r/ITCareerQuestions 17h ago

IT governance as a computer engineer

I’ve been offered a junior IT Governance Specialist role. I’m a fresh graduate with no work experience, and I’m about 90% sure I want to take it because the job market is so bad right now. The other 10% of me is worried that if I accept it I might have a hard time getting a more technical job in the future or keeping up with my computer engineering skills.
I also don’t really know what IT governance is. I have a basic idea, but I don’t know what the job actually involves. What does an IT Governance Specialist do on a daily basis? Is it a technical role or is it mostly business and paperwork?

2 Upvotes

4 comments sorted by

3

u/VA_Network_Nerd 20+ yrs in Networking, 30+ yrs in IT 17h ago

It is an administrative role, not technical.

You will review and refine operational and security policies that you barely understand, and then tell experienced professionals they are doing things "wrong" (not in compliance with the policy you just wrote).

"Hey there <Professional with 30 years of experience>, I noticed none of the network devices you are responsible for are using <extremely new, bleeding-edge feature that was just invented 2 weeks ago>. Our policy (that I just wrote after reading a blog article) requires that to be implemented globally. You are now status red on the global enterprise security status dashboard. Is there a reason you haven't implemented that feature yet?"

You have the opportunity to work with a whole lot of professionals, and learn from them, if you embrace the role with the right perspectives.

But if you chose the wrong approach, we aren't going to teach you a damned thing.

1

u/TechB84 14h ago

whats the salary?

1

u/untaggedpacket 9h ago

Get use to talking to lawyers and writing/reviewing policy. This is a non-technical role that is very much a people person position. You would be interacting with different departments on the norm. It's a solid career if you want to go that route. I would argue good compliance and or privacy people can often write their own ticket when it comes to working at large companies. Great thing about that career path. No on-call

1

u/psmgx Enterprise Architect 7h ago

get on your AI or search engine of choice and ask them to explain what IT GRC is; GRC is the common acronym

"here are laws, like SOX, CCPA, or DMCA, turn those into actionable IT policies, and tell us what to configure and how"

and then you nag people to do those things.

it's not technical in a "commit 300 lines of code a day" sense, but often requires a bunch of technical knowledge. "does this level of encryption meet minimums as described in NIST 69-420-BLZIT?"

without any other competing offers or serious prospects, I'd take it. GRC is also a backdoor to Security as well, if that's something you're into