DEV Community

Cover image for GRC Analyst
M.naveen
M.naveen

Posted on

GRC Analyst

When people hear cybersecurity, they often think about penetration testing, hacking, malware analysis or SOC operations.

But there is another important side of cybersecurity that doesn't require you to spend your day hacking systems:

GRC — Governance, Risk and Compliance.

GRC professionals help organizations understand security risks, follow regulations and standards, maintain security policies, prepare for audits and make sure security controls are working.

What Does a GRC Analyst Do?

A GRC Analyst helps an organization answer questions like:

What cybersecurity risks do we have?
What security controls do we have?
Are our controls working?
Are we following required regulations?
Are our policies up to date?
Are vendors following security requirements?
What evidence do we need for an audit?
How should we reduce identified risks?

What Does a GRC Analyst Actually Do?

Imagine a company wants to prepare for an ISO 27001 audit.

A GRC Analyst may:

  1. Identify requirements

  1. Map requirements to security controls

  1. Identify control owners

  1. Collect evidence

  1. Test whether controls are operating

  1. Identify gaps

  1. Create remediation plans

  1. Track the gaps until they're closed

Learn more

Top comments (0)