Blog
sprinto angle right
Newsletter
sprinto angle right
From Board Minutes to Risk Registers: One GRC Practitioner’s Unlikely Path

From Board Minutes to Risk Registers: One GRC Practitioner’s Unlikely Path

Most people in GRC will tell you they “fell into” the field.

For Will Haddix, that path began far from the usual security career ladder. Now a Deputy CISO at a fintech, his route into GRC was shaped by years spent watching executives make decisions, rather than through code or certifications.

His journey reveals which skills actually determine whether a GRC practitioner is effective.

Part 1: How Will got here

Career progression path from Hospitality to Deputy CISO, showing roles including Exec assistant, EA to CLCO, Risk analyst, and Bootcamp + TPRM.

Will spent his first decade in hospitality. Front office, then an executive assistant role to an Assistant General Manager. He prepared committee briefs, documented board minutes, and built presentations for executives who were themselves leaders in marketing, finance, and law. He learned how to translate complexity into something a board could act on. He learned what to leave out.

As Will put it,” You want to make sure you stay at the right altitude. You just need to give them enough information to make informed decisions.”

Diagram showing three levels of board communication: board altitude (yes/no decision), recommendation (compressed technical reality), and technical reality (full operating plan details).

He eventually moved to a fintech as the EA to the Chief Legal and Compliance Officer. That role put him next to the GRC function for the first time, and he realized the cyber side was where he wanted to be.

So he did something most people talk about, and few do. He asked the GRC team if he could take on third-party risk management work alongside his EA role. Then he enrolled in a six-month cybersecurity bootcamp at Northwestern, three evenings a week, with six to eight hours of weekend assignments on top. He was simultaneously an EA, a junior GRC team member, and a bootcamp student. After he finished, he earned Security+. The governance manager brought him on full-time as a risk analyst.

Then he kept stacking, deliberately. AWS Cloud Practitioner when the company moved to the Cloud. Certified Blockchain Security Professional because the business worked with digital assets. PCIP because card payments were on the roadmap.

A few months ago, Will was promoted to Deputy CISO. The title is impressive on its own, but the timeline is the real story: within a short span, he went from volunteering for third-party risk work alongside his EA role to helping lead the security function at a fintech.

That is not just a career pivot. It is a case study in what actually compounds in GRC.

Part 2: What his journey actually reveals

The easy reading is that Will worked hard and got lucky. That’s true, but it misses what’s portable. Four skills carried him through every transition, the same four that separate effective GRC practitioners from the ones who stall.

Translation between two worlds

Diagram showing how GRC mediates between leadership and technical perspectives in decision-making.

That sentence captures one of the most important parts of GRC work: translation.

GRC practitioners often sit between two groups that consistently misunderstand each other. Leadership wants a clear recommendation. Technical teams need room for nuance. The work is not to erase that nuance, but to convert it into something the business can act on. A good GRC practitioner turns technical reality into executive judgment, then routes the remaining complexity into the operating plan.

Quote card: Will Haddix, Deputy CISO, on connecting leadership vision with technical feasibility.

Will’s training for this came from his EA years, well before the bootcamp. By the time he moved into a risk analyst seat, this muscle was already built.

The second skill is, on its surface, insultingly basic. Then you look at what a mid-stage GRC program contains. A control library with hundreds of items. A vendor inventory that grows every quarter. A risk register only useful if it’s current. All of it is conceptually simple. All of it falls apart without disciplined tracking.

The deeper insight is that organization in GRC goes beyond personal productivity. It’s about building systems that hold their shape on their own, even when you step away. When Will took over third-party risk management, he inherited a process designed for a fully-staffed team that had since been reduced. Rather than working harder, he redesigned the structure to hold under the new constraints. That’s the skill. System design under constraint, well beyond list-making.

Anchoring everything to risk

Most GRC programs accumulate controls the way an attic accumulates boxes. Will’s discipline against this:

Quote card: Will Haddix, Deputy CISO, questioning the effectiveness of security controls that don't address underlying risks.

The harder move underneath this question is the willingness to walk away from a control. Every control has a cost in attention, friction, and maintenance, and piling on unjustified ones dilutes attention away from the ones that matter. Being able to say “this doesn’t address a real risk for us” and document why is what determines whether your program is in service of the business or in service of itself.

Continuous learning aligned to the business

Will’s certification trail is the illustration. Each one mapped to a real shift inside the business. That discipline, reading your own organization’s roadmap as carefully as you read frameworks, is the one most practitioners forget to apply to their own learning.

A table showing how four security certifications addressed business needs: Security+, AWS Cloud Practitioner, Blockchain Security Pro, and PCIP.

He also flagged one piece of advice no security curriculum includes: if speaking to executives makes you nervous, take an improv class or join Toastmasters. It’s the highest-leverage skill investment most early-career GRC people could make, and it lives well outside any certification path.

The through-line

All four of these skills sit independently of deep technical expertise, framework specialization, or a CISSP.

Will’s path looks unusual on paper. The through-line is that every role trained him in at least one of those skills before he ever stepped into security. The certifications came later, and they mattered. But they sat on top of a foundation most security-first careers skip past.

That ordering, more than any credential, is what’s worth paying attention to.

A maturity gauge prompts readers to assess their AI governance strength across their organization and vendors.

Subscribe to our newsletter for full access to the content

newsletter
Srikar Sai
Author

Srikar Sai

As a Senior Content Marketer at Sprinto, Srikar Sai believes good content should be bookmark-worthy by default. He writes about cybersecurity and GRC, aiming to move the needle with every piece. He’s also an ISO 27001-certified Lead Auditor.
Tired of fluff GRC and cybersecurity content? Subscribe to our newsletter and get detailed
research & insights curated to help you earn a seat at the table.
single-blog-footer-img