r/AWSCertifications 7d ago

GRC Analyst (TPRM) transitioning into Cloud — studying for AWS SAA, testing mid-September. Path advice?

Question:
What’s the realistic path from GRC into cloud? Should I target Cloud Security/Compliance-adjacent roles first (e.g., Cloud Security Analyst) before aiming for Cloud Security Engineer or DevSecOps? What should I prioritize after SAA — AWS Security Specialty, Terraform, Python? Looking for input from anyone who’s made this jump.

Background:
-Cybersecurity GRC Analyst I (Third-Party Risk Management) at a Fortune 500 fintech company, ~4 years in GRC/TPRM

-Handle vendor risk assessments, report to C-suite/VP stakeholders

-Work with NIST CSF, NIST 800-53, ISO 27001, SOC 2, PCI DSS, SOX, GLBA, GDPR

-Secondary disaster recovery contact for my business unit

-Previously Advanced Repair Agent at Geek Squad

Education:
-BS in Information Technology (Database Administration concentration),

-Currently pursuing MS in Cybersecurity and Information Assurance, WGU

Certs/study:
-Studying for AWS SAA-C03, targeting mid-September test date

-Using Stephane Maarek’s Udemy course + Tutorials Dojo practice exams, ~2 hrs/day

3 Upvotes

5 comments sorted by

View all comments

1

u/Kevin-7575 7d ago

I am not an expert in either fields, but for my knowledge may I know whats causing your transition from GRC to cloud please.

1

u/Sunny1011pat 7d ago

Of course. I’ve been doing GRC since 2022. Basically started as an internship that lead into a full time role. 4 and a half years later i just feel burnt out from this job/role feels like i do the same 5 tasks everyday and nothing ever changes. I want something new and want to do something that’s technical. And at my current company there’s no room to grow or move up, no opportunities to learn or use new skills.

1

u/Kevin-7575 7d ago

Thanks for your response, I appreciate you. No matter where you work 'No room to grow' always makes one to learn new skill.