Information Security

GRC

Builds enterprise resilience through frameworks, audits, and board-level risk communication. Creates CISOs who speak C-suite language and transform security from cost center to business enabler.

L1 – L9 · 9 tours Leads to: CISO → What's a Reference DRS?

The Career Arc

Rotational · L1–L3

Build the GRC craft. Prove you can wield the tools of Information Security.

  • L1 : Learn GRC fundamentals and support compliance
  • L2 : Execute GRC processes and maintain documentation
  • L3 : Own GRC domains and drive compliance

Transformational · L4–L7

Deliver GRC outcomes — each Information Security tour at this altitude has a defined mission and success criteria.

  • L4 : Lead GRC function and mentor team
  • L5 : Develop GRC strategy for domains
  • L6 : Own GRC strategy and compliance
  • L7 : Shape enterprise GRC vision and define risk management strategy

Manage a Team?

Great GRC managers are practitioners first. The Information Security IC responsibilities in L4–L7 are your foundation — your management responsibilities are additive:

  • • Hire security professionals who can communicate risk to non-technical leaders
  • • Build a culture where security is everyone's job—not just your team's
  • • Run 1:1s that develop both technical depth and executive presence
  • • Give feedback that balances paranoia with pragmatism—security enables, not blocks
  • • Remove blockers—fight for budget, tools, and a seat at leadership tables

Foundational · L8–L9

Shape the Information Security organization from the GRC chair — build institutions, not just products.

  • L8 : Scale GRC across organization
  • L9 : Define GRC strategy and risk posture
→ C-Suite: L10 is the CISO path — a distinct page, not duplicated here.

L1 — Associate GRC Analyst Rotational Full detail →

Mission

Learn GRC fundamentals and support compliance

This tour of duty

Complete your first compliance assessment

Own the outcomes

  • • Learn GRC fundamentals including frameworks, regulations, and controls
  • • Support compliance documentation and evidence collection
  • • Write basic policy documents with guidance
  • • Document control procedures and compliance status
  • • Support risk assessment activities
  • • Participate in audits to learn compliance processes

GRC at L1 — the competency bar

Information Security
2
Operational Excellence
2
Legal & Compliance
1

AI in this role

  • • Analyzing compliance data
  • • Drafting policy documents
  • • Generating risk summaries

L2 — Junior GRC Analyst Rotational Full detail →

Mission

Execute GRC processes and maintain documentation

This tour of duty

Own GRC processes and maintain compliance

Own the outcomes

  • • Execute GRC processes independently following procedures
  • • Conduct control assessments and document findings
  • • Write comprehensive policy and procedure documents
  • • Design simple compliance approaches for requirements
  • • Contribute to risk register maintenance
  • • Support audit preparation and evidence gathering

GRC at L2 — the competency bar

Information Security
2
Legal & Compliance
2
Operational Excellence
1
Finance
1
Human Resources
1

AI in this role

  • • Building compliance workflows
  • • Analyzing control effectiveness
  • • Creating audit documentation

L3 — Senior GRC Analyst Rotational Full detail →

Mission

Own GRC domains and drive compliance

This tour of duty

Lead GRC for domains

Own the outcomes

  • • Own GRC domains end-to-end including policies and compliance
  • • Design risk assessment approaches for organizational needs
  • • Lead compliance efforts for regulatory requirements
  • • Lead policy development for security domains
  • • Mentor junior analysts on GRC practices
  • • Drive compliance improvements that reduce risk

GRC at L3 — the competency bar

Information Security
3
Legal & Compliance
2
Operational Excellence
1
Finance
1
Human Resources
1

AI in this role

  • • Modeling risk scenarios
  • • Synthesizing assessment data
  • • Generating compliance reports

L4 — Staff GRC Analyst / Manager, Security Transformational Full detail →

Mission

Lead GRC function and mentor team

This tour of duty

Develop GRC approaches that improve compliance

Own the outcomes

  • • Lead GRC initiatives spanning multiple domains
  • • Design GRC programs that meet complex requirements
  • • Mentor analysts on risk thinking and compliance management
  • • Define GRC standards and assessment methodologies
  • • Drive cross-functional compliance coordination
  • • Own compliance posture for critical regulations

GRC at L4 — the competency bar

Information Security
3
Operational Excellence
2
Legal & Compliance
2
Finance
1
Human Resources
1

AI in this role

  • • Analyzing GRC patterns
  • • Building assessment playbooks
  • • Creating training content

L5 — Senior Staff GRC Analyst / Senior Manager, Security Transformational Full detail →

Mission

Develop GRC strategy for domains

This tour of duty

Drive GRC excellence and risk management

Own the outcomes

  • • Drive GRC strategy decisions organization-wide
  • • Design GRC programs that scale with organizational growth
  • • Define GRC standards and best practices
  • • Lead evaluation of GRC tools and frameworks
  • • Mentor senior analysts and shape GRC culture
  • • Solve the most complex compliance challenges

GRC at L5 — the competency bar

Information Security
4
Legal & Compliance
3
Operational Excellence
2
Finance
1
Human Resources
1

AI in this role

  • • Designing GRC strategies
  • • Modeling risk scenarios
  • • Generating strategic recommendations

L6 — Director, GRC Transformational Full detail →

Mission

Own GRC strategy and compliance

This tour of duty

Own GRC strategy and compliance posture

Own the outcomes

  • • Set direction for GRC across the company
  • • Define GRC strategy and multi-year roadmap
  • • Establish standards ensuring compliance excellence
  • • Drive alignment on GRC investments
  • • Represent GRC in executive and board discussions
  • • Shape the vision for GRC evolution

GRC at L6 — the competency bar

Information Security
4
Operational Excellence
3
Legal & Compliance
3
Strategy
2
Finance
1
Human Resources
1

AI in this role

  • • Analyzing strategic risks
  • • Building governance frameworks
  • • Creating executive content

L7 — Senior Director, GRC Transformational Full detail →

Mission

Shape enterprise GRC vision and define risk management strategy

This tour of duty

Build the team and systems that scale GRC

Own the outcomes

  • • Shape the company's GRC vision and strategy
  • • Define innovative approaches to risk management
  • • Establish principles guiding GRC decisions
  • • Influence industry GRC practices and standards
  • • Mentor directors and senior GRC leaders
  • • Drive GRC innovation

GRC at L7 — the competency bar

Information Security
2
Strategy
2
Legal & Compliance
2
Operational Excellence
1
Finance
1
Human Resources
1

AI in this role

  • • Designing team capabilities
  • • Building GRC systems
  • • Creating hiring frameworks

L8 — VP, GRC Foundational Full detail →

Mission

Scale GRC across organization

This tour of duty

Create the operating model that drives GRC excellence

Own the outcomes

  • • Build and lead GRC teams that ensure compliance
  • • Define organizational structure for GRC
  • • Establish hiring standards for GRC professionals
  • • Create the operating model for GRC excellence
  • • Partner with executives on risk management
  • • Develop GRC managers and leaders

GRC at L8 — the competency bar

Information Security
2
Operational Excellence
2
Strategy
1
Legal & Compliance
1

AI in this role

  • • Modeling GRC maturity
  • • Analyzing compliance patterns
  • • Generating operating models

L9 — SVP, GRC Foundational Full detail →

Mission

Define GRC strategy and risk posture

This tour of duty

Define the GRC strategy that manages risk

Own the outcomes

  • • Own GRC strategy and execution organization-wide
  • • Define multi-year roadmap for risk management
  • • Build culture that attracts top GRC talent
  • • Partner with executives and board on risk strategy
  • • Establish GRC as organizational strength
  • • Shape the future of GRC at the company

GRC at L9 — the competency bar

Operational Excellence
2
Information Security
1
Strategy
1
Legal & Compliance
1

AI in this role

  • • Building strategic planning systems
  • • Analyzing regulatory trends
  • • Creating GRC architectures

What Hiring Managers Look For

•

L1-L3: Demonstrate you can translate regulatory requirements into actionable technical controls and speak fluently to both auditors and engineers.

•

L4-L6: Show evidence of designing compliance programs that actually reduced business risk rather than just checking boxes, with metrics to prove it.

•

L7+: Board members evaluate whether you can articulate cyber risk in business terms and have a track record of preventing regulatory disasters that could sink the company.

Common Career Transitions

→

GRC → Product Security at L4-L5 for hands-on technical risk assessment

→

GRC → Security Architecture at L5-L6 to design preventive controls rather than detective ones

→

GRC → Privacy Engineering at L4-L6 leveraging regulatory expertise in emerging data protection landscape

Official Classifications

System Code Official Title
O*NET-SOC (US) 15-1212.00 Information Security Analysts
ISCO-08 (UN/ILO) 2529 Database and Network Professionals Not Elsewhere Classified

At L6 and above, the manager classification 1330 — Information and Communications Technology Service Managers applies IN ADDITION to the professional code — a manager is a superset of the individual contributor, never a replacement.

Measure yourself against this ladder — pin it to your Career Record.

Build Your Career Record