# Blank Résumé — GRC Analyst

> A markdown résumé scaffold matched to the four-section résumé anatomy on
> `/resume`. Fill the rows in, save as PDF, mirror the lines onto a Word
> version. Designed to fit one page once trimmed.

# First Last

📍 City, Region · ✉️ you@example.com · 📞 +1 555 010 0101 · 🔗 linkedin.com/in/your-handle

## Summary

Three lines, target title first. Name the frameworks you are conversant in
and one quantifiable win you can defend in the interview.

> GRC analyst with hands-on experience running SOC 2 readiness assessments,
> standing up enterprise risk registers, and preparing vendor security
> reviews against ISO 27001 and NIST CSF 2.0. Closed 23 risks and supported
> one clean SOC 2 Type II report over the past two cycles.

## Experience

### Company Name — Role Title
*Mon 2023 — Present*

- **Stood up the first enterprise risk register** for a 220-person SaaS,
  scoring 28 risks on a 5x5 grid with named owners; SOC 2 Type I readiness
  cited the register as the strongest Identify-function control.
- **Owned the SOC 2 evidence collection cycle** across all five Trust
  Services Criteria; produced one-page summaries per criterion so auditors
  walked the evidence without a live walkthrough.
- **Drove the vendor security review** for a new revenue-ops platform
  processing customer PII; approved with four contractual mitigations
  (data residency, 30-day breach notice, subprocess approval, audit-log
  access).

### Prior Company — Prior Role
*Mon 2020 — Mon 2023*

- One STAR bullet per major project. Lead with the number. Name the
  framework. End with the measurable result.
- One STAR bullet per audit, vendor review, policy, or runbook you
  authored.
- Older bullets go in three-line summary form. Anything older than ~7
  years can collapse to a single line.

## Skills

**Domain**: risk assessment, internal audit, vendor risk, policy drafting,
incident response, compliance program management

**Frameworks**: NIST CSF 2.0, NIST RMF, ISO 27001, SOC 2, PCI DSS, GDPR,
HIPAA, COBIT

**Tooling**: the SIEM, ticketing system, GRC platform, identity provider,
and ERP you have actually touched. Drop the soft ones ("communication,
teamwork"). Recruiters skim this column.

## Education

- Degree, Field — University, Year
- One line per degree. Add study-abroad, honors, or relevant coursework
  only if it earned a credential.

## Certifications

- Cert Name — Issuer, Year earned (Expiration year if it expires)
- List the cert, not the prep course. Date format consistent down the
  list. Drop certs that did not require a proctored exam.

## Notes for the reviewer

- One page. Two pages only if you have 10+ years of directly relevant
  experience.
- Bullets read cleanly as standalone lines. Each line should survive if
  the interviewer asks you to defend it cold.
- Quantify wherever the number is honest: percent, dollars, count of
  risks/audits/policies, days saved, controls remediated.
- Keep the framework names spelled out the first time you use each
  acronym on the page. SOC 2 first — `(SOC 2)` after that.
