FieldsCybersecurityGRC Analyst
GRC Analyst
Keep the organization compliant, audited, and ahead of risk.
Career
- Structure
- 8 modules, each ending in a milestone
- Proof
- Verified against real tasks from module 2
- Ends in
- A defended capstone and a high-assurance credential
The journey
Practised under observation
Governance, risk and compliance: what this function is forThe discipline's purpose and its shared language: why organisations govern security, what the three letters actually mean, and the security literacy that makes the work real.Practised under observation
MilestoneUnderstands the function and can talk to engineersNothing an engineer tells you gets written down without being questioned first, and a document that produces no decision is named as what it is.
From here, milestones are verified rather than practised.
Verified against a real task
Risk management as a disciplineThe core intellectual work: risk identified, assessed honestly, treated deliberately, and owned by somebody with the authority to act.Verified against a real task
MilestoneRuns a risk program, not a spreadsheetA risk nobody had written down gets found by talking to people rather than by copying a template, every treatment carries a name and a date, and a number is refused where the data does not support one.
Frameworks, regulations and the obligation landscapeWhat the organisation is actually required to do, with frameworks understood as tools rather than checklists and duplicated effort collapsed.Verified against a real task
MilestoneMaps the obligations, collapses the duplicationThe obligations this organisation does not actually carry are ruled out rather than imported, and one control satisfies several frameworks so the evidence is collected once.
Policy, standards and the control environmentTurning obligations into rules people follow: policy that is enforceable, standards that are testable, and a control environment that operates rather than decorates.Verified against a real task
MilestonePolicy that holds, controls that operateEvery rule is written so that breaking it can be detected, and a requirement nobody could actually meet is rewritten rather than published.
Assessment, audit and evidenceFinding out whether it is true, with control testing done properly, evidence sampled honestly, and findings written to be fixed.Verified against a real task
MilestoneTests the control, evidences the truthAsking whether a control happens is the weakest evidence there is and you do not stop there, the sample is one you can defend for its size and its selection, and the person who owns the control accepts the finding rather than fights it.
Incident, privacy and business continuity obligationsWhen something goes wrong: the notification clock, the privacy obligations that outlast the incident, and the continuity plan that is tested rather than filed.Verified against a real task
MilestoneMakes the determination, meets the clockThe determination is made on the evidence available because the clock does not wait for certainty, and an exercise that reveals the plan does not work is reported as a success.
Running the GRC programGovernance as a system rather than a person, with a program that scales, reporting that drives decisions, and technology that helps instead of adding process.Verified against a real task
MilestoneRuns the program, reports the truthA board reads the report and states the real exposure back to you, and a measure that exists to reassure is replaced by one that shows whether the program works.
The GRC Analyst in the organizationThe seat's integrity core: being useful without being captured, saying the unwelcome thing, and the honest difference between managing risk and documenting it.Verified against a real task
MilestoneUseful, credible, and unwilling to say it is fineCompliant and safe are not the same sentence and you will say so, a certification that is not ready does not get signed off to be helpful, and a risk the business has been quietly accepting is put to somebody who can actually decide it.
- Capstone
A program that knows the truth
A complete governance, risk and compliance engagement for a realistic organisation, worked under observation, from a governance landscape analysis and a risk assessment through the obligation map, the policy and control environment, control testing and the incident, privacy and continuity obligations to the program design and the professional layer of the seat.
DefenceYou walk an instructor through your own program: this organisation's top risks and who owns each, the risk you found that nobody had written down, whether the organisation is compliant and separately whether it is managing its risk, and what the organisation is quietly accepting without having decided to. The credential is not awarded if you cannot account for your own work.
- Credential
High-assurance credential
Evidence that you can tell whether an organisation is actually managing its risk, and say so when the answer is unwelcome. It does not claim seniority, and it does not oblige any employer to accept it.
What is not live yet
The desktop app, consent-based observation, scoring, and credentials are in development. Nothing here implies they are live yet.
Get early access