GRC (Audit, Risk, Compliance)
Governance, risk and compliance. Policy, audit, evidence, frameworks. Biased toward CISA / CRISC / CISM, NOT toward OSCP.
The lane the technical-security crowd looks down on, and the one that quietly pays well and travels into management. Worth taking seriously if the framework work doesn't bore you.
You're comfortable with policy, audit and stakeholder management, and you'd rather write a risk paper than chase an alert. GRC is the cleanest route from non-technical backgrounds into security.
You want hands-on technical work. You'll spend most days in meetings, spreadsheets and evidence requests, and pretending otherwise leads to burnout inside a year.
Phased progression
Foundations → first role → specialisation → advanced. The realistic order, not a script.
- 010–6 monthsFoundations
Literacy, lab habits, the cert that opens first conversations.
ISO 27001 Lead Implementer - 026–18 monthsFirst paid role
Land a GRC Analyst. Operational time, not more certs, earns the next move.
GRC Analyst£32–48k GRC analyst - 031.5–3 yearsSpecialisation
Add a specialist credential aligned to the work you're already doing.
CRISCCGRC£55–80k senior - 043+ yearsAdvanced
Move into adjacent roles. Long-term credentials become worth their cost.
Compliance SpecialistCISSP£85–120k GRC manager (UK; regulated firms top end)
- 01Foundations0–6 months
Literacy, lab habits, the cert that opens first conversations.
ISO 27001 Lead Implementer - 02First paid role6–18 months
Land a GRC Analyst. Operational time, not more certs, earns the next move.
GRC Analyst£32–48k GRC analyst - 03Specialisation1.5–3 years
Add a specialist credential aligned to the work you're already doing.
CRISCCGRC£55–80k senior - 04Advanced3+ years
Move into adjacent roles. Long-term credentials become worth their cost.
Compliance SpecialistCISSP£85–120k GRC manager (UK; regulated firms top end)
Certification sequence
Ordered by realistic relevance, not vendor marketing.
Practical projects
What to actually build, the portfolio that opens interviews.
- Map ISO 27001 controls to a real product
- Author a risk register with quantified risks
- Run a tabletop exercise and write the after-action
- ·Internal audit → security audit pivot
- ·PM → security PM → GRC
Realistic expectations
What no recruiter will tell you.
That GRC is the easy route. It's the easier-to-enter route, which is different. The senior end of GRC is high-stakes work with auditors, regulators and the board, and that's not a soft skill.
Twelve to twenty-four months to first GRC role from a relevant background like audit, project management or compliance. Cold entry from a non-IT, non-business background is genuinely hard.
Where this fits
A pathway is a sequence, not a destination. Here are the roles and certs along it.
- Security Architect (after 7+ years)
Design the trust boundaries. Pursued after 7+ years of hands-on work, not as a starting lane.
- Cloud Security Engineer
Cloud-native IAM, workload security, policy-as-code. Entered from cloud, not from SOC.
- Enterprise IT. Windows / AD / M365
The Microsoft-shop spine. A durable, hireable lane and a direct on-ramp to security, cloud and IAM.
- AI will not delete IT, but it will shrink one kind of IT role
The 'AI replaces all of IT' narrative is wrong. The narrower version is mostly right, and worth planning around.
- Is CISSP actually worth it in 2026?
Yes, but only for a specific person at a specific moment. For everyone else it's 12–18 months optimising for the wrong thing.
- How people actually get their first job in cyber
In progress. Not via the cert stack the influencers sell. Five real patterns, ranked by how often they work.
The next step
The pathway is plausible. Whether it holds for five years is a different question.
A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.
A route shows what people usually do. A Career Verdict judges whether it's realistic for you.
A Career Verdict includes
Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.