HN user

gt_grc

37 karma
Posts0
Comments8
View on HN
No posts found.

Also seems like Gen X has pretty good musical knowledge overall! But probably due to being the 'right age' for having been able to listen to a lot of stuff.

I came to this same conclusion. Growing up, I heard a little '40s music from my grandparents and a lot of '50s, '60s and '70s from my parents. Hip-hop, new wave, alternative and grunge all came along during my lifetime.

I used to work for a credit bureau, and a lender once asked us to build an application that could pull credit files based on SSN only. (Pulling a credit file normally requires multiple identifiers.) Fortunately, someone foresaw the very problem that you mentioned, and we declined to build it.

When the Department of Revenue published the proposed designs, some of them contained the phrase "In God We Trust," while others didn't. It wasn't made clear that the phrase "In God We Trust" wasn't part of any of the designs; it's just an optional sticker that goes where the county name (also a sticker) is usually found on the plate. The miscommunication upset just about everyone because the vote (which was just an online poll, not an official vote) to select a new design effectively became a referendum on whether the state's license plate should contain the phrase "In God We Trust." The Department of Revenue decided to republish the proposed designs without the sticker so that the public could vote again.

Two things that come to mind are sales engineer (tech skills, sales, training) and consultant (tech skills, project management, team management, sales). If you've worked with a particular software vendor's products, it could help you get your foot in the door as a sales engineer for that vendor. You could also do technology consulting at one of the Big Four or a similar consulting firm. And you can leverage your reputation and network to go back into industry if consulting isn't a long-term fit. (A few years ago, I was in a similar place career-wise and went to one of the Big Four for a while. It was a good experience for me because it basically forced me to improve my weaker skills, and it exposed me to new domains outside of my areas of expertise.) The downside is that you'll travel a lot in either job.

What's SAP? 6 years ago

"Beasts of expert domain knowledge hidden in shitty codebases" is a great way to describe most of the enterprise software I've spent my career configuring and administering. And it highlights what most users of enterprise software don't fully grasp: You don't buy it because it's user-friendly or because it's the most modern technology; you buy it for the battle-tested built-in domain knowledge.

I didn't even know that an out-of-network provider was involved in my surgery until after it was over. A couple of weeks after the surgery, my insurance company sent me an unexpected check for $3,000. I called and asked them about it. They said, "It's to pay the surgical assistant. They're out of network, so we can't pay them directly." I had no idea that a surgical assistant was even there. (I hadn't yet received the bill.) The insurance company told me that since I had already been anesthetized and couldn't ask the surgical assistant if they were in-network, I didn't have to pay anything out of pocket for the surgical assistant.

I don't have any other recommendations for studying, but as someone who made the transition from IT to GRC, I can offer some advice about getting practical experience.

A Big Four firm is a good place to get started in a GRC career. You'll get pretty broad exposure to the field, and you'll have the opportunity to develop expertise in specific GRC domains.

If you're already working in a regulated industry (especially for a publicly traded company), you may be able to move into a GRC position at your present company. Compliance, internal audit, third party risk management, business continuity/resiliency and disaster recovery are common areas that fall under the broad GRC umbrella.

I worked in various IT roles at a financial services company, and I was able to move into a risk analyst role, then I went to a Big Four firm, and I'm now back in industry.

As far as certs go, CRISC, CISA and CISSP are the most common I've seen among GRC folks, although most of the people I've worked with didn't have any of them.