March 3, 2022, 7:51 p.m. | /u/EsqueletoBlanco

cybersecurity www.reddit.com

Currently in a GRC Analyst interview loop and I’m almost positive that the manager will ask me to explain my practical experience with one or more risk or other industry regulatory frameworks (CMMI, NIST CSF, NIST RMF, FAIR, ISO, COSO, COBIT, AICPA TSP/SOC, PCI, FedRAMP/NIST 800-53, etc).

In my current position, I’ve dealt with industry self-assessments that are based upon NIST CSF & NIST 800-53.

My understanding is that frameworks align your processes, policies and tools with the controls outlined …

cybersecurity experience frameworks regulatory risk

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Cybersecurity Triage Analyst

@ Peraton | Linthicum, MD, United States

Associate DevSecOps Engineer

@ LinQuest | Los Angeles, California, United States

DORA Compliance Program Manager

@ Resillion | Brussels, Belgium

Head of Workplace Risk and Compliance

@ Wise | London, United Kingdom