I've spent my career translating federal grant requirements into proposals that get funded, server-level security into blog posts a small-business owner can actually use, and community needs data into assessments that told a board why the numbers mattered, not just what they were.
Different subjects, same skill: taking something dense and consequential and making it clear enough to act on. That's why governance, risk, and compliance feels less like a career change and more like the same job with different clothes on.
GRC is where writing, evidence, and accountability meet, and I've been living that life for well over a decade. I just didn't realize it. Grant compliance meant managing a large federal portfolio under civil rights and affirmative action requirements, writing the policy, tracking the KPIs, and standing behind every claim when the auditor showed up. That's not adjacent to GRC work. That is GRC work.
Right now I'm building the credentials to match the experience: I'm working through ISC2's Certified in Cybersecurity training, enrolled in a diploma-bearing cybersecurity program, and studying NIST frameworks and practicing GRC concepts on my own time because, frankly, I find it interesting. My portfolio includes original policy documents mapped to PCI DSS, NIST CSF 2.0, and ISO 27001 — the kind of artifacts that show I can do the work, not just talk about it.
The content background isn't exactly something I'm leaving behind, either. Ten-plus years writing for B2B, enterprise, and agency clients taught me how to write for humans and machines at once (AKA how to make a document that a person will actually read and a system will actually parse). In compliance, that's not a soft skill. That's the difference between a policy that sits in a shared drive and one that people follow.
I'm based in Wisconsin, share an office with two opinionated dogs (Ziggy Woofdust and Stevie Licks), and believe that clarity is a competitive advantage. So am I.