If you already work in audit, legal, banking or administration, you are closer to a cybersecurity GRC role than most people starting from zero. You already handle evidence, policies, deadlines and regulators; the gap is technical literacy and the vocabulary of security frameworks, and both can be closed deliberately in a few months of focused work.
This post is for the career changer who wants a plan rather than encouragement. It covers what transfers from each background, what does not, the frameworks to learn first, three work samples you can build at home, and how to rewrite your CV so a security hiring manager recognises you.
What does a GRC analyst actually do all week?
Governance, risk and compliance (GRC) is the part of security that decides what should be protected, how much risk the organisation will accept, and whether it can prove its controls work. A typical week for an entry-level GRC analyst might include:
- Collecting evidence for an audit: access reviews, backup logs, training records.
- Updating the risk register after a new system goes live.
- Mapping a policy to a framework such as ISO/IEC 27001 or NIST CSF 2.0 and noting the gaps.
- Sending a security questionnaire to a vendor and assessing the answers.
- Chasing control owners for overdue actions, and writing it up for a committee.
If that list sounds like your current job with different nouns, that is the point. For a fuller picture of the role, read What is a GRC analyst?.
Which of your skills transfer, and what is missing?
Each background brings something different. Be honest about both columns.
| Background | What transfers directly | What you need to add |
|---|---|---|
| Internal or external audit | Control testing, sampling, evidence standards, working papers, writing findings | How IT controls work technically (access management, logging, backups, change management) |
| Legal or company secretarial | Reading regulation closely, contracts and data-processing clauses, privacy law, careful drafting | Risk assessment methods, security controls, how data actually flows through systems |
| Banking (operations, risk, compliance) | Regulatory reporting, operational risk, KYC/AML control thinking, incident escalation | Security frameworks, technical vocabulary, cloud and identity basics |
| Administration or office management | Process documentation, supplier management, policy rollout, organising evidence and people | Most of the technical layer, and risk methodology |
The common gap across all four is technical literacy. You do not need to configure a firewall, but you must understand what one does well enough to judge whether “we have a firewall” is real evidence. An auditor who cannot tell a meaningful access review from a screenshot of a user list will struggle.
Which frameworks should I learn first?
Learn three properly rather than ten badly.
- NIST Cybersecurity Framework 2.0. Free to download from NIST. It organises security outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Version 2.0 added Govern, which is essentially the GRC function written down. It is the friendliest starting point.
- ISO/IEC 27001:2022. The international standard for an information security management system, published by ISO. Learn the structure: the management-system clauses (context, leadership, planning, support, operation, performance evaluation, improvement) and the Annex A list of 93 controls grouped into organisational, people, physical and technological themes. The standard itself is paid; plenty of free summaries explain the structure.
- The data protection law that applies where you work. In Nigeria that is the Nigeria Data Protection Act 2023, enforced by the Nigeria Data Protection Commission, which also issues implementation guidance. In the UK it is UK GDPR and the Data Protection Act 2018. Lawyers and compliance staff often have a head start here.
Once those are solid, add whatever your target employers use. Fintechs selling to foreign customers often meet SOC 2, an attestation built on the AICPA’s Trust Services Criteria. Banks in Nigeria work to Central Bank of Nigeria cybersecurity requirements; read the current circulars on the CBN website rather than relying on summaries.
A 90-day plan for the switch
This assumes 8–10 hours a week alongside a full-time job. Adjust the pace, not the order.
Days 1–30: technical literacy
Your aim is to be able to explain, in plain English, how a small organisation’s IT works and where it goes wrong.
- Learn networking basics: IP addresses, DNS, ports, firewalls, VPNs.
- Learn identity basics: accounts, groups, multi-factor authentication, privileged access, joiners-movers-leavers.
- Learn the common attacks at a conceptual level: phishing, credential theft, ransomware, misconfigured cloud storage.
- Start Security+ study if you want a structured syllabus. Its Security Program Management and Oversight domain (20% of SY0-701) is close to day-to-day GRC work, and the other domains give you the technical layer.
A useful test at the end of month one: could you explain to your current boss why “we have antivirus” is not the same as “we are protected from ransomware”?
Days 31–60: frameworks and risk
- Read NIST CSF 2.0 end to end. Write one sentence per category in your own words.
- Learn ISO/IEC 27001’s clause structure and skim the Annex A control list.
- Learn one risk method: identify asset, threat, vulnerability; score likelihood and impact; decide to treat, transfer, avoid or accept.
Days 61–90: build three work samples
Hiring managers for junior GRC roles rarely see evidence of actual work. Give them some. Build all three for a fictional organisation, for example a 40-person payments start-up called Acme Fintech.
1. A small risk register (10–15 risks). Use a spreadsheet. Example rows:
| ID | Risk | Likelihood (1–5) | Impact (1–5) | Score | Treatment | Owner |
|---|---|---|---|---|---|---|
| R-01 | Staff reuse passwords; one phished account exposes customer data | 4 | 4 | 16 | Enforce MFA on email and admin tools within 30 days | Head of IT |
| R-02 | Leavers keep access to the cloud console | 3 | 5 | 15 | Monthly access review signed by team leads | Head of IT |
| R-03 | Only backup copy sits in the same cloud account as production | 2 | 5 | 10 | Add an isolated, tested backup copy | CTO |
In the spreadsheet, the score column is simply =C2*D2. Add conditional formatting so anything 15 or above turns red. Simple scoring like this is a common starting point; say in your notes that real organisations calibrate the scales.
2. A gap assessment. Pick ten NIST CSF 2.0 categories. For each, write what Acme does today, what good looks like, the gap, and a recommended action. Two pages is plenty.
3. One policy, rewritten. Draft an access-control policy of no more than two pages. Lawyers and admin professionals usually shine here: clear, short, enforceable. Note which ISO/IEC 27001 Annex A controls it supports.
Put all three in a PDF portfolio or a simple website. In interviews, walk through how you scored the top risk and why.
How do I rewrite my CV for a GRC role?
Translate, don’t invent. Every bullet should show a GRC skill using your real experience.
| Before | After |
|---|---|
| “Conducted branch audits” | “Tested operational controls across 12 branches, sampled evidence and reported exceptions to the audit committee” |
| “Reviewed vendor contracts” | “Reviewed supplier contracts for data-protection and confidentiality clauses; flagged gaps to legal and procurement” |
| “Handled KYC escalations” | “Escalated and documented control failures in customer due diligence under regulatory deadlines” |
| “Managed office IT and suppliers” | “Maintained the supplier register and coordinated onboarding and offboarding of staff system access” |
Use the numbers you genuinely have. Then add a “Security projects” section linking your three work samples.
Which GRC jobs can a career changer apply for?
Titles vary a lot. Search for: GRC analyst, IT risk analyst, information security analyst (compliance), IT audit associate, third-party risk analyst, data protection officer assistant, compliance analyst (technology). If you are in banking, look first at your own organisation’s IT risk or information security team; an internal move, where people already trust your work, is often the easiest route.
Not sure GRC is the right side of security for you? Compare it honestly in GRC analyst vs SOC analyst: which suits you?. And if age is part of the worry, read Switching to cybersecurity at 30, 40 or later.
Do I need a certification to get into GRC?
Not strictly, and no certification guarantees a job. A recognised baseline helps you get past CV filters, though, and Security+ is a common choice because it proves the technical literacy that career changers are assumed to lack. Several well-known GRC and audit certifications have work-experience requirements, so check each issuer’s eligibility rules before you pay for anything. A short-course certificate is not a certification; list it under training.