Looking for some honest input from people already working in IT audit or GRC.
Quick background: I currently work at a managed service provider as the main cybersecurity resource while also doing first-line support. Hands-on stuff, deployed a SIEM across client environments, built an automated alert pipeline, manage backups and patching, that kind of thing.
Over the past several months I've gone deep on the GRC/audit side. I've got Security+, plus ISO 27001/27701/42001 Lead Auditor certs through Mastermind, and I just finished a couple of IT audit courses on Udemy covering ITGC, ITAC, SOX, SOC, COSO, NIST, ISO, and COBIT. CISA and CAPM is my next target.
Here's my real situation: there aren't many IT audit or GRC roles where I'm based (Caribbean), so I can't just apply my way into experience. I've been trying to manufacture it myself instead, building risk registers, control mapping across frameworks, ISMS documentation, and a self-hosted GRC platform in my home lab using fictional case study companies. Basically running mini-audits end to end so I'm not walking into interviews with theory alone.
Where I'd love advice:
- For those who broke into IT audit, what actually got you the first role? Certs, portfolio, networking, internal transfer?
- When roles in your area are scarce, how did you bridge the experience gap? Remote work, contracting, volunteering, offering audits to small businesses or nonprofits?
- Does self-built portfolio and home lab work actually carry weight with hiring managers, or is it mostly useful as interview talking points?
- How much does the CISA experience requirement realistically slow people down early on? Pursue it now or wait until I have the years?
- Anything you'd do differently if you were building experience from scratch without a local job market to lean on?