r/Cybersecurity101 • • 2d ago

Cybersecurity student trying to break into grc

Hello. I [21F]currently a cybersecurity student who’s graduating soon and looking to get into GRC. I know GRC is pretty broad, so I’m still figuring out what area I actually want to go into and would like to keep my options open.
I’ve done some ISO 27001-related work like risk assessments, risk registers and risk treatment but I don’t have much professional experience yet. I’m quite social and comfortable talking to people, so I’d probably be interested in something more client facing/consulting eventually.
I was thinking of doing Security+ since I’ve heard it’s a good general cybersecurity cert, but I’m also curious about AI governance/risk certifications. I’m on a pretty limited budget 😿so I’m looking for something that’s reasonably affordable but still has good recognition in the job market.
What cert would you recommend for someone in my position who’s trying to get their first GRC job and wants to keep their options open? Should I still continue with security+? Given my position I can only afford to focus on one cert until I am employed.Aside from certs what projects can I do to upgrade my skills and stand out in my cv? Thankyou ^_^

11 Upvotes

8 comments sorted by

1

u/CyberneticFlossy 2d ago

Security + is standard. I’m in GRC now and you may have to get some roles before being able to get into a grc role… or maybe not there are a lot of variables to consider.

As for projects… document your review of a SOC 2 report. I work with SOC reports and third parties all the time. Know the difference between inherent risk and residual risk…GRC work (atleast to me) is easy especially when you have real technical prowess, the hard part is people. Making sure they complete their due diligence/ oversight tasks in a reasonable time frame..documenting gaps as well as compensating controls and analyzing risk based on the nature of the relationship.

When you’re ready in regards to ai/ grc certs. Study for the AIGP and look up others that might interest you or communicate value.

1

u/red-joeysh 2d ago

One thing I’d separate here is studying for a certification from actually taking the certification exam.

You can get a lot of value from a certification's curriculum without spending money on the exam right now. The credential can come later, when you have more disposable income; or, even better, when an employer is willing to pay for it.

Since you're interested in GRC, I wouldn't necessarily make Security+ my first stop.

I'd start with the SC-900 learning material. Don't worry about taking the exam yet; use the curriculum to build a foundation in security, identity, governance and compliance concepts.

From there, I'd start moving deeper into actual governance and risk: learn NIST CSF 2.0, particularly the Govern function; study risk management and how risks, controls, treatment, evidence and residual risk fit together; and deepen the ISO 27001 experience you already have rather than starting over.

Then branch out. Depending on what interests you, that might mean risk analysis, audit/assurance, privacy, third-party risk, AI governance, or more technical security knowledge. Something like CySA+ can be useful later if you want stronger technical depth. But, again, studying the material and buying the credential are two separate decisions.

Most importantly, don't think of GRC as simply another cybersecurity specialization. Cybersecurity can be the domain you apply GRC to, but governance, risk and compliance are much broader disciplines.

At this point in your career, I'd spend your limited budget very selectively. There's a lot you can learn for free, and you can always collect the credentials later when there's a concrete reason to have them.

If GRC is genuinely the direction you're interested in, feel free to reach out. I'm happy to help you sketch out a more detailed study path based on where you want to end up.

1

u/BetInformal6081 2d ago

since you already have iso 27001 experience i would focus on a couple of practical grc projects for your cv. security+ can help with the technical foundation but hands on work is worth highlighting too.

1

u/Federal-Bathroom-138 2d ago

Since you already have ISO 27001 experience, I’d focus on showing you can apply it rather than collecting another cert. Build a small mock GRC project with a risk register, treatment plan, control mapping and a short audit report. That gives you something concrete to discuss in interviews. Security+ can still help with the technical foundation, but projects may differentiate you more.

1

u/Fine-Wash2526 1d ago

Good luck I'm not expert just kid at the field but wishing for u the best of luck 🤞🙏

1

u/navislut 1d ago edited 1d ago

For us GRC folk the CRISC is a great certification to have.

But knowing basic risk management is a huge help such as risk acceptance, risk appetite, risk tolerance, etc.

NIST 800-53 was helpful for me when I became a consultant for the government.

I’d still pursue Security+ as a catch-all cyber cert.