
2+ years IT support + ISO 27001 Lead Auditor cert — 6 months job hunting for GRC/IT Audit, no luck. Resume feedback + advice needed
Background: I have 2+ years of experience as a desktop support/system engineer at BFSI company (insurance), where I did endpoint security compliance monitoring — patch checks, antivirus, DLP, access controls. Not formal audit work, just operational compliance checking.
I completed ISO 27001:2022 Lead Auditor certification (CQI-IRCA) — failed first attempt, passed on resit. Been job hunting for GRC/IT Audit entry-level roles for 6 months now.
Results so far: Getting phone screens regularly, but most fall apart when I explain I don't have direct GRC/audit experience just the technical operations background + cert. Got to a Last round with one company but got rejected struggled on TPRM and SIEM questions, and he also grilled me on why I quit my last job to pursue this transition unemployed.
Genuinely asking:
- Is my resume the problem, or is this just how brutal the entry-level GRC market is right now?
- Am I positioning my experience wrong on my resume?
- Should I stop targeting GRC/Audit titles and look at "Security Analyst" or similar instead?
- Anyone who broke in from a similar IT support background what actually worked?
Appreciate any honest feedback, even harsh.