I found six (6) GRC and security assurance roles that look realistic for people trying to break into the field or build their first few years of experience. I want y'all to take a look and see if any of these align with your goals. 1. Jamf | Security Risk & Compliance Analyst Remote US $85K–$154K 1+ year experience Focus: NIST, ISO 27001, SOC 2, vendor risk, risk assessments, security questionnaires 2. KAYAK | Associate GRC Analyst Cambridge/Concord, MA | Hybrid $85K–$95K Early career. Internships, academic projects, capstones, and volunteer experience can count. Focus: NIST CSF, SOC 2, PCI DSS, control testing, audit evidence, BC/DR 3. Commerce | Security GRC Analyst I Remote US $50K–$73K 0–2 years, internships count Focus: SOC 2, ISO 27001, NIST, PCI DSS, third-party risk, evidence collection 4. Zip | GRC Analyst San Francisco $95K–$150K + equity 2+ years Focus: SOC 1, SOC 2, ISO 27001, ISO 42001, vendor risk, security questionnaires 5. InterSystems | Technical Cybersecurity Associate Boston | Onsite $87K–$109K 1–3+ years Focus: SOC 2, ISO 27001, HITRUST, NIST, FedRAMP, audit readiness, cloud security 6. Vercel | GRC Analyst Remote/Hybrid US Up to $202K in SF 3+ years Stretch role Focus: SOC 2, ISO 27001, PCI, HIPAA, cloud audits, controls, remediation, GRC tooling the biggest pattern across these roles: employers keep asking for SOC 2, ISO 27001, risk assessments, control testing, evidence collection, vendor risk, and basic cloud knowledge. if you're trying to break into GRC, build projects and resume bullets around those activities instead of only listing framework names under a skills section.