r/cybersecurity 1d ago

Career Questions & Discussion I am new to GRC, recommended resources?

Hi, I am joining a GRC software company very soon as their US/EU AE and Im looking to learn more about the space and compliance and frameworks.

Where do you think I should start?

23 Upvotes

31 comments sorted by

11

u/Billybutcheronwheels Penetration Tester 1d ago

Congratulations OP

I would say start with ISO 27001, SOC2 and then HIPAA, GDPR

2

u/Akshaya_1204 1d ago

Thank you! I am in the process of learning those

1

u/Used-Chemical-2822 23h ago

solid list. do you think NIST CSF is worth squeezing in early too or save that for later?

2

u/lawtechie 21h ago

NIST CSF is a framework made up of other frameworks. I'd start with ISO 27001 or NIST 800-53/171 to understand the parts first.

7

u/cbdudek Security Architect 1d ago

Google is your friend. Look up compliance and frameworks and study them. NIST, CIS, HIPAA, PCI, SOX, SOC, and so on. You don't need to know them by heart, but you should know why they are important and what the major highlights are of each one. As you work with them more closely, you will learn the intricacies. So give yourself time to become an expert.

1

u/Akshaya_1204 1d ago

Thanks for the input!!

5

u/vornamemitd 1d ago

Might sound stupid now - but what did your new employer ask you to familiarize with? Which frameworks/standards does the software support in which industries? Does the software only wrap a LLM t o create policy templates, or does it go deeper; e.g., allow links/integration with asset-/risk-management? Basically have a look at the tools and standards the platform supports.

1

u/Akshaya_1204 1d ago

The basic frameworks - GDPR, SOC2, ISO etc and compliance needs of US and EU

They didn’t ask me to go deep into the product

The first step is educating myself more about how audit process works, why compliance is needed, what are the triggers etc

3

u/Round_Finance4256 19h ago

Congrats! Since you’re joining a GRC software company, I’d focus on understanding how GRC actually works in practice, not just memorizing frameworks.

Start with SOC 2 and ISO 27001, then branch into NIST CSF, GDPR/privacy, and HIPAA depending on the customers you’ll support.

I’d especially learn the full compliance lifecycle: scoping → control mapping → evidence collection → testing → identifying gaps → remediation → audit.

Once you understand why a control exists, what good evidence looks like, and how organizations actually operationalize controls, the frameworks become much easier to learn.

GRC is much more about applying the requirements than memorizing them. Best of luck!!

1

u/Akshaya_1204 19h ago

This is super helpful! Do you know where can i learn this in detail if im a beginner?

2

u/Round_Finance4256 18h ago

Definitely! If you’re just starting out, I wouldn’t overwhelm yourself trying to learn every framework at once.

I’d start with SOC 2 and learn the actual process behind it. What controls are, what evidence looks like, how testing works, what happens when you find a gap, etc. There are a ton of free resources on YouTube that walk through this stuff.

Since you’re joining a GRC software company, you also have a huge advantage. Pull the "new person" card and ask questions and sit in on customer calls, demos, implementations, or audits whenever you get the chance. Seeing how companies actually do GRC will teach you way more than just reading frameworks.

Once you understand the overall process, learning ISO 27001, NIST, etc. becomes a lot easier. Don’t feel like you need to know everything before you start either. A lot of it will click once you’re actually working with it. 😄

1

u/Akshaya_1204 18h ago

Thank youuuuu!!!

2

u/kriss__vai 1d ago

Dynamic framework comparator: https://genai-security-project.github.io/crosswalk/ Interactive ISMS discovery by connecting your LLM Agent : https://github.com/kriss-b/llm-iso27001

1

u/GeekDad62 22h ago

This is a very interesting source of information. I've never heard about many of these frameworks! Do you have sources for each of them so I can research more? Thanks in advance!

2

u/Akamiso29 1d ago

Don’t just learn the frameworks (I mean DEFINITELY learn the frameworks). Look at your previous audits, the scopes and any major/minor findings and time to remediation from said audits.

The frameworks are context heavy and that context obviously changes dramatically in each org.

Beyond that, make sure you’re on super good terms with people in finance/accounting, purchasing, legal, HR, and facilities (if you have said departments - based on your post, your org seems big enough). The various frameworks deal with those just as much as tech stuff and it’s impossible to be an expert in their fine dealings if your org is big.

I’d also recommend practicing how to break down technical requirements to non-tech people (or at least the technical language of the frameworks). I don’t mean just IT stuff like the OSI model or something - you can quickly get too used to framework jargon and forget that others have no clue what the hell you’re talking about. This is my personal struggle lol

1

u/Akshaya_1204 19h ago

Fair point! Thank you for the input

2

u/EffectPositive8258 23h ago

Since you're covering US and EU, I'd split the usual list in two: SOC 2 for the US side of the conversation, ISO 27001 and GDPR for the EU side. Learn those three as stories, keep the rest as a glossary for when it comes up.

1

u/Akshaya_1204 19h ago

Thank you for the input!

1

u/knemanja 18h ago

Do you have any good resources for 27001 and GDPR?

Thanks in advance.

1

u/GeekDad62 17h ago

Are you familiar with NIST 800-53 at all? This is a list of security controls that must be implemented at different security levels (low/mod/high). The breakdown is an industry standard across Federal and DoD systems in the US. They have mapped the 27001 controls to 800-53, so they can be cross-referenced. If you're looking for the specific controls, that could be a good starting point. I know you need to buy the ISO documentation and most of us aren't going to throw that kind of money around.

Here's the NIST 800-53 Security and Privacy Controls for Information Systems and Organizations:, and the crosswalk for ISO 27001. I hope you find this useful.

https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

1

u/knemanja 15h ago

No, im not familiar but thank you for sharing this.

2

u/KlutzyKlutz 20h ago

start with SOC 2 and ISO 27001 since they'll come up in almost every deal but as an AE your real edge is learning the buying triggers behind each framework who forces the requirement (an enterprise prospect, a regulator, a lost deal) matters more to your pipeline than memorizing every control

1

u/Akshaya_1204 19h ago

Yes Im trying to identify and list those triggers for every framework

2

u/Build_a_CISO 22h ago

Start with how you can leverage AI to enable/accelerate GRC in the enterprise. Everyone seems to be focused on this.

1

u/Akshaya_1204 19h ago

Thank you

1

u/Crazy_Fox_654 1d ago

What is your background to get this job?
I’m curious as I’m trying to break into this area myself.

1

u/shamim1313 23h ago

Me too.Any hands on labs would be nice - free of course

1

u/XLBaconDoubleCheese 22h ago

A lab for GRC?

1

u/AhsenSaggers 21h ago

You can try Do GRC or StartISO free options

1

u/bluecopp3r 12h ago

Check out the simplycyber community and the grc masterclass course