Build your knowledge around

GRC areaFrameworks you should know particularly well
Risk managementNIST CSF, NIST 800-53, ISO 27001, DORA, NIS2
Access control / IAMNIST 800-53, ISO 27002, PCI DSS, SOC 2
Security policiesISO 27001/27002, NIST, SOC 2
Incident managementNIST, ISO 27002, PCI DSS, NIS2, DORA
Business continuity / DRISO 27002, NIST 800-53, DORA, NIS2
Vulnerability managementNIST 800-53, ISO 27002, PCI DSS, NIS2
Logging / monitoringNIST 800-53, ISO 27002, SOC 2, PCI DSS
Data protection / privacyGDPR, UK GDPR, ISO 27002, NIST 800-53
Third-party riskISO 27002, NIST 800-53, SOC 2, DORA, NIS2
Security awarenessNIST 800-53, ISO 27002, PCI DSS, NIS2
CryptographyISO 27002, NIST 800-53, PCI DSS, GDPR, NIS2
Secure developmentNIST 800-53, ISO 27002, PCI DSS, NIS2, EU AI Act
Audit/evidence/testingISO 27001, SOC 2, PCI DSS, NIST 800-53
AI governanceEU AI Act
Financial operational resilienceDORA

The key GRC skill you are building

You should eventually be able to take something like:

GDPR Article 32 → Security requirement → ISO 27001/27002 control → NIST control → Evidence → Test → Gap → Remediation

or:

DORA Article 6 → ICT risk requirement → ISO 27001 control → NIST control → Evidence → Testing → Gap → Remediation

That mapping/crosswalk ability is much more valuable to you than simply memorizing framework names.