Skip to content
LIVE · 10 WEEKS · PORTFOLIO-GRADED

Governance, Risk & Compliance

Run risk assessments, build ISMS controls, and carry an organization through audit.

Overview

GRC is where security meets the business, and it is the single most accessible entry point into this industry for people without a technical background. Auditors, analysts, operations managers, and quality professionals already have most of the underlying skill — what they lack is the security framework and the vocabulary.

This program supplies both. You build a real information security management system from an empty page: risk register, policy set, control implementation, evidence collection, and an internal audit you run yourself.

What you’ll learn

Six modules. Every one ends in something you built, not something you watched.

01

Security governance foundations

Governance structuresRoles & accountabilitySecurity strategyBoard reporting

DeliverableA governance charter for a mid-sized organization.

02

Risk assessment & management

Risk identificationLikelihood & impact scoringRisk registerTreatment plansRisk acceptance

DeliverableA complete, defensible risk register with treatment decisions.

03

Frameworks & control mapping

ISO 27001NIST CSFSOC 2Control mappingStatement of Applicability

DeliverableA cross-framework control mapping that removes duplicate work.

04

Policy authoring & implementation

Policy structureStandards vs proceduresException handlingAdoption & training

DeliverableA policy suite written to survive an external auditor.

05

Control testing & evidence

Test designSamplingEvidence collectionFindings & remediation tracking

DeliverableAn internal audit report with tested controls and evidence.

06

Third-party risk & audit readiness

Vendor assessmentDue diligenceContractual controlsAudit preparationAuditor management

DeliverableA vendor risk program and a certification readiness pack.

Tools you'll operate

Set in mono, not borrowed logos — we're telling you what you'll use, not implying a partnership we don't have.

ISO 27001NIST CSFSOC 2CIS ControlsRisk registersEvidence managementVendor assessment frameworks

Career outcomes

Roles this prepares you for

  • GRC Analyst
  • Compliance Analyst
  • Information Security Risk Analyst
  • ISMS Coordinator
  • Internal Auditor (security)

What you can do on day one

  • Run a risk assessment and defend every score in it
  • Map an organization's existing controls to a framework
  • Write a policy that people actually follow
  • Prepare an organization for a certification audit without panic

What you leave with

  • A complete ISMS documentation set built from scratch
  • A risk register and treatment plan for a realistic organization
  • An internal audit report with tested evidence

Who this is for — and who it isn’t

The right-hand column costs us enrollments on purpose. A wrong placement helps nobody twice.

A good fit if

  • Career switchers from audit, finance, operations, quality, or business analysis — no technical background required
  • IT professionals moving into policy, risk, and compliance roles
  • Founders and managers who need to carry their company through SOC 2 or ISO 27001

Probably not if

  • You want hands-on technical work — take SOC Analyst or Cloud Security
  • You are looking for a purely theoretical framework overview
  • You dislike writing; this role is substantially a writing role

Questions about this track

Book your call

Thirty minutes. One practitioner. A roadmap you keep.

  • We map your current skills, background, and real constraints
  • We identify the specific gaps between you and your target role
  • We recommend a track — or tell you honestly if now isn't the right time
  • You receive a written roadmap by email, whether or not you join
30 minutes
1:1, not a webinar
No payment talk

No sales pressure, and no payment discussion unless you raise it.

Can’t find a slot that works? Email info@skillxgen.com and we’ll sort a time manually.

Step 1 of 3 — Your details

We use your details only to arrange this call. Privacy.