree. Check the full description rather than assuming either that a degree is mandatory everywhere or that it never matters.
Can you get into GRC with no experience?
You can build relevant knowledge and apply for supervised early-career opportunities without a previous GRC title. Whether you qualify depends on what the employer requires. A project helps demonstrate your thinking, while internships, internal support work and adjacent roles can provide supervised experience.
Do GRC analysts need to code?
Coding is not the main activity in every GRC role. Evidence review, writing and coordination can be central, while engineering-oriented compliance roles may expect scripting or automation. Read the duties. Even without coding, you’ll benefit from understanding the systems and controls you assess.
How long does it take to become a GRC analyst?
There’s no reliable universal timeline. Your existing experience, study time, location and the vacancies available all matter. Set milestones you can evaluate, such as explaining an access control, completing a review and discussing a finding, rather than treating a course’s duration as a hiring forecast.
Where can a GRC career lead?
You can build depth in IT risk, security compliance, third-party risk or audit, and later take responsibility for more complex work or a team. Progress depends on your experience and the organization. A first analyst role doesn’t imply a fixed timetable to management.
Choose one suitable GRC vacancy, identify a responsibility you need to understand better, and make that the focus of your next work sample.


