User
Write something
Pinned
👋 Welcome to GRC Career Path!
I created this community to help people build practical GRC skills, turn those skills into credible career proof, and approach the job search with a clear plan. This won’t be a community where you collect resources and never use them. You’ll learn how GRC work is actually performed, create a simulated portfolio, practice explaining your decisions, and build a focused strategy for the roles you want. Start here: 1. Introduce yourself in the comments using the prompts below. 2. Open the Classroom and complete Module 0: Start Here. 3. Make your own copy of the Module 0 assignment template. 4. Submit your completed assignment under the Module 0 Assignment lesson. For your introduction, share: - Your name and location - Your current role or background - The GRC role you’re interested in - Your biggest career obstacle right now - What you want to accomplish in the next 90 days I’ll go first: I’m Winton. I currently work in security assurance at Airbnb, and I came into GRC through IT audit. I created this community because too many people are told to collect certifications without learning how to evaluate risk, write controls, assess evidence, or explain their judgment. My goal is to help you leave with something stronger than course-completion screenshots. You should leave with work you can honestly discuss with hiring managers. Introduce yourself below, then head to Module 0. Module 0: https://www.skool.com/grc-career-path-4325/classroom/67e52554?md=0ab31719dcbe493fbf23e9bed3e259b0
Pinned
📥 Free GRC Resume Template (Grab yours inside the Classroom!)
Hey everyone, the free resume template is available in the Classroom, along with tips for presenting your experience and portfolio projects for GRC, IT audit, and security assurance roles. Grab your template here. If you’re stuck on a resume bullet, share it below with the role you’re targeting. Remove any personal or confidential information, and we can work through it together.
What certification are you working toward next?
I want to make sure the free resources I add here are actually useful, not just more stuff to scroll past. What certification are you focused on right now, and why? It could be CISA, Security+, CISSP, CRISC, ISO 27001, or something else. Drop the cert and your reason in the comments. I’ll use the responses to decide which certification guide, study plan, or practical resource I build next.
4 Early-Career GRC and TPRM Roles Worth Applying To This Week
Howdy y'all! Look below for some open roles. Four new roles cleared the filter. Cloud for Good is the strongest traditional GRC opening. TIAA is the best true entry-level opportunity because it requires no prior experience. Broadridge is a clean 1-3 year TPRM role. Rose International is a solid contract option for someone with about 3 years of risk experience. 1) IT GRC Analyst | Cloud for Good - Location: Remote, US or Canada | Up to 30% travel - Salary: Not listed in the verified posting - Experience: 2+ years in GRC, IT compliance, or security operations - Skills: SOC 2 Type I/II, audit evidence and auditor coordination, vendor and penetration-test management, security questionnaires and due diligence, risk registers and security policies - Why it matters: This is a strong early-career GRC role because you would own real SOC 2, customer assurance, vendor risk, policy, evidence, and remediation work instead of just supporting one narrow compliance process. - Apply: https://www.linkedin.com/jobs/view/it-grc-analyst-at-cloud-for-good-4458273622 2) 2027 Early Talent Rotational Program: Audit, Risk & Compliance | TIAA - Location: Charlotte, NC | Hybrid/in-office - Salary: $28.22-$35.53/hour - Experience: No experience required - Education: Bachelor's degree required - Start date: July 2027 - Skills: Audit program execution, risk and compliance operations, regulatory assessments, governance reporting, process and procedure documentation - Why it matters: This is one of the better genuine break-in opportunities because the 24-month program provides up to three rotations across Audit, Risk, and Compliance with no prior professional experience required. - Apply: https://careers.tiaa.org/2027-early-talent-rotational-program-audit-risk-compliance/job/74F263FAFF1ECA82A9334779057BF8B8
1
0
GRC Weekly Brief 001 | AI Threats, Vulnerability Priorities, and a NIST Resource
October 1, 2026 Starting a weekly roundup here of GRC, AI, and cybersecurity updates worth understanding. I’ll include the sources and what I’d pay attention to in the actual work. 1) CISA is changing its vulnerability updates CISA announced September 28 as the retirement date for its weekly Vulnerability Bulletin, part of a shift toward risk-based vulnerability prioritization. My takeaway: If your vulnerability process depends on a weekly email or a severity score, review it. Can you explain which affected systems matter most, who owns remediation, and what evidence supports closing a finding? Source: CISA bulletin notice https://www.cisa.gov/news-events/bulletins 2) Anthropic reports AI being used to coordinate cyberattacks Anthropic’s September threat report describes cases where attackers used AI to execute or coordinate reconnaissance, exploitation, and data theft. Humans still directed targets and reviewed results. The report covers activity from December 2025 through August 2026, rather than attacks that all happened this week. My takeaway: Give your next incident-response exercise a tighter timeline. Test how quickly the team can identify the owner, revoke compromised access, preserve evidence, and escalate. Treat these as vendor-reported case studies, not a measurement of every attacker’s capabilities. Source: Anthropic’s September report https://www.anthropic.com/threat-intelligence-report-september-2026 3) A practical NIST resource to review before October 15 NIST’s draft SP 1353 explores using AI for Cybersecurity Framework analysis and reporting. Released in August, it includes example prompts, simulated company files, and three illustrative use cases. Public comments remain open through October 15. This is draft guidance. My takeaway: This could make a useful portfolio exercise. Use the fictional company materials, generate a draft analysis, then document what you corrected and why. Show your judgment alongside the output.
1
0
1-30 of 37
powered by
GRC Career Path
skool.com/grc-career-path-4325
Career changers and early-career cybersecurity professionals trying to land their first dedicated GRC role.
Build your own community
Bring people together around your passion and get paid.
Powered by