Hello! I’m working on transitioning and trying to use my resources better, I barely use Reddit but it’s a super good source of information and conversations I either haven’t had the chance to have, or just didn’t think about it.
I’m pivoting from customer service/sales to Cybersecurity. I took a 6 week class a while back on the NIST RMF process from the viewpoint of an ISSO, learned some basic networking, got experience with some documents like the SSP, a CUI SSP, POA&M, practiced writing risk registers & doing risk assessments as well as control selection, and did some basic networking and malware practice to learn how some of that stuff works. I’ve also taken Gerald Auger’s GRC masterclass, and am going through a skillternship course on Udemy focused on GRC projects from the lens of a GRC analyst. I haven’t taken a bootcamp for anything after the initial class because I genuinely like researching this stuff myself, but have admittedly spun myself in a circle trying to figure out what I need to master to REALLY make myself a good candidate for a GRC role to get in and work my way up.
I like the technical stuff too though, so I’ve done a little training on tryhackme and portswigger as well. In my day to day I’m vice president of an ERG, I do a lot of event planning and projects for my day to day job as well - I’m currently a pricing analyst who writes contracts for safety services in the manufacturing space, and I have projects on merging contracts types, improving training, and working with other teams to build automation, just because I see a problem and try to build a way to solve it.
I have a plan to go through the masterclass one more time to refresh as well as complete the Udemy course to build some more projects and get out there. I’m looking forward to connecting and talking with you all more! Please feel free to reach out as well, I’m always looking forward accountability partners, mentors, and friends in general that are on the same path or have walked it before.