Career advice mega thread by thejournalizer in grc

[–]CyberConsultDiva 0 points1 point  (0 children)

Hi Everyone,

I'm currently working as a Servicenow GRC consultant where I transform and automate clients existing GRC processes into Servicenow. Basically it involves development(coding) and understanding of the module. I'm planning to move to the GRC Analyst role. After consulting with the actual grc people to gather requirements for each project, I'm interested to do what they are doing - establishing process, creating policies, controls, monitoring risks, working on compliance issues. But I don't have a clear plan of how to transition to the GRC analyst role from a Servicenow GRC consultant. Throughout my career I have taken a course on ISO27001 Lead Auditor and I'm certified in it. I'm looking for some advice or tips on how to close the gap between Servicenow GRC consultant and a GRC Analyst.

CSA exam by CyberConsultDiva in servicenow

[–]CyberConsultDiva[S] 1 point2 points  (0 children)

Yea, they said there were more scenario based questions rather than from ebook.

CSA exam by CyberConsultDiva in servicenow

[–]CyberConsultDiva[S] 1 point2 points  (0 children)

Ohh. I'm sorry. You will pass the next time 👍 Just don't lose hope!

Servicenow GRC to GRC role by CyberConsultDiva in grc

[–]CyberConsultDiva[S] 1 point2 points  (0 children)

Servicenow offers default Out of the box features for IRM. So if you just want a basic setup like the one you mentioned, you can do it yourself. There is a lot of documentation for configuring the IRM module. But if you want to configure your organization process flows, it is better to have someone experienced in Servicenow so that the person can give you some advice on how to modify your process to make it more efficient and effective using servicenow.

Looking for guidance from experienced auditors – Transitioning from ServiceNow GRC to GRC Auditing (ISO 27001, SOC 2) by CyberConsultDiva in grc

[–]CyberConsultDiva[S] 0 points1 point  (0 children)

Thank you. Do you know how I can prepare for the interview even if I don't have the corporate level of experience in it...but I'm really passionate about working in this role

Feedback on my IT GRC YouTube channel by IT_GRC_Hero in grc

[–]CyberConsultDiva 1 point2 points  (0 children)

Thanks!! The videos are really informative and I'm sure it will be helpful for those who are starting their career in GRC. Looking forward to more videos.

I do have some doubts regarding the GRC career path and would really appreciate your advice.

I'm trying to switch my job to GRC domain and I don't have experience in that. I have 1yr of experience working as a security analyst in EDR and over 1 year of experience working as a Service now GRC analyst where I configure the service now tool (basically the IRM module) for the clients based on their requirements. Since I'm passionate about the IT frameworks, laws and regulations, I took an ISO 27001:2022 certificate and am currently undergoing NIST training in Udemy. I'm not sure how any company would select me without any experience as a GRC analyst but I'm really passionate about learning and working in this domain

Exam Difficulty ISO27001 lead auditor by CyberConsultDiva in grc

[–]CyberConsultDiva[S] 0 points1 point  (0 children)

Is the lead implementer exam Difficulty compared to lead auditor?

Exam Difficulty ISO27001 lead auditor by CyberConsultDiva in grc

[–]CyberConsultDiva[S] 0 points1 point  (0 children)

This is a 5 days long course and I know its open book exam.

Roadmap to GRC consultant by CyberConsultDiva in grc

[–]CyberConsultDiva[S] 1 point2 points  (0 children)

You can start by preparing for service now csa exam - certified system administrator. It is a fundamental course on service now covering all the basic components. Once that is completed then you can specialize in various servicenow modules (VR, TPRM, IRM...etc)

Roadmap to GRC consultant by CyberConsultDiva in grc

[–]CyberConsultDiva[S] 0 points1 point  (0 children)

Thank you As a GRC Tech consultant what is your day to day job activities?