What does GRC look like in Cloud Computing. Is Third Party Risk Management Dead?
For 7+ years I've worked for several different organizations in Governance, Risk and Compliance. My current role is a third party risk analyst for a large financial services company. Our team performs onsite and remote assessments. I've obtained my CISSP and CRISC certifications, and now like a lot of folks I'm ready to chase the next shiny object (Cloud Security) and so I've started to study for the AWS Cloud Practitioner exam which is utilized in my organization.
You might ask why? Well from the beginning GRC was probably less technical then what I was looking for and since I actually don't like spending time on preparing for presentations to senior leadership and having back to back meetings that limits my career options for the higher level roles within GRC (at least the one's that pay). What I would like to do is find a role where I could combine my GRC experience with cloud computing, but I am unsure what that role would look like.
I envision one of the key responsibilities to be configuring the cloud environment to fit a particular security control set or baseline. I just don't know what level of skill is needed to do this. I've read several cloud security job descriptions but each description appears to be different. With that stated, I have a few questions for the community.
-Are there roles on the market right now that combine the two disciplines (GRC and Cloud)? If so, what skills do I need. If not, do you think these roles will exist in the future?
-Through my discussion with recruiters wages have dropped for TPRM roles. I personally think TPRM is undervalued and is considered low value work. I also think that these roles are being off boarded to offshore workers and companies are starting to purchase tools to automate TPRM. What do you think is the future of third party risk management (TPRM) within the cybersecurity sector?