8 years ago, I left technical cyber security and moved into GRC.
Everyone thought I was crazy.
And honestly… even I wasn’t 100% sure I was making the right decision.
At the time, it felt like I was walking away from the “real cyber” work.
The tools, the technical depth, the analyst identity.
But I did it anyway.
Now, 8 years later, I’ve got a lot to say about this move because I’ve lived both sides:
the technical path
the GRC path
and what nobody tells you before you switch
8 years later: GRC
In this video, I also share exactly what I said in the interview that got me hired, and the one thing I chose not to tell the hiring manager at the time because I genuinely thought it might make me look bad.
So I made a video sharing the full story, the trade-offs, what I gained, what I lost, and the real answer to the question: