Learn Computer Stuff
Home / Cybersecurity / Governance, Risk & Compliance Analyst
Cybersecurity

Governance, Risk & Compliance Analyst

You turn a security standard into things the organisation actually does, and prove it did them.

No degree needed Moderate, and much less technical than the rest of this family.


Can I actually do this?

In our reading, this is the most reachable security role for someone without a technical background, and a genuine route in for people from audit, admin, project or legal work. Open without a degree. The trade-off is honest: you will be less hands-on than the rest of this family, and some engineers will undervalue the work. The standards are published free.

Who it suits. People who write clearly, chase things down, and are not bored by a control matrix.

Runway. Months. One of the shorter runways in security.

Coming from another job?

Coming from audit, administration, project management or writing? This is the security role those backgrounds transfer into most directly. Help Desk / IT Support Technical Writer

Also advertised as

  • GRC Analyst
  • Security Compliance Analyst
  • Risk Analyst
  • Information Security Officer

The route

Four stations, in order. Each one is a thing you finish before the next matters.

  1. Station one

    Learn it free

    Only the best few, deliberately. Every one of these is free to use — the pill on each card says exactly what is and isn't free.

    NIST Cybersecurity Framework

    Free to learn · no certificate

    The framework most organisations map themselves against, free from NIST. Learn its functions and you can hold a conversation in any GRC interview.

    OWASP Top 10 Proactive Controls

    Free to learn · no certificate

    You will be asking engineers whether a control exists. Knowing what the control actually is stops the conversation being theatre. Free.

    How to Meet WCAG (Quick Reference)

    Free to learn · no certificate

    Accessibility is a compliance obligation in a growing number of jurisdictions and often lands on GRC. Free from the W3C.

    See the full catalog in the explorer →

  2. Station two

    Attest strategically

    This field does put weight on certification more than most, and the recognised ones are expensive and often require documented experience before you can even sit them. We are not naming one because we have not verified current pricing and eligibility to this project's standard — and eligibility matters as much as price here, since several cannot be earned at entry level at all. Learn the frameworks free, get the first role, then let an employer fund it.

    Nothing here is worth paying for

    No credential needed

    This field does put weight on certification more than most, and the recognised ones are expensive and often require documented experience before you can even sit them. We are not naming one because we have not verified current pricing and eligibility to this project's standard — and eligibility matters as much as price here, since several cannot be earned at entry level at all. Learn the frameworks free, get the first role, then let an employer fund it.

  3. Station three

    Prove it

    A certificate says you passed a test. These say you can do the job.

    A control mapped to evidence

    Take one control from a real framework and show exactly what evidence would satisfy it. This is the entire job in miniature.

    A risk written so a director can decide on it

    Likelihood, impact, and the actual choice being asked for. One page, no jargon.

    A policy someone could follow

    Write one that a real employee could act on without asking you what it means.

  4. Station four

    Get hired

    Search these exact titles

    • GRC analyst
    • security compliance analyst
    • risk analyst
    • information security analyst

    Who hires for this. Regulated industries above all — finance, health, government — plus any company going through certification or selling to enterprise customers.

    Written artifacts carry this role, because the deliverables are documents and interviewers can read them. That is our reasoning about what is inspectable, not a hiring statistic we have verified.

    On salary

    We don't publish salary estimates. Numbers copied between blogs drift from reality, and a wrong number costs you real negotiating power. When we have a verified public source, it goes here with its date.


Where this route continues

· How we verify