Information Security

GRC

Builds enterprise resilience through frameworks, audits, and board-level risk communication. Creates CISOs who speak C-suite language and transform security from cost center to business enabler.

L1 – L9 · 9 tours Leads to: CISO → What's a Reference DRS?

The Career Arc

Rotational · L1–L3

Build the GRC craft. Prove you can wield the tools of Information Security.

  • L1 : Learn GRC fundamentals and support compliance
  • L2 : Execute GRC processes and maintain documentation
  • L3 : Own GRC domains and drive compliance

Transformational · L4–L7

Deliver GRC outcomes — each Information Security tour at this altitude has a defined mission and success criteria.

  • L4 : Lead GRC function and mentor team
  • L5 : Develop GRC strategy for domains
  • L6 : Own GRC strategy and compliance
  • L7 : Shape enterprise GRC vision and define risk management strategy

Manage a Team?

Great GRC managers are practitioners first. The Information Security IC responsibilities in L4–L7 are your foundation — your management responsibilities are additive:

  • Hire security professionals who can communicate risk to non-technical leaders
  • Build a culture where security is everyone's job—not just your team's
  • Run 1:1s that develop both technical depth and executive presence
  • Give feedback that balances paranoia with pragmatism—security enables, not blocks
  • Remove blockers—fight for budget, tools, and a seat at leadership tables

Foundational · L8–L9

Shape the Information Security organization from the GRC chair — build institutions, not just products.

  • L8 : Scale GRC across organization
  • L9 : Define GRC strategy and risk posture
→ C-Suite: L10 is the CISO path — a distinct page, not duplicated here.

L1 — Associate GRC Analyst Rotational

Mission

Learn GRC fundamentals and support compliance

This tour of duty

Complete your first compliance assessment

Own the outcomes

  • Learn GRC fundamentals including frameworks, regulations, and controls
  • Support compliance documentation and evidence collection
  • Write basic policy documents with guidance
  • Document control procedures and compliance status
  • Support risk assessment activities
  • Participate in audits to learn compliance processes

GRC at L1 — the competency bar

Information Security
2
Operational Excellence
2
Legal & Compliance
1

AI in this role

  • Analyzing compliance data
  • Drafting policy documents
  • Generating risk summaries

L2 — Junior GRC Analyst Rotational

Mission

Execute GRC processes and maintain documentation

This tour of duty

Own GRC processes and maintain compliance

Own the outcomes

  • Execute GRC processes independently following procedures
  • Conduct control assessments and document findings
  • Write comprehensive policy and procedure documents
  • Design simple compliance approaches for requirements
  • Contribute to risk register maintenance
  • Support audit preparation and evidence gathering

GRC at L2 — the competency bar

Information Security
2
Legal & Compliance
2
Operational Excellence
1
Finance
1
Human Resources
1

AI in this role

  • Building compliance workflows
  • Analyzing control effectiveness
  • Creating audit documentation

L3 — Senior GRC Analyst Rotational

Mission

Own GRC domains and drive compliance

This tour of duty

Lead GRC for domains

Own the outcomes

  • Own GRC domains end-to-end including policies and compliance
  • Design risk assessment approaches for organizational needs
  • Lead compliance efforts for regulatory requirements
  • Lead policy development for security domains
  • Mentor junior analysts on GRC practices
  • Drive compliance improvements that reduce risk

GRC at L3 — the competency bar

Information Security
3
Legal & Compliance
2
Operational Excellence
1
Finance
1
Human Resources
1

AI in this role

  • Modeling risk scenarios
  • Synthesizing assessment data
  • Generating compliance reports

L4 — Staff GRC Analyst / Manager, Security Transformational

Mission

Lead GRC function and mentor team

This tour of duty

Develop GRC approaches that improve compliance

Own the outcomes

  • Lead GRC initiatives spanning multiple domains
  • Design GRC programs that meet complex requirements
  • Mentor analysts on risk thinking and compliance management
  • Define GRC standards and assessment methodologies
  • Drive cross-functional compliance coordination
  • Own compliance posture for critical regulations

GRC at L4 — the competency bar

Information Security
3
Operational Excellence
2
Legal & Compliance
2
Finance
1
Human Resources
1

AI in this role

  • Analyzing GRC patterns
  • Building assessment playbooks
  • Creating training content

L5 — Senior Staff GRC Analyst / Senior Manager, Security Transformational

Mission

Develop GRC strategy for domains

This tour of duty

Drive GRC excellence and risk management

Own the outcomes

  • Drive GRC strategy decisions organization-wide
  • Design GRC programs that scale with organizational growth
  • Define GRC standards and best practices
  • Lead evaluation of GRC tools and frameworks
  • Mentor senior analysts and shape GRC culture
  • Solve the most complex compliance challenges

GRC at L5 — the competency bar

Information Security
4
Legal & Compliance
3
Operational Excellence
2
Finance
1
Human Resources
1

AI in this role

  • Designing GRC strategies
  • Modeling risk scenarios
  • Generating strategic recommendations

L6 — Director, GRC Transformational

Mission

Own GRC strategy and compliance

This tour of duty

Own GRC strategy and compliance posture

Own the outcomes

  • Set direction for GRC across the company
  • Define GRC strategy and multi-year roadmap
  • Establish standards ensuring compliance excellence
  • Drive alignment on GRC investments
  • Represent GRC in executive and board discussions
  • Shape the vision for GRC evolution

GRC at L6 — the competency bar

Information Security
4
Operational Excellence
3
Legal & Compliance
3
Strategy
2
Finance
1
Human Resources
1

AI in this role

  • Analyzing strategic risks
  • Building governance frameworks
  • Creating executive content

L7 — Senior Director, GRC Transformational

Mission

Shape enterprise GRC vision and define risk management strategy

This tour of duty

Build the team and systems that scale GRC

Own the outcomes

  • Shape the company's GRC vision and strategy
  • Define innovative approaches to risk management
  • Establish principles guiding GRC decisions
  • Influence industry GRC practices and standards
  • Mentor directors and senior GRC leaders
  • Drive GRC innovation

GRC at L7 — the competency bar

Information Security
2
Strategy
2
Legal & Compliance
2
Operational Excellence
1
Finance
1
Human Resources
1

AI in this role

  • Designing team capabilities
  • Building GRC systems
  • Creating hiring frameworks

L8 — VP, GRC Foundational

Mission

Scale GRC across organization

This tour of duty

Create the operating model that drives GRC excellence

Own the outcomes

  • Build and lead GRC teams that ensure compliance
  • Define organizational structure for GRC
  • Establish hiring standards for GRC professionals
  • Create the operating model for GRC excellence
  • Partner with executives on risk management
  • Develop GRC managers and leaders

GRC at L8 — the competency bar

Information Security
2
Operational Excellence
2
Strategy
1
Legal & Compliance
1

AI in this role

  • Modeling GRC maturity
  • Analyzing compliance patterns
  • Generating operating models

L9 — SVP, GRC Foundational

Mission

Define GRC strategy and risk posture

This tour of duty

Define the GRC strategy that manages risk

Own the outcomes

  • Own GRC strategy and execution organization-wide
  • Define multi-year roadmap for risk management
  • Build culture that attracts top GRC talent
  • Partner with executives and board on risk strategy
  • Establish GRC as organizational strength
  • Shape the future of GRC at the company

GRC at L9 — the competency bar

Operational Excellence
2
Information Security
1
Strategy
1
Legal & Compliance
1

AI in this role

  • Building strategic planning systems
  • Analyzing regulatory trends
  • Creating GRC architectures

What Hiring Managers Look For

L1-L3: Demonstrate you can translate regulatory requirements into actionable technical controls and speak fluently to both auditors and engineers.

L4-L6: Show evidence of designing compliance programs that actually reduced business risk rather than just checking boxes, with metrics to prove it.

L7+: Board members evaluate whether you can articulate cyber risk in business terms and have a track record of preventing regulatory disasters that could sink the company.

Common Career Transitions

GRC → Product Security at L4-L5 for hands-on technical risk assessment

GRC → Security Architecture at L5-L6 to design preventive controls rather than detective ones

GRC → Privacy Engineering at L4-L6 leveraging regulatory expertise in emerging data protection landscape

Official Classifications

System Code Official Title
O*NET-SOC (US) 15-1212.00 Information Security Analysts
ISCO-08 (UN/ILO) 2529 Database and Network Professionals Not Elsewhere Classified

At L6 and above, the manager classification 1330 — Information and Communications Technology Service Managers applies IN ADDITION to the professional code — a manager is a superset of the individual contributor, never a replacement.

Measure yourself against this ladder — pin it to your Career Record.

Build Your Career Record