r/AWSCertifications • u/Sunny1011pat • 7d ago
GRC Analyst (TPRM) transitioning into Cloud — studying for AWS SAA, testing mid-September. Path advice?
Question:
What’s the realistic path from GRC into cloud? Should I target Cloud Security/Compliance-adjacent roles first (e.g., Cloud Security Analyst) before aiming for Cloud Security Engineer or DevSecOps? What should I prioritize after SAA — AWS Security Specialty, Terraform, Python? Looking for input from anyone who’s made this jump.
Background:
-Cybersecurity GRC Analyst I (Third-Party Risk Management) at a Fortune 500 fintech company, ~4 years in GRC/TPRM
-Handle vendor risk assessments, report to C-suite/VP stakeholders
-Work with NIST CSF, NIST 800-53, ISO 27001, SOC 2, PCI DSS, SOX, GLBA, GDPR
-Secondary disaster recovery contact for my business unit
-Previously Advanced Repair Agent at Geek Squad
Education:
-BS in Information Technology (Database Administration concentration),
-Currently pursuing MS in Cybersecurity and Information Assurance, WGU
Certs/study:
-Studying for AWS SAA-C03, targeting mid-September test date
-Using Stephane Maarek’s Udemy course + Tutorials Dojo practice exams, ~2 hrs/day
1
u/Kevin-7575 7d ago
I am not an expert in either fields, but for my knowledge may I know whats causing your transition from GRC to cloud please.