Related Posts
Any any insight on Greenberg Traurig?
More Posts
How is the work life balance in cognizant ?
It's my birthday. Can I leave at 5?
Ey work life balance
Additional Posts in Cyber Security Bowl
Anyone ever heard of or worked for Sygnia?
Any tips or tricks for CSX certification?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.




Mentor
Fun. Easy. Interesting. Currently, in data privacy, shifting towards privacy engineering.
Working on infrastructure and gearing up for assessments related to new data protection enforcements coming in March.
Mentor
https://www.insideprivacy.com/advertising-marketing/rules-on-targeted-advertising-what-do-the-digital-markets-act-and-digital-services-act-say/
A ton of risk assessments, designing/implementing/assessing controls, critical assets, developing/ maintaining governance documents etc. overall fun but can be hectic depending on where you work.
Community Builder
GRC can be technical as well. Just depends on the type of control and process frameworks used, service methodology and the company you work for. Just from experience GRC can require strong familiarity with NIST 800-53, NIST 800-171, HITRUST, CIS version 8 and ISO 27001.
Type of services range from control assessments, readiness assessments, process maturity assessments risk assessments and framework control audits. Each of these services offers a certain methodology and metrics to measure security governance.
Elements of Privacy acts/ laws and regulations can further be mapped to standard frameworks to conduct privacy assessments specific to laws such as GDPR and CCPA/CPRA.
Important work due to the fact that they police us. Keeping us inline. One job which will last for a while.
Just boring for me though. I prefer the technical side
It’s the least interesting part of what I do but it generates a backlog of work. I enjoy the remediation work more on the technical side.