Governance, Risk & Compliance
Every new privacy law and industry regulation creates more GRC headcount, and unlike a lot of hands-on-keyboard security work, this branch is a realistic path in for people coming from law, audit, or business backgrounds rather than IT — from day-to-day compliance tracking up through formal auditing and enterprise risk management.
Third-Party / Vendor Risk AnalystCyber Risk Quantification AnalystSecurity Program Manager
GRC Analyst
Turns laws and frameworks into policies the company can actually follow — and checks that it does.
What it's about & how to get in
You help translate security requirements, laws, industry frameworks like NIST or ISO 27001, and internal policy, into things the rest of the company can actually follow, then check that they're actually following them. Day to day that looks like running risk assessments, maintaining policy documents, tracking audit findings to resolution, and answering security questionnaires from customers and partners.
It's one of the more approachable entry points into cybersecurity for people who are strong writers and organized thinkers but aren't looking to spend their day in a terminal.
Where you can work
- Internal GRC or security compliance teams at mid-size and large companies
- Consulting and audit firms (including the Big Four) running compliance engagements for clients
- Healthcare organizations managing HIPAA compliance
- Financial services companies managing SOX, PCI-DSS, and similar frameworks
- SaaS companies maintaining SOC 2 compliance to close enterprise sales deals
What it pays
Certifications that open doors
Where you can actually learn it
Compliance Analyst
Focused on passing specific audits — SOC 2, ISO 27001, PCI-DSS, HIPAA.
What it's about & how to get in
A close cousin of the GRC analyst role, usually with a narrower focus on making sure the company passes specific audits and certifications, SOC 2, ISO 27001, PCI-DSS, HIPAA, rather than the broader risk-management side of GRC. You gather evidence for auditors, manage compliance tracking software, coordinate with different departments to close gaps before an audit, and keep required documentation current.
It's often the first compliance-track role someone takes, sometimes moving in from an audit, legal, or general IT background rather than a security one.
Where you can work
- In-house compliance teams, often reporting into legal, IT, or a dedicated GRC function
- SaaS companies pursuing SOC 2 or ISO 27001 certification for the first time
- Healthcare providers and their business associates (HIPAA compliance)
- Payment processors and retailers handling card data (PCI-DSS)
- Compliance-as-a-service platforms and the consulting firms built around them
What it pays
Certifications that open doors
Where you can actually learn it
IT / Security Risk Manager
Owns what could actually hurt the business, and helps leadership decide what to fix first.
What it's about & how to get in
You own the process of identifying what could actually hurt the business, a vendor with weak security, an unpatched system holding sensitive data, a regulatory gap, and quantifying it well enough that leadership can decide what to fix first and what risk to formally accept.
It's a step up from GRC analyst work: less document-chasing, more judgment calls, and regular reporting to senior leadership or the board about the company's risk posture. Most risk managers have several years of GRC, audit, or security analyst experience before moving into this role.
Where you can work
- Enterprise risk management functions at large companies, often reporting to a CISO or CRO
- Financial services firms with formal, regulator-facing risk programs
- Insurance companies — both managing their own risk and underwriting cyber insurance for others
- Consulting firms running third-party/vendor risk assessment engagements
- Healthcare and critical infrastructure organizations with regulatory risk-reporting requirements
What it pays
Certifications that open doors
Where you can actually learn it
Security Auditor
Runs the SOC 2 and ISO 27001 audits that prove a company's controls actually work.
What it's about & how to get in
A Security Auditor plans and executes internal or external audits — SOC 2, ISO 27001, PCI DSS, and similar frameworks — testing whether an organization's security controls are actually designed and operating effectively, then reporting findings to leadership, auditors, or certification bodies.
This is distinct from the Compliance Analyst role already on the site, which focuses on ongoing compliance tracking and control maintenance day to day; the Security Auditor instead runs the periodic, evidence-based audit engagements that GRC Analysts and Compliance Analysts prepare evidence for, and feeds findings back to IT/Security Risk Managers.
Where you can work
- Public accounting and audit firms (Big 4 and mid-market CPA firms performing SOC 2/ISO audits)
- Internal audit departments at large enterprises (finance, healthcare, insurance)
- GRC and cybersecurity consulting firms
- Certification bodies and ISO 27001 registrars
- Government agencies and defense contractors under FISMA/FedRAMP audit requirements