Interview prep

Three categories of GRC interview questions — with sketches, not just prompts.

Walk sample technical, behavioral, and situational questions before your next interview. Each prompt comes with a short answer sketch you can adapt live — short on jargon, named after the frameworks the interviewer will likely cite. Free to access; pair with the résumé guide and the certification roadmap to walk in with a defensible answer to every common category.

What you will walk

23 sample questions across 3 categories.

Each prompt pairs with a short answer sketch — short on jargon, anchored to the framework the interviewer is most likely citing. Use the sketch as a starting vocabulary list, not a script; rehearse it in your own voice before the live interview.

Technical — risk, controls, audit walkthroughs

8 questions

Probes of the technical vocabulary a GRC analyst must hold cold: how risks are scored, what a control actually is, and what an auditor walks through on day one. Sketches name the framework the answer is anchored to so you can quote the standard if the interviewer pushes back.

  • Walk me through how you would score a single risk on a 5×5 likelihood × impact grid and end up with a defensible residual rating.

    Start with the inherent score: confirm the threat, the asset, and the existing controls with the owner, then place the risk on the 5×5 grid before any mitigations. Apply the named control set (matched to NIST CSF 2.0 Identify, ISO 27001 risk treatment, or COBIT governance language depending on the program) and re-rate — that is the residual. Document the inherent → residual delta with the control citation so the next reviewer can replay the trail.

  • What is the difference between a control and a framework, and where do they meet in the audit cycle?

    A framework is the catalog — NIST CSF 2.0 functions, ISO 27001 Annex A, or the SOC 2 Trust Services Criteria. A control is the operating mechanism — the policy, procedure, or technical safeguard that the framework demands. They meet in the controls matrix: each Annex A control or TSC point is mapped to a named owner, an evidence source, and a test cadence. The audit cycle walks that matrix end to end, not the framework narrative.

  • If I handed you a 90-person SaaS with no SOC 2 history, what would your first 30 days look like?

    Scope: which Trust Services Criteria the business actually needs — usually Security plus Availability if customers ask, with Confidentiality gated on the data classes in scope. Run a gap analysis against every selected TSC point, capture evidence owners, and stand up a weekly PBC cadence before the observation window starts. The deliverable audit committees expect is a controls matrix with named owners and a remediation roadmap, not a binder of policies no one has read.

    Framework anchors

  • How would you map an existing SOC 2 control library to ISO 27001:2022 Annex A without re-implementing everything?

    Decompose each Annex A control into the SOC 2 criteria and TSC points that already cover it; flag the 93 Annex A controls on a single spreadsheet; mark which are covered, partially covered, or net-new. The mapping becomes the Statement of Applicability, and the net-new lines become the implementation backlog. Most SOC 2 shops land on 70–80% Annex A coverage with no new work; the residual 20–30% is where the implementation project lives.

    Framework anchors

  • Name the seven NIST RMF steps in order and tell me which step most often fails in practice.

    Categorize, Select, Implement, Assess, Authorize, Monitor — and the preparation step at the front. The step that most often fails is Assess: teams skip the formal control assessment because they assume the implementer tested the control, and the Authorizing Official ends up signing a package without an independent test result. The remediation is a named control assessor role outside the implementer chain.

    Framework anchors

  • How do you decide what is in PCI DSS scope and what is out?

    Scope follows the cardholder data environment (CDE): any system that stores, processes, or transmits CHD, plus any system connected to it. Segmentation evidence is the live debate — network diagrams, segmentation test reports, and the compensating control worksheet are what the assessor will ask for. A defensible scope reduction needs a tested, documented segmentation, not just a hopeful firewall diagram.

    Framework anchors

  • When does a DPIA become mandatory under GDPR, and what five things must it contain?

    A DPIA is mandatory when processing is likely to result in a high risk to data subjects — large-scale special category data, systematic monitoring, new technologies with limited transparency, or data matching across sets. The Article 35 minimum is a description of processing, an assessment of necessity and proportionality, an assessment of risks to data subjects, the mitigations, and the DPO sign-off. The DPIA is what the regulator asks for first when an incident lands.

    Framework anchors

  • When does COBIT 2019 add value beyond ISO 27001 or NIST CSF on a governance committee?

    COBIT is the management-system overlay — it tells the committee how to govern, not what to secure. Use COBIT when the audience is the board and the question is who owns what, what the maturity targets are, and how the assurance case rolls up to enterprise risk. Use ISO 27001 when the audience is the ISMS auditor; use NIST CSF when the audience is the engineering team. Most mature programs run all three, mapped to each other.

Behavioral — STAR-format answers for compliance work

7 questions

STAR (situation, task, action, result) prompts the interviewer will use to test whether your résumé bullets are stories you can actually tell. Sketches are written to fit a two-minute spoken answer — situation in one sentence, action as the meat, result with a number the interviewer can write down.

  • Tell me about a time you disagreed with an engineering lead on the severity of a finding. What did you do?

    Situation: a SOC 2 readiness walkthrough surfaced a logging gap that engineering called "expected" and I called a Type II finding candidate. Task: reach a defensible severity rating without poisoning the relationship. Action: pulled the relevant TSC points, scheduled a 30-minute walk-through with engineering and the audit lead, and asked engineering to walk me through the compensating detection they had in mind. We landed on a lower severity, named compensating controls, and added a 60-day hardening sprint. Result: finding closed inside the observation window; engineering lead cited the same walkthrough as the template for the next three disagreements.

  • Describe a time you had to explain a technical control to a non-technical executive.

    Situation: the CFO asked why we were spending $180k on a SIEM upgrade when "we already have logs." Task: translate the gap into risk language the executive committee would act on. Action: built a one-page memo with one paragraph of business impact (audit finding risk, customer contract risk, breach exposure), one paragraph on what the spend bought, and one chart of the current vs target detection coverage. Result: budget approved in one cycle; the same memo template became the standard for the next four security asks at the committee.

  • Give me an example of a time you had to choose between two competing compliance deadlines. How did you decide?

    Situation: GDPR-ready-for-renewal and a SOC 2 Type II observation window landed within six weeks of each other; both had the same engineer footprint. Task: sequence the work without dropping either ball. Action: mapped each workstream to its critical path, identified the audit-blocking items on each, and negotiated with the SOC 2 audit lead for a two-week evidence-submission extension in exchange for a tighter Type II report. We ran GDPR on its original clock and absorbed the SOC 2 shift. Result: both reports issued with no findings; the same sequencing logic was used for the next two competing-deadline cycles.

    Framework anchors

  • Tell me about a compliance project that did not land. What would you do differently?

    Situation: I owned the rollout of a new vendor risk management program across 87 vendors; 12 months in, only 30% of vendors had completed the deep review. Task: name what failed and own it. Action: we had built the questionnaire and the dashboard, but we had not built the operational incentive — vendor procurement still signed contracts regardless of review status. The fix was a contractual gate tied to procurement, not a better dashboard. Result: the second iteration moved the 30% to 92% inside one quarter because we changed the system that bought the reviews, not the review itself.

  • How have you helped a less experienced analyst grow in GRC?

    Situation: a junior analyst joined our team from a non-security background — strong writer, no framework vocabulary. Task: ramp them to running their own vendor review inside 90 days. Action: paired them on my next two vendor reviews, gave them the questionnaire ownership on the second one, ran weekly framework-vocabulary sessions mapped to our actual catalog (NIST CSF 2.0 Identify and Protect, ISO 27001 Annex A 5 and 6), and reviewed their first solo memo with red-line commentary tied to our house style. Result: they owned three solo vendor reviews by week 10 and are now the lead on our small-vendor queue.

    Framework anchors

  • Tell me about a time you received critical feedback on a piece of compliance work.

    Situation: a peer reviewer flagged my first ISO 27001 control mapping as "accurate but unreadable by the auditor" — they were right; the Statement of Applicability read like an internal memo, not an audit artifact. Task: rewrite without losing the technical accuracy. Action: pulled two exemplar SOAs from peer-led ISO implementations, asked the audit lead to walk me through the one-paragraph format they wanted, and rewrote the entire mapping around that structure. Result: the next peer review passed in one round; the auditor used the mapping as evidence without reformatting.

    Framework anchors

  • Describe a time you worked through ambiguity in a regulation or standard.

    Situation: a new state privacy law required "reasonable" data-retention limits without defining the floor; we had a dozen systems storing customer data on timelines no one had reconciled. Task: produce a defensible retention policy the regulator would accept without forcing a multi-quarter data project. Action: researched peer-state guidance, sat with legal to define "reasonable" as the shortest interval tied to an active business purpose, then mapped every system to one of seven retention tiers with an exception register. Result: policy adopted in 32 days; the regulator accepted the policy without redefinition when they audited us 14 months later.

Situational — incident response, vendor risk, audit under pressure

8 questions

Hypotheticals the interviewer uses to test how you think under time pressure: a regulator just called, a vendor just disclosed a breach, an auditor flagged a finding 30 days before the report. Sketches walk the decision in the order you would make the call, with the framework the interviewer is most likely citing named in-line.

  • A vendor handling EU personal data just disclosed a breach to your security team. What do you do in the first 72 hours?

    First hour: confirm scope — what data classes, which data subjects, what jurisdictions. Convene the cross-functional bridge (security, legal, privacy, comms, the data owner) inside 30 minutes. Pull the DPA breach-notice clause to lock the notification clock; GDPR gives you 72 hours from awareness. Containment first: confirm the vendor has rotated credentials, isolated the affected systems, and preserved forensic evidence. Communication next: regulator draft holds for legal review, customer draft holds for the comms lead. Run the post-incident review after containment, not after notification — the lessons-learned clock waits for the irreducible response work to finish.

    Framework anchors

  • A board member asks how exposed we are to a single sub-processor failure. How do you answer?

    Pull the sub-processor inventory: every critical vendor, their critical sub-processors, and the data classes each one touches. Score concentration by data-class impact — a sub-processor holding cardholder data or EU personal data is a higher concentration risk than one holding operational telemetry. Pair the score with the contractual mitigation: does the DPA give us a right of audit, a sub-processor approval right, a 30-day breach window, and a documented exit plan? Answer the board member with the concentration matrix and the four contractual mitigations we already have or do not.

    Framework anchors

  • An auditor flags a critical finding 30 days before your SOC 2 Type II report. Walk me through the next two weeks.

    Day 1: read the finding, write your own one-paragraph summary, agree with the auditor that the summary is accurate. Day 2–3: identify the root cause, the owner, and the remediation path. Day 4–7: implement the remediation and capture before/after evidence. Day 8–10: write the management response — finding, root cause, remediation, owner, target date. Day 11–14: submit response, negotiate target date, and confirm the auditor will close the finding before report issuance. If they will not, document the compensating controls and disclose in the report — but ask first; do not concede compromise without a negotiation.

    Framework anchors

  • A policy you drafted is stuck in legal review for three months. The CISO wants it published this quarter. What do you do?

    Diagnose first: ask legal what specifically is unstuck (likely a clause that touches state privacy law or a cross-border data clause). Pull the specific clause, draft a redline that addresses the concern, and walk it through legal in a 30-minute working session, not another round of async review. If the concern is structural, narrow the policy scope to what legal has signed off and split the rest into a follow-on draft. The deliverable CISO needs is a published effective date with an exception register, not a perfect document that keeps editing itself.

  • A customer asks for HITRUST in a renewal cycle. Your team is SOC 2 and ISO 27001 only. How do you respond?

    First call: do not commit to HITRUST in the renewal cycle — the certification is multi-quarter and the audit window rarely compresses. Counter-propose HITRUST readiness (a scoped gap assessment, an evidence-mapping memo, and a roadmap to certification post-renewal) so the customer sees the plan, not a yes-then-no. Use the readiness engagement to map HITRUST controls into the SOC 2 + ISO 27001 evidence you already have so the eventual certification lands cheaper. Most of HITRUST maps cleanly across SOC 2 and ISO Annex A once you connect the crosswalks.

    Framework anchors

  • You discover a business unit is using an unsanctioned SaaS tool that holds customer PII. What do you do?

    Triage before blame: pull the data classes the tool actually holds, the user population, and the integration points. Convene the business unit lead, the security team, and legal in a single session — the goal is to decide if the tool stays sanctioned with mitigations or comes out. If it stays: write a conditional approval with contract changes (DPA, breach notice, sub-processor approval right, exit plan) and a 30-day shadow-IT scan to confirm there are no other tools in the same shape. If it comes out: write the migration plan with a named owner, a target date, and a customer notification if personal data actually moved. Either way, document the decision in the risk register so the next auditor can see the loop closed.

    Framework anchors

  • Your PCI DSS assessor flags cardholder data encrypted with an algorithm on the deprecation list. How do you handle it?

    Confirm the scope: which systems, which records, which algorithms. Pull the PCI DSS v4.0 deprecation timeline and map the affected systems against the key rotation roadmap. The remediation has three moves in parallel: rotate the affected keys to an approved algorithm, re-encrypt the stored data inside the rotation window, and decommission the legacy cipher stack at the encryption layer (not at the application layer) to keep the change auditable. Capture the migration evidence for the assessor in a single change ticket so the next review can replay the trail. If the assessor closes the finding inside the deprecation grace period, you walk away clean; if not, negotiate the compensating controls and document the gap.

    Framework anchors

  • You are running a CMMC Level 2 readiness assessment for a defense prime contractor. Where do you start?

    CUI scoping first: identify every system that stores, processes, or transmits Controlled Unclassified Information, plus every system connected to those. CMMC Level 2 maps directly to NIST 800-171 — start there before you read CMMC language; the controls are the same 110 controls with CMMC's assessment language wrapped around them. Score each control family on the same maturity scale you would for a NIST CSF 2.0 assessment, prioritize the families the prime customer is most likely to probe (Access Control, Identification and Authentication, Audit and Accountability), and produce a remediation roadmap the engineering team can staff against inside the procurement window.

    Framework anchors

Pair this with the resume guide and certification roadmap

The answer sketch and the resume bullet are the same story.
The STAR bullets on your resume and the interview sketches you walk here sit on the same shelf. Tighten the bullet on paper; rehearse the sketch out loud. Then check the certification roadmap so the credential line on the resume matches the framework vocabulary the sketch quotes.