2+ years IT support + ISO 27001 Lead Auditor cert — 6 months job hunting for GRC/IT Audit, no luck. Resume feedback + advice needed
▲ 19 r/ISO27001+1 crossposts

2+ years IT support + ISO 27001 Lead Auditor cert — 6 months job hunting for GRC/IT Audit, no luck. Resume feedback + advice needed

Background: I have 2+ years of experience as a desktop support/system engineer at BFSI company (insurance), where I did endpoint security compliance monitoring — patch checks, antivirus, DLP, access controls. Not formal audit work, just operational compliance checking.

I completed ISO 27001:2022 Lead Auditor certification (CQI-IRCA) — failed first attempt, passed on resit. Been job hunting for GRC/IT Audit entry-level roles for 6 months now.

Results so far: Getting phone screens regularly, but most fall apart when I explain I don't have direct GRC/audit experience just the technical operations background + cert. Got to a Last round with one company but got rejected struggled on TPRM and SIEM questions, and he also grilled me on why I quit my last job to pursue this transition unemployed.

Genuinely asking:

  1. Is my resume the problem, or is this just how brutal the entry-level GRC market is right now?
  2. Am I positioning my experience wrong on my resume?
  3. Should I stop targeting GRC/Audit titles and look at "Security Analyst" or similar instead?
  4. Anyone who broke in from a similar IT support background what actually worked?

Appreciate any honest feedback, even harsh.

u/Particular-Report-12 — 11 days ago