From SOC analyst to GRC analyst
Yes, SOC to GRC is a well worn move, and your queue history is the best part of your application. You have watched controls fail in production: the MFA exception nobody reviewed, the log source that went quiet for a week. GRC analysts spend their days asking whether those controls work, and you already know where they break.
What you are missing is usually the vocabulary and the paperwork: mapping a control to NIST CSF, ISO 27001 or SOC 2, running a risk assessment, and collecting evidence an auditor will accept. Those can be learned on the job you have now, before you apply.
Talk to Carmen
Your AI career coach
Say it the way you’d say it to a friend. Carmen will ask what she needs to know.
$129,180 a year
Median pay for information security analysts, May 2025 (BLS counts SOC and GRC analysts in this one occupation)
BLS Occupational Outlook Handbook$125,420
Median for information security analysts in management, scientific, and technical consulting services, where many GRC and audit advisory roles sit, May 2025
BLS Occupational Outlook Handbook3 years of IS audit, control or security work, across at least two of its four domains, within the prior 10 years
CRISC experience needed before certification
ISACA5 years of IS audit, control or security experience within the prior 10 years
CISA experience needed before certification
ISACAWhat already carries over
Seeing how controls fail
Every alert you closed tested a control. In GRC that becomes control testing: you can tell an auditor that the EDR policy exists on paper and also say which hosts it missed last quarter.
Incident write-ups
A clean ticket with a timeline, root cause and fix is the raw material for a risk register entry and a corrective action plan. GRC teams hire for that kind of writing.
Knowing where the logs live
Auditors ask for evidence that logging, access reviews and alerting actually ran. You already know which SIEM query or console screenshot proves it, which saves a GRC team days of back and forth.
Working with IT owners under pressure
You have chased sysadmins to isolate a host at 2 a.m. Chasing a control owner for quarterly access review evidence is the same conversation with a longer deadline.
Threat context
When a risk assessment asks how likely a threat is, you can point to what your SOC actually sees, such as phishing volume or credential stuffing attempts, instead of guessing.
What to build
Framework fluency
Read the NIST CSF 2.0 document (free from NIST) and learn its six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Then map five controls your SOC touches to the CSF subcategories they support. If your company has a SOC 2 report or ISO 27001 certificate, ask to read the control list.
Risk assessment method
Take a short course on risk assessment, then write one assessment for a real risk you have seen in the queue: the asset, the threat, the likelihood and impact, the current controls and what you would recommend.
Audit evidence and control testing
Offer to help your GRC or compliance team gather evidence for the next audit. Pull the SIEM, EDR or access review artifacts yourself and write down what made each one acceptable or not.
Policy writing
Draft or update one policy or standard your SOC depends on, such as logging and monitoring or incident response, and ask the policy owner for a review.
A GRC credential for later
Most entry GRC postings ask for framework knowledge first. CRISC and CISA both have experience requirements set by ISACA (three and five years), so check whether your SOC work counts toward them before you book an exam.
Your first 90 days
A starting plan. Carmen adjusts it to your hours, your savings and where you live.
- 1
Days 1 to 30
- Read NIST CSF 2.0 end to end and note which Functions your SOC work already covers, mostly Detect and Respond.
- Ask your GRC or compliance lead for 30 minutes to learn which frameworks your company reports against (SOC 2, ISO 27001, others) and when the next audit is.
- Pick five controls you see every day, such as MFA, EDR coverage and log retention, and write one paragraph each on how you would prove they work.
- 2
Days 31 to 60
- Volunteer to gather evidence for one control area in the next audit or internal review.
- Write a full risk assessment for one risk from your queue and ask a GRC colleague to critique it.
- Collect 10 GRC analyst postings and list the frameworks, tools and certifications they name, so you know what the market near you asks for.
- 3
Days 61 to 90
- Rewrite your résumé so each SOC bullet reads as control, risk or evidence work, using the examples below.
- Apply internally first if your company has a GRC team, then to the external postings that match your framework list.
- Practice explaining a control failure you found in the SOC as a risk to a non-technical manager, out loud, until it takes under two minutes.
Your résumé, rewritten for grc analyst roles
Fill the blanks with your real numbers. Anything you cannot back up, leave out.
Before
Triaged ___ alerts per shift in Splunk and escalated true positives to L2.
After
Monitored detective controls across ___ log sources in Splunk and documented ___ control gaps with evidence for remediation owners.
Before
Investigated phishing incidents and reset compromised accounts.
After
Tested the effectiveness of email and identity controls through ___ phishing investigations and wrote root cause findings that fed the risk register.
Before
Wrote incident reports for confirmed security events.
After
Produced incident reports with timelines, root cause and corrective actions, used as audit evidence for the incident response control.
Sample conversation
Planning the move with Carmen
Carmen asks before she suggests. An illustrative example, not a real person.
I've done two years of L1 and L2. I want GRC but every posting asks for audit experience.
Your incident reports and escalation tickets are audit evidence already. Does your company go through SOC 2 or ISO 27001?
SOC 2, every year. I've never been involved.
Then that audit is your way in. Want to write a short note to the compliance lead offering to pull the logging and incident evidence this cycle?
Map your own move to grc analyst
Carmen’s team maps what carries over from your actual work, then drafts the story of your switch.
Questions & answers
- How long does it take to go from SOC analyst to GRC analyst?
- It depends on whether your company has a GRC team you can help, how soon its next audit is, and how much framework reading you have done. An internal move after helping with an audit cycle is often quicker than applying cold, but there is no standard timeline.
- Do I need a certification to get a GRC analyst job?
- Not always for entry roles. Check 10 local postings. CRISC requires three years and CISA five years of relevant experience, per ISACA, so many people start GRC work first and certify once their experience qualifies.
- Which framework should a SOC analyst learn first for GRC?
- The one your company or target employers report against. NIST CSF 2.0 is free and a good general map. SOC 2 is common at US software companies that sell to other businesses, and ISO 27001 is common where customers ask for a certified information security management system.
- Will I lose technical skills if I move from SOC to GRC?
- You will use them differently. You will spend less time in the SIEM and more time asking whether controls work. Many GRC analysts keep their edge by owning technical control testing, where SOC experience stands out.
Other moves for security analysts
Sources
- BLS Occupational Outlook Handbook: Information Security Analysts
- ISACA: Get CRISC certified
- ISACA: Get CISA certified
- NIST: Cybersecurity Framework (CSF 2.0)
- NIST CSWP 29: The NIST Cybersecurity Framework (CSF) 2.0, February 26, 2024
- AICPA & CIMA: SOC 2 examinations
- ISO: ISO/IEC 27001 Information security management systems
Last checked September 29, 2026.