Full route detail

GRC (Audit, Risk, Compliance)

Governance, risk and compliance. Policy, audit, evidence, frameworks. Biased toward CISA / CRISC / CISM, NOT toward OSCP.

Last reviewed May 2026Reviewed by a practitioner working in grc analyst hiringUpdated quarterly against live job listings

Phased progression

Foundations → first role → specialisation → advanced. The realistic order, not a script.

  1. 01Foundations
    0–6 months

    Literacy, lab habits, the cert that opens first conversations.

    ISO 27001 Lead Implementer
  2. 02First paid role
    6–18 months

    Land a GRC Analyst. Operational time, not more certs, earns the next move.

    GRC Analyst
    $70–130k entry
  3. 03Specialisation
    1.5–3 years

    Add a specialist credential aligned to the work you're already doing.

    CRISCCGRC
    $130–180k senior
  4. 04Advanced
    3+ years

    Move into adjacent roles. Long-term credentials become worth their cost.

    Compliance SpecialistCISSP
    $130–180k senior

Certification sequence

Ordered by realistic relevance, not vendor marketing.

  • CGRC

Practical projects

What to actually build, the portfolio that opens interviews.

  • Map ISO 27001 controls to a real product
  • Author a risk register with quantified risks
  • Run a tabletop exercise and write the after-action
Compliance SpecialistRisk AnalystSecurity Manager
  • ·Internal audit → security audit pivot
  • ·PM → security PM → GRC

Realistic expectations

What no recruiter will tell you.

Misconception

That stacking certifications shortcuts the timeline. It doesn't. Operational time and a public portfolio are what compress the path.

Honest window

12–24 months is the realistic time to the first role on this route. Most people overshoot by 6–12 months. Plan for it; don't panic when it happens.