Resume guide
A four-section resume that reads like a GRC analyst.
Header, summary, experience, skills — in that order, on one page. Everything below is structured to drop into Word, Google Docs, or a markdown editor with the line breaks intact. Free to access; pick a section, copy the bullet, paste it in.
Name, email, phone, city. LinkedIn optional. Drop the street address — recruiters will not mail you a calendar invite.
Three lines tied to the role: target title, the frameworks or regs you are conversant in, and one quantification you can defend in the interview (years, audits passed, risks closed).
Bullets in STAR shape — situation, task, action, result — with the number up front. One bullet per lab, role, or audit. Group by job, newest first.
Two columns: domain (risk, audit, vendor, policy, incident) and tooling (the SIEMs, ticketing systems, ERPs, GRC platforms you have actually used). Skip the soft ones.
Skills to spotlight
Three skills every GRC analyst résumé should foreground.
Each card maps to the framework coverage already in your library. Cross-link directly into the course page to refresh the language before the interview.
Identified, scored, and treated enterprise risks on a 5×5 grid; produced registers auditors could trace from inherent to residual.
Coverage
Bullet library
12 STAR-format bullets, six GRC families.
Situation, task, action, result — written to fit on one line of an experience block. Copy a bullet with one click and paste it straight into your résumé.
Risk register
Bullets that name the asset, the threat, and the score — register rows you can defend if the interviewer asks "how did you score that."
- Stood up the first enterprise risk register
- Situation
- A 220-person SaaS had no documented risk register; auditors were flagging it as a material weakness on every SOC 2 walkthrough.
- Task
- Build a defensible register in 60 days that product, security, and finance would all agree on.
- Action
- Ran a half-day risk workshop with each function head, drafted 28 risk statements on a 5×5 likelihood × impact grid, paired each with a named owner and a control reference, and circulated the draft for sign-off.
- Result
- 28 risks logged within 60 days, 100% owner-assigned; the SOC 2 Type I readiness walkthrough cited the register as the strongest control in the Identify function.
Clipboard is not available in this browser. Select and copy from the block below.
• Stood up the first enterprise risk register Situation: A 220-person SaaS had no documented risk register; auditors were flagging it as a material weakness on every SOC 2 walkthrough. Task: Build a defensible register in 60 days that product, security, and finance would all agree on. Action: Ran a half-day risk workshop with each function head, drafted 28 risk statements on a 5×5 likelihood × impact grid, paired each with a named owner and a control reference, and circulated the draft for sign-off. Result: 28 risks logged within 60 days, 100% owner-assigned; the SOC 2 Type I readiness walkthrough cited the register as the strongest control in the Identify function.
- Re-rated residual risk after a control change
- Situation
- Engineering rolled out MFA to all admin accounts and asked the GRC team to reflect the change in the register before the next quarterly review.
- Task
- Update the affected risks, defend the new residual score, and document the reasoning the audit committee would understand.
- Action
- Pulled the four risks that referenced compromised-admin scenarios, walked each through the 5×5 scoring rubric with security and the control owner, and documented the inherent → residual delta with the MFA control citation.
- Result
- Four risks re-rated, residual likelihood dropping by one full step on three of them; quarterly review adopted the new scoring in under a week.
Clipboard is not available in this browser. Select and copy from the block below.
• Re-rated residual risk after a control change Situation: Engineering rolled out MFA to all admin accounts and asked the GRC team to reflect the change in the register before the next quarterly review. Task: Update the affected risks, defend the new residual score, and document the reasoning the audit committee would understand. Action: Pulled the four risks that referenced compromised-admin scenarios, walked each through the 5×5 scoring rubric with security and the control owner, and documented the inherent → residual delta with the MFA control citation. Result: Four risks re-rated, residual likelihood dropping by one full step on three of them; quarterly review adopted the new scoring in under a week.
Framework implementation
Bullets that show you can land a framework, not just talk about one — gap analysis, control mapping, and a roadmap the engineering team can execute.
- Drove a NIST CSF 2.0 readiness assessment
- Situation
- A Series-B fintech was preparing for its first enterprise customer audits and needed a credible posture against the six NIST CSF 2.0 functions.
- Task
- Run a 90-day readiness assessment, score each subcategory, and produce a roadmap that engineering could staff against.
- Action
- Interviewed control owners across product, infrastructure, and security; scored all 106 subcategories on the four-tier maturity scale; mapped gaps to NIST 800-53 control families; sequenced fixes into three sprints ordered by audit impact.
- Result
- Subcategory maturity rose from 1.8 to 3.1 average across the Govern and Identify functions; roadmap still driving the engineering backlog two quarters later.
Clipboard is not available in this browser. Select and copy from the block below.
• Drove a NIST CSF 2.0 readiness assessment Situation: A Series-B fintech was preparing for its first enterprise customer audits and needed a credible posture against the six NIST CSF 2.0 functions. Task: Run a 90-day readiness assessment, score each subcategory, and produce a roadmap that engineering could staff against. Action: Interviewed control owners across product, infrastructure, and security; scored all 106 subcategories on the four-tier maturity scale; mapped gaps to NIST 800-53 control families; sequenced fixes into three sprints ordered by audit impact. Result: Subcategory maturity rose from 1.8 to 3.1 average across the Govern and Identify functions; roadmap still driving the engineering backlog two quarters later.
- Built the ISO 27001 Annex A control mapping
- Situation
- A managed-services client needed to map existing SOC 2 controls to ISO 27001:2022 Annex A before a European customer required certification.
- Task
- Produce a defensible mapping that the ISO lead auditor could walk without a translator.
- Action
- Decomposed each Annex A control into applicable SOC 2 criteria and TSC points; onboarded the 93 Annex A controls into the GRC platform; flagged 17 controls that needed net-new implementation evidence.
- Result
- Mapping reviewed by external ISO lead auditor without findings; client hit Statement of Applicability review on the first pass.
Clipboard is not available in this browser. Select and copy from the block below.
• Built the ISO 27001 Annex A control mapping Situation: A managed-services client needed to map existing SOC 2 controls to ISO 27001:2022 Annex A before a European customer required certification. Task: Produce a defensible mapping that the ISO lead auditor could walk without a translator. Action: Decomposed each Annex A control into applicable SOC 2 criteria and TSC points; onboarded the 93 Annex A controls into the GRC platform; flagged 17 controls that needed net-new implementation evidence. Result: Mapping reviewed by external ISO lead auditor without findings; client hit Statement of Applicability review on the first pass.
Audit support
Bullets that read like PBC lists and finding memoranda — what you gathered, what you wrote, and what the auditor said back.
- Owned the SOC 2 evidence collection cycle
- Situation
- A 90-person SaaS passed its SOC 2 Type I but was six weeks from the Type II observation window with no evidence owner named.
- Task
- Stand up a weekly PBC cadence that produced auditor-ready evidence on every common criterion.
- Action
- Built a single evidence tracker across all five trust services criteria; partnered with IT, HR, and engineering to schedule weekly evidence pulls; wrote one-page summaries per criterion so the auditor could read without a walkthrough.
- Result
- Type II report issued with zero exceptions; auditor flagged the evidence tracker as the cleanest they had reviewed that quarter.
Clipboard is not available in this browser. Select and copy from the block below.
• Owned the SOC 2 evidence collection cycle Situation: A 90-person SaaS passed its SOC 2 Type I but was six weeks from the Type II observation window with no evidence owner named. Task: Stand up a weekly PBC cadence that produced auditor-ready evidence on every common criterion. Action: Built a single evidence tracker across all five trust services criteria; partnered with IT, HR, and engineering to schedule weekly evidence pulls; wrote one-page summaries per criterion so the auditor could read without a walkthrough. Result: Type II report issued with zero exceptions; auditor flagged the evidence tracker as the cleanest they had reviewed that quarter.
- Drafted the management response to an audit finding
- Situation
- An internal audit identified a recurring access-review finding across three business units, with a 90-day remediation window.
- Task
- Write a management response that named an owner, a remediation plan, and a measurable target date.
- Action
- Convened the three business-unit leads, decomposed the finding into four root causes, negotiated the corrective actions and target dates, and circulated the response to the audit committee.
- Result
- Finding closed within the 90-day window; same template adopted as the standard format for the next four quarterly findings.
Clipboard is not available in this browser. Select and copy from the block below.
• Drafted the management response to an audit finding Situation: An internal audit identified a recurring access-review finding across three business units, with a 90-day remediation window. Task: Write a management response that named an owner, a remediation plan, and a measurable target date. Action: Convened the three business-unit leads, decomposed the finding into four root causes, negotiated the corrective actions and target dates, and circulated the response to the audit committee. Result: Finding closed within the 90-day window; same template adopted as the standard format for the next four quarterly findings.
Vendor & third-party reviews
Bullets that show the diligence thinking — what you asked for, what you read, what you decided, and what you wrote into the contract.
- Ran the security review on a critical SaaS vendor
- Situation
- A new revenue-ops platform was being onboarded to process customer PII; standard procurement only covered pricing and SLAs.
- Task
- Complete a security review that mapped to the company SOC 2 and EU GDPR posture before the contract was signed.
- Action
- Sent a 96-question vendor questionnaire, reviewed the vendor SOC 2 Type II report against our Trust Services Criteria, walked the sub-processor list against our DPA, and wrote a go/no-go memo with mitigations.
- Result
- Approved with four contractual mitigations (data-residency clause, 30-day breach notice, subprocess approval right, audit-log access); contract signed inside the original procurement window.
Clipboard is not available in this browser. Select and copy from the block below.
• Ran the security review on a critical SaaS vendor Situation: A new revenue-ops platform was being onboarded to process customer PII; standard procurement only covered pricing and SLAs. Task: Complete a security review that mapped to the company SOC 2 and EU GDPR posture before the contract was signed. Action: Sent a 96-question vendor questionnaire, reviewed the vendor SOC 2 Type II report against our Trust Services Criteria, walked the sub-processor list against our DPA, and wrote a go/no-go memo with mitigations. Result: Approved with four contractual mitigations (data-residency clause, 30-day breach notice, subprocess approval right, audit-log access); contract signed inside the original procurement window.
- Built the recurring vendor risk review cadence
- Situation
- A scale-up had 87 active vendors and a one-off risk assessment process nobody owned; the board flagged third-party concentration risk.
- Task
- Stand up a reoccurring review cadence that re-rated vendor criticality and refreshed evidence on the right cadence.
- Action
- Tiered vendors into critical (annual deep review), moderate (annual questionnaire), and low (biennial); assigned a single accountable analyst per critical vendor; instrumented a recurring calendar invitation and a dashboard.
- Result
- All 87 vendors moved onto a tiered review schedule within one quarter; the board received the first quarterly concentration report that same cycle.
Clipboard is not available in this browser. Select and copy from the block below.
• Built the recurring vendor risk review cadence Situation: A scale-up had 87 active vendors and a one-off risk assessment process nobody owned; the board flagged third-party concentration risk. Task: Stand up a reoccurring review cadence that re-rated vendor criticality and refreshed evidence on the right cadence. Action: Tiered vendors into critical (annual deep review), moderate (annual questionnaire), and low (biennial); assigned a single accountable analyst per critical vendor; instrumented a recurring calendar invitation and a dashboard. Result: All 87 vendors moved onto a tiered review schedule within one quarter; the board received the first quarterly concentration report that same cycle.
Policy drafting
Bullets that show you can write a policy people actually follow — version control, stakeholder review, and a published effective date.
- Rewrote the information security policy suite
- Situation
- A mid-market company had 14 security policies written between 2018 and 2022 in three different formats; employees could not find the authoritative version.
- Task
- Consolidate into a single suite aligned to ISO 27001 and NIST CSF 2.0, with owners, version history, and review cadences published.
- Action
- Mapped existing policies to ISO 27001 Annex A and NIST CSF 2.0 subcategories; drafted six umbrella policies and 14 supporting standards; ran a two-week stakeholder review with legal, HR, IT, and the executive team.
- Result
- Policy suite published on a single internal portal; ISO lead auditor used the mapping as evidence that Annex A 5.1 and 5.2 were operating effectively.
Clipboard is not available in this browser. Select and copy from the block below.
• Rewrote the information security policy suite Situation: A mid-market company had 14 security policies written between 2018 and 2022 in three different formats; employees could not find the authoritative version. Task: Consolidate into a single suite aligned to ISO 27001 and NIST CSF 2.0, with owners, version history, and review cadences published. Action: Mapped existing policies to ISO 27001 Annex A and NIST CSF 2.0 subcategories; drafted six umbrella policies and 14 supporting standards; ran a two-week stakeholder review with legal, HR, IT, and the executive team. Result: Policy suite published on a single internal portal; ISO lead auditor used the mapping as evidence that Annex A 5.1 and 5.2 were operating effectively.
- Drafted the acceptable-use policy that survived legal review
- Situation
- A new state privacy law required an updated acceptable-use policy that HR could hand to every new hire on day one.
- Task
- Draft a policy readable at a high-school level, defensible against the new statute, and durable across the next two compliance cycles.
- Action
- Read the statute, mapped each obligation to a clause in the policy, partnered with employment counsel on California- and New York-specific carve-outs, and ran a comprehension pass with three non-security hires.
- Result
- Policy adopted in 32 days; legal sign-off in one round; new-hire onboarding completion rate measured at 99% in the first quarter.
Clipboard is not available in this browser. Select and copy from the block below.
• Drafted the acceptable-use policy that survived legal review Situation: A new state privacy law required an updated acceptable-use policy that HR could hand to every new hire on day one. Task: Draft a policy readable at a high-school level, defensible against the new statute, and durable across the next two compliance cycles. Action: Read the statute, mapped each obligation to a clause in the policy, partnered with employment counsel on California- and New York-specific carve-outs, and ran a comprehension pass with three non-security hires. Result: Policy adopted in 32 days; legal sign-off in one round; new-hire onboarding completion rate measured at 99% in the first quarter.
Incident response
Bullets that show you have run the clock — triage, communication, lessons-learned, and the control change that made the next incident cheaper.
- Coordinated the cross-functional response to a credential-stuffing event
- Situation
- A 1.4M-customer retail platform detected credential-stuffing traffic across 38k accounts during a peak sales window.
- Task
- Coordinate detection, containment, eradication, and customer notification inside the company 72-hour breach clock.
- Action
- Stood up the incident bridge with security, fraud, customer support, legal, and comms in under 30 minutes; froze the affected API routes; rotated the targeted passwords; prepared regulator and customer notification drafts and held them for legal sign-off.
- Result
- Containment in 4 hours, full eradication in 18 hours, regulator notification within the 72-hour window; post-incident review produced three new detections and one MFA control change.
Clipboard is not available in this browser. Select and copy from the block below.
• Coordinated the cross-functional response to a credential-stuffing event Situation: A 1.4M-customer retail platform detected credential-stuffing traffic across 38k accounts during a peak sales window. Task: Coordinate detection, containment, eradication, and customer notification inside the company 72-hour breach clock. Action: Stood up the incident bridge with security, fraud, customer support, legal, and comms in under 30 minutes; froze the affected API routes; rotated the targeted passwords; prepared regulator and customer notification drafts and held them for legal sign-off. Result: Containment in 4 hours, full eradication in 18 hours, regulator notification within the 72-hour window; post-incident review produced three new detections and one MFA control change.
- Wrote the runbook that cut the next incident in half
- Situation
- After the credential-stuffing incident, leadership wanted a runbook so the next on-call analyst did not have to reinvent the response.
- Task
- Produce a runbook that an on-call analyst could follow end to end at 2 a.m. without paging the CISO.
- Action
- Documented the full triage → containment → eradication → recovery path with decision trees, named owners, communication templates, and the explicit criteria for escalating to a declared incident; ran a tabletop with two analysts to stress-test it.
- Result
- Tabletop completion time dropped from 73 minutes to 34 minutes against the same scenario; the runbook became the standard template for the four subsequent incident-class documents.
Clipboard is not available in this browser. Select and copy from the block below.
• Wrote the runbook that cut the next incident in half Situation: After the credential-stuffing incident, leadership wanted a runbook so the next on-call analyst did not have to reinvent the response. Task: Produce a runbook that an on-call analyst could follow end to end at 2 a.m. without paging the CISO. Action: Documented the full triage → containment → eradication → recovery path with decision trees, named owners, communication templates, and the explicit criteria for escalating to a declared incident; ran a tabletop with two analysts to stress-test it. Result: Tabletop completion time dropped from 73 minutes to 34 minutes against the same scenario; the runbook became the standard template for the four subsequent incident-class documents.
Pair this with the certification roadmap
Read the roadmap before you lock the certification line on your résumé — the tier and issuer labels on each card map directly into how a recruiter reads a GRC résumé.
Blank résumé template
The four-section structure matched to the anatomy above. Header → Summary → Experience → Skills, plus Education and Certifications. Beyond blank rows, the template notes what each section is for and what a strong entry looks like.
Markdown renders in Notion, Confluence, GitHub, Obsidian, and most static-site generators. Convert to PDF with your editor of choice once the rows are filled in.