The four buckets of work
Every GRC role is a blend of four workstreams. The blend changes by company and by seniority, but if you have seen all four, you have seen the job.
1. Compliance and audit
The business gets asked, are we compliant with HIPAA, with SOC 2, with this customer's requirements? Your job is to find out and prove it. That means running control assessments, gathering evidence, interviewing the people who actually do the work, and writing reports that leadership can act on.
A real audit has a rhythm: prepare the control list, schedule the interviews, review documents in advance, go ask the questions, then reconcile what you heard against what you saw. The skill is in the asking. You do not read a control aloud and wait. You ask the engineer to show you the last four new hires and how their access was granted, and let the evidence talk.
2. Risk assessment
Some days you are scoring risks: how likely is this threat, how bad would the impact be, what is the risk value, and what should we do about it. You sit with the business and ask what happens if the system goes down for a week, and you turn answers into numbers that a CFO can weigh against the cost of a control.
The output is a prioritized list. The most valuable thing you bring is not the spreadsheet, it is the defensible reasoning behind every number, so the business can make an informed call.
3. Governance and policy
Policy work is writing the rules and keeping them alive. That means drafting an acceptable use policy, defining standards (passwords expire every 90 days, MFA on all remote access), and documenting procedures so work happens the same way every time.
The discipline is in the details: a policy needs a purpose, a scope, enforceable statements, a management signature, and a review schedule. A policy nobody signed and nobody reviews is a document, not governance.
4. Security awareness
Someone has to train the humans. That is awareness work: phishing simulations, training for new hires, targeted messages for executives who get targeted by business email compromise, and reminders that are short enough to actually read.
The craft is knowing your audience. Finance gets a different message than engineers. A personal hook, protect your own bank account, lands better than protect the company, and takes ten seconds to deliver.
What the week actually looks like
A realistic week mixes all of it. Monday you are gathering evidence for an audit. Tuesday you run a risk scoring session with IT. Wednesday you draft a policy update and get feedback from legal. Thursday you review a vendor's SOC 2 report and answer a customer questionnaire. Friday you write the summary for leadership and start planning next week's controls testing.
It is analytical, it is communicative, and it is more varied than people expect. If you like understanding how businesses work and explaining complex things simply, the day to day will feel familiar quickly.
Next: Lesson 4 takes the concept of risk and explains it with one concrete example you will never forget.