For career switchers and junior analysts

From zero to GRC analyst — a flight simulator, not a lecture hall.

Eleven roadmap stages, fifteen hands-on labs with real company briefs, AI scoring against a rubric, and a portfolio of artifacts you actually produced. Free to start; Pro unlocks full AI grading and company generation.

Hours
55–80
Labs
15
Companies
8 briefs
Sample lab brief
Northbeam Analytics — build a risk register for a Series-B SaaS

You joined as the lead GRC analyst last month. Produce a 90-day plan that addresses the most material audit findings, stands up a vendor risk program, and gets the org to its first SOC 2 Type I readiness assessment.

AI rubric items

  • Statement quality
  • Scoring discipline
  • Controls — not vague
  • Owner by function
Open this lab →
Roadmap

Eleven stages, ordered, with honest time estimates.

From cybersecurity fundamentals to career readiness. Each stage has a summary, the topics it covers, and the hours it actually takes.

Stage 1 · Intro to Cybersecurity
3–5 hrs

CIA triad, threat actors, attack surfaces, and the language every analyst uses

CIA triad
Threat actors
Attack surfaces
Security vocabulary
Stage 2 · GRC Foundations
4–6 hrs

What GRC actually is, where it sits in an org, and how governance differs from security ops

Governance vs risk vs compliance
Three lines of defense
Policy hierarchy
GRC roles
Stage 3 · Risk Management
6–8 hrs

Risk identification, 5×5 scoring, inherent vs residual risk, and the register that auditors love

Risk identification
5×5 scoring
Inherent vs residual
Risk register
Stage 4 · Governance & Documentation
4–5 hrs

Policies, standards, procedures — what belongs at each layer and how to draft each

Policy hierarchy
Standards and procedures
Owner assignment
Version control
Stage 5 · Controls & Control Testing
5–7 hrs

Preventive vs detective, manual vs automated, and how to design tests that prove a control works

Control types
Control design
Walkthroughs
Test plans
Stage 6 · Compliance & Audits
5–6 hrs

Internal vs external audit, evidence requests, and how to keep an auditor happy

Audit lifecycle
Evidence collection
Findings management
Auditor communication
Stage 7 · Frameworks Deep Dive
8–10 hrs

NIST CSF/RMF, ISO 27001, SOC 2, PCI, HIPAA, GDPR — what each actually requires

NIST CSF 2.0
NIST RMF
ISO 27001
SOC 2 TSC
PCI DSS
HIPAA
GDPR
CMMC
COBIT
Stage 8 · Third-Party Risk
3–4 hrs

Vendor due diligence, SOC 2 reports, ongoing monitoring, and how to score vendor risk

Vendor inventory
SIG/CAIQ
SOC 2 review
Ongoing monitoring
Stage 9 · Reporting & Communication
3–4 hrs

Executive summaries, board reporting, and translating risk into business language

Audience
Metrics
Visualization
Risk narrative
Stage 10 · Practice Labs
8–12 hrs

15 hands-on exercises with real company briefs and AI-graded written answers

Risk register build
Vendor SOC 2 review
Policy gap analysis
Executive summary
Stage 11 · Career Readiness
4–6 hrs

Resume, interview prep, the GRC analyst portfolio, and landing your first role

Resume framing
Portfolio
Common questions
First-90-days plan
Frameworks

Nine frameworks, one comparison surface.

NIST CSF 2.0, NIST RMF, ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, CMMC, and COBIT — the worked examples use the framework the company actually needs.

Framework
Advanced
CMMC

The DoD's Cybersecurity Maturity Model Certification — the gating posture assessment for defense contractors handling CUI.

Explore →
Framework
Intermediate
COBIT

ISACA's governance and management framework for enterprise IT — the language risk and audit committees speak.

Explore →
Regulation
Intermediate
GDPR

EU data protection. Lawful basis, data subject rights, DPIAs, and the 72-hour breach clock.

Explore →
Regulation
Intermediate
HIPAA

Privacy, Security, and Breach Notification rules for any US entity touching protected health information.

Explore →
Standard
Advanced
ISO 27001

The international ISMS standard. Annex A controls, certification audits, and the gold-stamp global enterprises ask for.

Explore →
Framework
Beginner
NIST CSF 2.0

A voluntary framework with the six functions Govern, Identify, Protect, Detect, Respond, Recover — language that maps to almost any other standard.

Explore →
Framework
Advanced
NIST RMF

The federal risk management lifecycle — Categorize, Select, Implement, Assess, Authorize, Monitor — and the playbook most US federal work runs on.

Explore →
Standard
Intermediate
PCI DSS

Cardholder data protection. Twelve requirements, four SAQ levels, and the only one with hard technical mandates.

Explore →
Audit
Intermediate
SOC 2

Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) — the SaaS default report in the US.

Explore →
Labs

Sixteen labs. Each one is a real artifact you can show in an interview.

Risk register, 5×5 calibration, ISO 27001 gap analysis, vendor SOC 2 review, executive summary — all with real company briefs and an AI rubric.

Risk
Beginner
35 min
Build a Risk Register

Identify, score, and record 8–12 risks for a SaaS company with remote engineers.

Open lab →
Risk
Beginner
40 min
Guided Risk Register — WovenCart

Build a structured 9-risk register for a mid-size D2C retailer using a guided form with 5×5 scoring and printable output.

Open lab →
Risk
Intermediate
30 min
Calibrate a 5×5 Scoring Matrix

Write the org-specific likelihood/impact definitions so two analysts score the same risk the same way.

Open lab →
Compliance
Advanced
55 min
ISO 27001 Gap Analysis

Map an existing control set to Annex A and produce a remediation roadmap.

Open lab →
Vendor
Intermediate
45 min
Review a Vendor SOC 2 Report

Read a SOC 2 Type II and produce a memo on what to trust, what to verify, and which exceptions matter.

Open lab →
Reporting
Intermediate
30 min
Write an Executive Summary

Translate a 60-page audit report into one page a CFO will actually read.

Open lab →
Companies

Eight realistic company briefs. Pro users can generate new ones.

Each brief has systems, regulatory exposure, relevant frameworks, risks, control priorities, audit concerns, vendor risk, BCP/DR concerns, and the analyst task to actually do.

SaaS
Northbeam Analytics

North America

Series-B observability platform with 180 employees, mostly remote engineers, processing customer telemetry in AWS.
Healthcare
Atlas Health Partners

US

Regional integrated delivery network with 14 clinics and a shared EHR, recently completed a merger with a smaller group.
Fintech
Trellis Pay

United States + EU

Cross-border B2B payments startup, 90 employees, money-transmission licenses in 12 US states plus an EMI in Ireland.
Retail
WovenCart

Global

D2C apparel brand with 400 employees, peak-season traffic concentrated in November-December.
Government Contractor
Ironfield Defense Systems

US

Mid-sized defense contractor with cleared personnel, handling Controlled Unclassified Information (CUI) and some ITAR data.
Education
Lumora Learning

EU

Online K-12 tutoring platform with 1.2M students across the EU, processing minors' data and special category data (educational records).
Manufacturing
Cobalt Industrial

North America + Mexico

Industrial OEM with eight plants, 3,000 employees, and a recently acquired IT/OT convergence program.
SaaS
VergeWorks

APAC

Singapore-headquartered dev tooling company with 60 employees and enterprise customers in JP, AU, and SG.
Pricing

Three tiers. Cancel any time.

Free
$0forever

The catalog, the briefs, the workbench, manual grading.

  • Full roadmap + frameworks
  • All 15 labs (you write)
  • Workbench + CSV export
  • Job functions + glossary
Start free
Pro
Most popular
Billing cycle
$19.99/month

Billed annually · $239.88/yr

  • AI rubric scoring on every lab (sub-scores, strengths, gaps).
  • AI company generator — spin up new briefs with one click.
  • Full framework walk-throughs (controls, related labs, premium templates).
  • Readiness dashboard, tracked achievements, exportable artifacts.
Team
Custom

Seats, content cohorts, and team-level reporting.

  • Seats across your team
  • Cohort progress reporting
  • Instructor dashboards
  • Priority support
Contact us
Job functions

26 concrete analyst responsibilities.

Why it matters, when it is done, inputs and outputs, a beginner example, and the common mistakes — for every job function in the GRC analyst playbook.

Read the 26 job functions →
Workbench

10 templates with seed data + CSV export.

Risk register, control matrix, policy outline, evidence checklist, remediation tracker, issue log, vendor worksheet, executive summary, compliance tracker, control test worksheet.

Open the workbench →
FAQ

Honest answers to the common questions.

Achievements

Six milestones that map to real GRC analyst behaviors.

  • First Lab

    Submit your first lab answer to start your analyst portfolio.

  • First Company Analysis

    Generate your first AI-created company brief.

  • Foundations Complete

    Complete the first five roadmap stages.

  • Frameworks Walked

    Walk through every framework in the catalog.

  • Ten Labs Strong

    Submit answers across ten distinct labs.

  • AI Power User

    Hit 50 AI calls in a single month.

Glossary

30 terms you'll hear in every interview.

CIA triad, residual risk, DPIA, RTO/RPO, SIG, TSC, CMMC, KRI — the vocabulary that distinguishes a candidate who has done the prep from one who hasn't.

See all 30 glossary terms →

Ready to start your analyst portfolio?

Create an account, take your first lab, and start collecting the artifacts you'll show in interviews.