GRC Analyst

For governance, risk, policy, audits, and security program work. Target role: Risk, audit, compliance. Expected timeline: 2-5 months.

Security+, CRISC, CISA, CISSP later25+ resourcesGRC

Study sequence

  1. Weeks 1-2: risk and control vocabulary
  2. Weeks 3-4: NIST CSF and CIS Controls
  3. Month 2: evidence, policies, and audit workflow
  4. Month 3+: SOC 2, ISO 27001, and business reporting

Portfolio projects

  • Risk register
  • Control mapping worksheet
  • Security policy sample
  • Audit evidence request checklist