Course 1: GRC Portfolio Builder
Course 1 Enrollment Β· Enroll by June 24 Β· Cohort Begins June 27, 2026

No admission into the program after June 24th. Enrollment closes June 24, 2026. Cohort begins June 27.

00Days
00Hours
00Mins
00Secs
Course 1: GRC Portfolio Builder

Learn How GRC Analysts Think β€” and Build the Portfolio That Proves It.

Most cybersecurity courses teach you the words. This one teaches you the work.

Over 8 weeks, you step into the role of a GRC analyst at TechFlow Solutions, a realistic fictional SaaS company. You assess TechFlow's business, identify what could go wrong, map applicable frameworks like SOC 2, HIPAA, and NIST, and produce five portfolio artifacts: an Executive Security Summary, an ISMS Roadmap, a Security Concepts Reference Guide, a Framework Quick-Reference Guide, and a complete Risk Register.

You leave with proof that you can size up a company, prioritize its risks, and explain your thinking to a hiring manager using your own work, not borrowed examples.

Timeline8 Weeks Β· 8 Modules
Outcome5 Portfolio Deliverables
SupportWeekly Live Sessions
PathAssess β†’ Prioritize β†’ Explain

Led by Dr. Rose Shumba, PhD Β· 20+ years in cybersecurity education Β· Former NSA/DHS Center of Academic Excellence Director Β· Featured in The New York Times Β· 500+ career transitions supported

Marcus was a plumber with a Security+ certification and no callbacks. After completing this program, he built real portfolio artifacts and landed a GRC Analyst role.
Start Here

Welcome from Dr. Rose Shumba

Start with the vision, the proof gap, and the exact path behind our promise: helping you build the portfolio work hiring managers want to see.

βœ“
Your Background Isn't Holding You Back. It May Be the Reason You Get Hired.

Maria was a bank teller. Marcus was a plumber. David had one certification and no callbacks. They did not come from traditional cybersecurity backgrounds. What they had was a willingness to build real proof and learn how to translate their experience into GRC work.

βœ•
This is not for you if:
  • βœ•You want a quick certificate shortcut
  • βœ•You want passive videos without producing real work
  • βœ•You are not willing to write, present, and defend your thinking
  • βœ•You expect enrollment alone to make you job-ready
Free Preview

See how Course 1 begins.

Get free preview access to Module 1 and experience how the course starts. Watch the welcome, hear what the industry expects, see the course overview, and preview the first lesson before deciding whether to continue.

Start the Free Preview
The Hiring Reality

The Non-Coding Cybersecurity Market Is Real.
But It Still Filters for Proof.

GRC is one of the clearest entry paths into non-coding cybersecurity, but employers are not hiring on interest alone. They want candidates who can think clearly, document well, and communicate like working analysts.

Press play to listen
Course 1 Podcast: What Hiring Managers Actually Want
A short industry perspective that frames the rest of this page.
Approx. 6-8 min
"Walk me through how you assessed the environment."
"Show me how you scored this risk."
"Explain the business impact."

Many candidates learn the language of GRC. Far fewer can open a real artifact, explain their reasoning, and defend the decisions behind it. That is the gap between being interested in the field and being taken seriously for a role.

59%
of organizations cite soft skills as the top cybersecurity workforce gap β€” ISACA 2025
57%
say critical thinking is one of the hardest competencies to find in candidates
Real Work
changes how hiring managers evaluate you. It moves you out of theory and into evidence.
Most programs explain what a risk register is. Course 1 makes you build one, justify it, and practice explaining it clearly.
What You Build & What You Get

What You Build &
What You Get

You are not just watching videos. Over 8 weeks, you are building professional artifacts, using guided structure, and practicing how to explain your work clearly.

What You Build

5 portfolio deliverables built over 8 weeks that help employers see proof β€” not just interest.

01
πŸ“‹

Executive Security Summary

Module 1
02
πŸ—ΊοΈ

ISMS Roadmap

Module 1
03
πŸ“„

Security Concepts Reference Guide

Module 2
04
πŸ“˜

Framework Quick-Reference Guide

Module 3
05
πŸ“Š

Risk Register

Module 4
The same finding threads across all five documents. One MFA vulnerability at TechFlow appears in the Executive Security Summary, the ISMS Roadmap, the Security Concepts Reference Guide, the Framework Quick-Reference Guide, and the Risk Register β€” each time analyzed deeper and from a different GRC perspective. This is how real GRC work connects.
Your GRC Engagement

You Are Not a Student.
You Are TechFlow's GRC Analyst.

From the beginning of Course 1, you step into a realistic GRC engagement with TechFlow Solutions and begin doing the work in context.

TF
TechFlow Solutions β€” Your Engagement Client
SaaSHealthcare DataFinancial DataEnterprise Clients
Status: No risk register Β· No formal policies Β· No compliance program Β· Your engagement starts now.
Exclusive Alumni Upgrades

Course 1 Is the Starting Point.
The Full Path Comes After.

Course 1 is where the foundation gets built. After that foundation is in place, alumni can continue into more advanced pathways.

Start Here
Course 1 β€” GRC Portfolio Builder
Build your foundation, complete your first realistic engagement, and create your first portfolio-ready artifacts.
Continue After
Course 2 β€” Audit-Ready Portfolio Builder
Go deeper into audit skills, controls, evidence validation, and more advanced applied work after Course 1.

Advanced Pathways for Alumni

These are not starter offers. They become available only after the foundation is in place.

AI Governance
Specialized work in AI governance and AI risk management for students who want deeper focus after the core path.
Available After Course 1
Industry Practicum
Applied professional experience for students who want a deeper practice-based extension beyond the two core courses.
Available After Course 1
Who This Is For

Who This Is For

This program is for people who are serious about entering non-coding cybersecurity but do not yet have the proof employers want to see.

πŸ”„

Career Changers

You may come from healthcare, banking, teaching, administration, customer service, project management, compliance, business, or another field. This program helps you translate your existing experience into GRC work and build portfolio artifacts that show employers you can think, write, and explain like an analyst.

πŸŽ“

Recent Graduates With Nothing Concrete to Show

You may have a degree, coursework, or even a certification, but still feel like you do not have real work to show in interviews. This program helps you move from academic knowledge to practical portfolio deliverables you can explain with confidence.

πŸ›‘οΈ

Certified but Not Getting Callbacks

You may already have Security+, another cybersecurity certification, or several online courses completed, but employers still are not calling you back. This program helps you move beyond credentials by building real GRC portfolio artifacts you can explain in interviews, so hiring managers can see more than a certificate on your resume.

Enrollment

Choose Your Course 1 Option

Start with Course 1 and build five portfolio deliverables for non-coding cybersecurity roles.

Course 1: GRC Portfolio Builder
Enrollment closes June 24, 2026 Β· Cohort begins June 27, 2026
Self-Paced
$297

Best if you want to work through the course on your own schedule.

Enroll Self-Paced β€” $297

Certificate of Completion and reference letter awarded upon completing all required coursework and deliverables. All courses are digital products. No refunds. All sales are final.

Start with Course 1.

If you want to land non-coding cybersecurity roles with real work to show, this is where you begin. In 8 weeks, you will build the foundation, complete your first engagement, and create the portfolio work that changes how employers see you.

Go to Enrollment
© 2026 Dr. Rose Shumba Β· Course 1: GRC Portfolio Builder
Contact