GRC Analyst
Govern security risk: policies, audits, compliance frameworks and third-party risk, including new AI governance work.
Growing with regulation, including AI governance requirements.
Day to day
- •Run risk assessments
- •Map controls to frameworks like ISO 27001 and SOC 2
- •Prepare for and support audits
- •Review vendor and AI system risk
Start from: No technical background required
- 1
Security and risk fundamentals
4 weeksSpeak the language of risk and controls.
Risk assessment
Everything in GRC starts from likelihood and impact.
Security controls
You map controls to risks and prove they work.
Policy writing
Policies are the organisation's rules, and you draft them.
Certifications
- CompTIA Security+ · CompTIA
Portfolio project
Write an acceptable-use policy and a risk register for a fictional company.
- 2
Frameworks and audits
6 weeksRun a control mapping and support an audit.
ISO 27001 and SOC 2
The frameworks customers ask about most.
Evidence collection
Audits pass or fail on evidence.
Third-party risk
Vendors are a leading source of breaches.
Certifications
No certification needed here. Your project is the proof.
Portfolio project
Map a company's controls to SOC 2 and list the evidence each one needs.
- 3
Senior GRC and AI governance
8 weeksLead programmes, including governance of AI systems.
AI risk management
Organisations now need policies for how AI is used and tested.
Security programme leadership
Senior roles own the roadmap, not just the checklist.
Reporting to leadership
Boards fund what they understand.
Certifications
- Certified Information Systems Security Professional · ISC2Practise
Portfolio project
Draft an AI acceptable-use policy and a risk assessment for an internal LLM tool.
Finish line
Prove you're ready to apply
18 workplace scenarios. Reach 80% with no area below 60% for a job-ready signal.
Take the readiness exam
Certification requirements, prices and exam formats change. Always confirm on the issuer's site, linked from the certifications page.