Step 1 of the GRC Portfolio Studio

The Real Reason Starting a Non-Coding Cybersecurity Career Feels So Hard (And How to Fix It in One Weekend)

Many people want a non-coding cybersecurity job but do not know where to start. You may have taken classes or earned a certificate, but still have no work to show an employer.

This weekend, you will work as a new Governance, Risk, and Compliance (GRC) analyst for TechFlow Solutions, a fictional company that wants an organized way to manage and improve information security, called an ISMS. You will help TechFlow put its starting structure in place: leadership approval, clear responsibilities, and the rules the company must follow.

Date: August 29 and 30, 2026  路  Time: 10:00 a.m. to 12:30 p.m. ET both days
Join the Challenge General $97 路 VIP $297 路 VIP limited to 10 seats

Does This Sound Familiar?

You may be thinking:

"I want a non-coding cybersecurity job, but I do not know where to start."

"I have learned some terms, but I do not know what GRC work looks like."

"I have work experience, but I do not know how it connects to GRC."

"I have nothing on my resume that shows I can do this work."

In the Challenge, you will learn the basics and complete one clear GRC assignment with live help and easy-to-use templates.

Build the Governance Package in One Weekend

The Governance Package is a set of five short documents that give TechFlow's security program its starting structure: a Program Charter that explains why TechFlow needs an information security program, a matrix showing who is responsible for what, a register of the rules TechFlow must follow, a high-level security policy, and basic rules for reporting risks.

Together, the five documents form one work sample. It shows a hiring manager that you understand how a security initiative is formally started, governed, and connected to leadership.

You will learn the basic GRC and ISMS terms as you use them, work from clear examples and templates, and have time to ask questions while you complete the work.

Saturday: Build the Foundation

  • Create your portfolio folder, cover page, introduction, and build checklist. See how the Challenge work connects to the full 10-step Studio path.
  • Learn the basic meaning of Governance, Risk, and Compliance, why leadership approval matters, and how an executive sponsor gives the program authority.
  • Review the TechFlow case, identify the project sponsor and stakeholders, assign responsibilities, and document the legal, contractual, customer, and business requirements the program must consider.

Your Saturday Assignment

Finish your Stakeholder and Responsibility Matrix and Requirements Register. Then list the main issues TechFlow leaders should address in the Program Charter and Information Security Policy on Sunday.

Sunday: Build the Governance Package

  • Document why TechFlow is starting the program, its objectives, sponsor, stakeholders, high-level scope, responsibilities, timeline, and approval expectations.
  • Define when information security concerns should be escalated, who can accept risk, and what types of issues require leadership attention.
  • Create the policy that sets TechFlow's overall direction and commitment to information security.
  • Create resume bullets and a structured interview explanation based on the governance work you completed.
Join the Challenge General $97 路 VIP $297

What You Will Take With You

  • An Information Security Program Charter that explains why the program is needed
  • A Stakeholder and Responsibility Matrix that shows who does what
  • A Requirements Register that lists the rules TechFlow must follow
  • A High-Level Information Security Policy
  • Basic rules for reporting and approving security risks
  • Resume bullets and a structured interview explanation

Here Is How It Works

When

Saturday and Sunday, August 29 and 30, 2026, 10:00 a.m. to 12:30 p.m. ET both days. Five hours in total.

Where

Live online from anywhere

Who It Is For

Career changers, recent graduates, and certificate holders who are new to Governance, Risk, and Compliance and want to build their first work sample. You do not need previous GRC or cybersecurity experience.

Want Feedback on Your Work? Choose VIP.

VIP includes everything in General Admission, plus seven-day replay access, one review from Dr. Shumba, and a completed TechFlow example with notes.

Finish your Information Security Governance Package, submit it with your resume bullets, and receive feedback.

Submission deadline: Submit your completed Governance Package and resume bullets within 48 hours after the Challenge ends, by Tuesday, September 1, 2026. Feedback is returned within seven days after you submit.

VIP example: You will also receive a completed TechFlow Information Security Governance Package with notes that explain each section.

Only 10 VIP seats are available because Dr. Shumba reviews each submission.

Choose VIP 路 $297

The Challenge Begins Soon

Challenge starts: Saturday, August 29, 2026, at 10:00 a.m. ET

Choose Your Ticket

Includes Feedback

VIP Admission

For participants who want replay access, feedback, and a completed example with notes.

$297
  • Both live sessions
  • Live teaching and time to complete the work
  • TechFlow Solutions company case
  • Step 1 templates and examples
  • Private event discussion group
  • Seven-day replay access
  • One review of your completed Governance Package and resume bullets
  • A completed TechFlow Governance Package with notes

Only 10 VIP seats are available.

Join VIP 路 $297

General Admission

For participants who can attend both sessions live and want to complete Step 1.

$97
  • Both live sessions
  • Live teaching and time to complete the work
  • TechFlow Solutions company case
  • Step 1 templates and examples
  • Private event discussion group

General Admission is live-only and does not include replay access or individual feedback.

Join General 路 $97

Your Ticket Counts Toward the Studio

The Challenge covers Step 1 of the GRC Portfolio Studio. Finish the required work and your TechFlow Information Security Governance Package becomes the first part of your GRC portfolio.

When you join the Studio, you keep the work you created and move to Step 2: Define Scope, Business Context, Assets, and Information. People who join the Studio without attending the Challenge complete the same Step 1 inside the Studio.

Your full Challenge ticket price will be credited toward the $997 founding Studio price when you enroll by Wednesday, September 9, 2026.

General Admission participants will have $900 remaining. VIP participants will have $700 remaining.

First-cohort enrollment closes Saturday, September 12, 2026.


See the Complete 10-Step Path

Meet Your Coach

Dr. Rose Shumba has more than 20 years of experience helping students and professionals prepare for technology and cybersecurity careers.

She is a cybersecurity educator, computing professor, and former director of a National Security Agency and Department of Homeland Security-designated Center of Academic Excellence in Cyber Defense.

Dr. Shumba holds the PECB ISO/IEC 27001 Foundation credential. She created the TechFlow Solutions case and teaches every Challenge session live.

Frequently Asked Questions

Is the Challenge Step 1 of the GRC Portfolio Studio?

Yes. The Challenge covers Step 1: Establish Leadership, Governance, and Project Approval. When you join the Studio, you move to Step 2 instead of repeating this work.

What is an ISMS, and will I build one this weekend?

An Information Security Management System, or ISMS, is the organized way a company manages and improves information security. You will not build the full ISMS in one weekend. You will build its leadership and governance foundation; the remaining work continues across the other nine Studio steps.

What will I complete during the Challenge?

A TechFlow Information Security Governance Package: an Information Security Program Charter, a Stakeholder and Responsibility Matrix, a Requirements Register, a High-Level Information Security Policy, and basic rules for reporting and approving security risks.

What if I cannot attend live?

General Admission is live-only and does not include replay access. VIP participants receive seven-day replay access. Try to attend live so you can ask questions and get help while you work.

Do I need previous GRC or cybersecurity experience?

No. The Challenge is made for beginners. You will learn the basic terms while you complete the work.

Do I need a technical background?

No. Basic computer, document, and spreadsheet skills are enough.

What is included with VIP?

Everything in General Admission, plus seven-day replay access, one review of your Governance Package and resume bullets, and a completed TechFlow example with notes.

How soon will I receive my VIP feedback?

Submit your Governance Package and resume bullets by Tuesday, September 1, 2026. Your feedback will be returned within seven days after you submit it.

Will the Challenge help me get a job?

The Challenge helps you build a work sample and practice explaining it. It does not promise an interview or a job. Employers make all hiring decisions.

What if I am still exploring non-coding cybersecurity roles?

Start with the free GRC Career Roadmap. It explains common roles, the skills employers look for, and the first steps you can take. Get it at kudzaiedugroup.com/grc_roadmap.

What is the refund policy?

You may cancel and request a refund until 10:00 a.m. ET on Thursday, August 27, 2026. No refunds will be given after that time or after the Challenge begins.

Stop Wondering What Work to Show Employers

Leave with an Information Security Governance Package you can show and explain during interviews.

Your portfolio starts here.

Join the Challenge General $97 路 VIP $297 路 VIP limited to 10 seats

Iron sharpens iron.