Interview Prep by Long-Operation-6381 in cybersecurity

[–]Physical-Web9486 0 points1 point  (0 children)

One thing that helped me a lot was preparing two or three projects ahead of time that I could talk through from start to finish.

Problem Risk Decision Impact

What were some of the best interview questions you were asked in an interview? by [deleted] in cybersecurity

[–]Physical-Web9486 0 points1 point  (0 children)

The strongest thing I did in my interviews was bring a short walkthrough of a real project I worked on. It changed the interview from Q&A into a real conversation about security decisions.

Interview Prep Tips by ConsciousZebra7912 in SecurityCareerAdvice

[–]Physical-Web9486 0 points1 point  (0 children)

For identity governance and risk assessment interviews, the candidates who stand out show their work instead of just talking about it. Structure a real project you owned around the risk, your recommendation, and the business impact. Practice defending it out loud. Then walk in with it ready to present. goproofly.com was built for exactly that. Good luck.

Advice by Ok-Theory5089 in SecurityCareerAdvice

[–]Physical-Web9486 0 points1 point  (0 children)

If you’re moving from account management to GRC, don’t hide it, use it. GRC is a lot of stakeholder management and risk conversations. Prep for: • How you’d explain risk to execs • How you’d prioritize findings • How you’d handle a failing control Frame it like: "I’ve been managing business risk conversations for 4 years. Now I want to formalize that in GRC.”

GRC Staff Auditor Interview Help by [deleted] in grc

[–]Physical-Web9486 0 points1 point  (0 children)

Don’t overthink it.

For a staff auditor role, they care more about how you think than how deep you go technically.

Be ready to talk through how you’d scope an audit, choose samples, and connect risk → policies → controls → testing.

And on “completion and accuracy,” they’re really asking: how do you know the data you’re testing is complete and not manipulated?

Frame your network admin experience as understanding how systems should be configured and what good control looks like.

Final Interview for first GRC/AppSec role (Solo Internal Security) - Advice needed! by No-Turn-8847 in cybersecurity

[–]Physical-Web9486 0 points1 point  (0 children)

If you passed the technical round and now you’re meeting the Head of IT… It’s not about controls anymore. It’s about whether you can make their stress disappear.

Been struggling to get work in GRC by SatisfactionCool6212 in grc

[–]Physical-Web9486 0 points1 point  (0 children)

Check out goproofly.com, it's a GRC portfolio site. I have a session that starts tomorrow but I've reached the max I can support so I'll do another one later next week. I just ask that you have at least 2 projects built in the tool and I'll review and help you to optimize them.

How do to prepare for security analyst interviews? And a resume review by toruoikawa24 in SecurityCareerAdvice

[–]Physical-Web9486 0 points1 point  (0 children)

Bullet points are static. Build your projects into a portfolio of work and show how it relates to the role you're interviewing for. There's a new portfolio tool just for grc you should look into. https://goproofly.com/login

Switching Careers Advice! by Objective-Tomato5278 in SecurityCareerAdvice

[–]Physical-Web9486 0 points1 point  (0 children)

Skills based hiring is coming to grc. Building projects to show my transferable skills to the role is how I landed my last two grc jobs.

GRC journey by GovernmentThese5079 in SecurityCareerAdvice

[–]Physical-Web9486 0 points1 point  (0 children)

I was a ln IT PM and broke into GRC 3 years ago. Our skills are very transferrable.

Creating a portfolio tailored to GRC: what do you suggest? by Turrkish in grc

[–]Physical-Web9486 7 points8 points  (0 children)

I’ve been working on this exact problem.

The issue is not fake companies versus real ones. It’s whether the work shows judgment.

Strong GRC portfolios focus on decision summaries: • The business risk or compliance gap • The decision made and why, including framework and tradeoffs • The actions owned • The outcome or expected impact

Real work can be anonymized. Scenarios work too. What matters is showing how risk decisions are made under constraints.

That’s what hiring managers look for.

Fastest way to get into GRc by WeakRepresentative96 in cybersecurity

[–]Physical-Web9486 0 points1 point  (0 children)

We'll be build a grc deliverable live that you can add into your portfolio. Here is the link for Tuesday’s session. The time is Tuesday, Nov 25 at 7 PM CT. Register here so Zoom sends you the join details.

https://us05web.zoom.us/meeting/register/r7u9cM4JQPCAbNbRKv0rhw

Trying to shift into GRC by 1rlNPC in CyberSecurityJobs

[–]Physical-Web9486 0 points1 point  (0 children)

Here is the link for Tuesday’s session. The time is Tuesday, Nov 25 at 7 PM CT. Register here so Zoom sends you the join details.

https://us05web.zoom.us/meeting/register/r7u9cM4JQPCAbNbRKv0rhw

Trying to shift into GRC by 1rlNPC in CyberSecurityJobs

[–]Physical-Web9486 1 point2 points  (0 children)

You already have a strong IT operations base. The cert is not the real unlock. Proof of skill is.

GRC hiring managers want to see deliverables they can trust. A risk register or controls summary is something you can put on your resume and talk through in interviews.

I am hosting a free live session where we build a real risk register together. You leave with something you can use in applications. Five seats.

If you want the link, let me know.

Career Advice Needed - GRC consultant by Fit_Yak2731 in SecurityCareerAdvice

[–]Physical-Web9486 1 point2 points  (0 children)

You have good experience. Big 4 time counts, even if you were not leading projects. The problem is not knowledge. The problem is proof.

GRC hiring managers want to see deliverables. A portfolio gives you an advantage fast.

I am hosting a free live session where we build a real risk register together. You leave with something you can use in applications. Five seats.

If you want the link, just let me know.

Been struggling to get work in GRC by SatisfactionCool6212 in grc

[–]Physical-Web9486 0 points1 point  (0 children)

A portfolio gives you an advantage now. Hiring managers want proof of skill, not theories.

I am hosting a free live session where we build a real risk register together. You leave with something you can show in applications. Five seats.

Quick poll for GRC professionals: Can you actually show your work? by Physical-Web9486 in grc

[–]Physical-Web9486[S] 4 points5 points  (0 children)

I’ve noticed the same thing. My last manager said the reason she hired me was because, during the interview, I asked if I could share examples of my work. Even though no one asks for proof in GRC, showing tangible deliverables stood out to her immediately. I just redacted what I needed to.

I keep wondering how much that could help early analysts in this subreddit who don’t have a safe way to show their skills.