Free live session with Dr. Rose Shumba

Non-Coding Roles in GRC and AI Governance

Learn how to build practical experience for your résumé, interviews, and advisory work.

Saturday, September 19, 2026, at 11:00 a.m. Eastern Time One hour, live online. One session only. If you register and cannot attend, you receive the recording.

Why companies need people who can review risks and check AI plans

In GRC, organizations need people to review security risks, check suppliers, and assess whether safeguards are working. In AI governance, they also need people to examine how AI will be used and how it could affect people.

Companies are buying AI tools quickly. Tools that answer customers. Tools that sort job applications. Tools that draft letters and reports.

Someone has to look at the plan before the company signs.

What will the tool do? What information will it use? Who could be harmed if it gets something wrong? Where does a person stay in charge? What has the supplier proved, and what are they only claiming?

Many companies are still deciding who will do that work. It is the work this session is about.

These are non-coding roles

You do not write code in this work.

You read the plan and the company records. You ask questions. You judge what the evidence supports and what is still an assumption. You write a recommendation a manager can act on.

You may review test results and check whether safeguards work. For technical testing that needs specialist skills, you involve the right people.

Two ways to use these skills

A career role inside a company.

You are the person who checks the plan, writes the record, and prepares the recommendation for the people who decide. This work sits in security, risk, compliance, internal audit, privacy, and vendor teams. The titles include GRC Analyst, IT Risk Analyst, Compliance Analyst, Third-Party Risk Analyst, AI Governance Analyst, and AI Risk Analyst.

Advisory work with clients.

You work from outside the company. A client asks you to review one plan. You agree what you will check. You ask for the information you need. You give them a written report and say where your work ends. The client still makes the decision.

You learn one set of skills. You can use them either way. Saturday covers both.

Who this session is for

  • Career changers who want to know how to build proof that they can do the work
  • Recent graduates who need work they can discuss with employers
  • People interested in AI governance
  • People interested in GRC
  • People who want to understand the difference between the two
  • Anyone who is not sure how to get started in a non-coding role

What you will learn

What people in GRC and in AI governance do each day, and how the two fields differ

Why organizations need someone to review an AI plan, through real cases and the questions behind each one

Where the work sits, and the job titles to look for

The two ways to use these skills: a role inside a company, or advisory work with clients

How to produce one piece of work and explain the reasons behind your decisions

How that one piece of work becomes a résumé line, an interview answer, and a service description

How the experience you already have connects to these roles

Your host

Dr. Rose Shumba is a cybersecurity educator with more than twenty years of experience preparing students and professionals for technology careers. She holds the PECB Certified ISO/IEC 42001 Lead Implementer credential for AI management systems. She also holds the PECB Certified ISO/IEC 27001 Senior Lead Implementer credential for information security management systems.

View Dr. Shumba’s bio

Good to know

The session is free. Near the end, Dr. Shumba describes a paid live weekend where you build and defend one piece of work. Joining the paid program is optional.

Advisory work takes knowledge, practice, and experience. This session shows you what the work involves and how to start building toward it.