Transcription
So, you want to land your first cyber security job, but you've heard things like cyber security is not entry level. Or maybe someone told you that first you need to become a network expert before you even begin to learn cyber security. But what if I told you that there is a huge area of the cyber security industry that has nothing to do with networking or coding. It is the most beginner friendly area of cyber security, but it's also the area with the least risk of being replaced by AI because it has a huge human interaction element. And the good news is this area is not just one role like a sock analyst or an ethical hacker. It's actually a group of roles that we collectively refer to as governance, risk, and compliance or GRC.
Now, here's what a typical entry-level cyber security job looks like. Some of them has strange experience requirements and overpriced certifications. Whereas entry-level GRC jobs actually look like this. They don't have those same crazy experience requirements that something like an ethical hacker job has, which wants you to have strong technical experience and really challenging and not beginner friendly certifications like the OCP, which actually costs thousands of dollars. Therefore, if you're trying to land your first cyber security job, it's a no-brainer which one of the two jobs you should be targeting.
But the question is, why don't most people apply to those GRC jobs? And the truth is, most people don't even know that these jobs exist. They don't know what job titles to search for. But even when they do, the problem is a lot of people end up wasting so much time and money on really low-quality classes that claim to be GRC, but actually lead them nowhere. And as a result, they tend to quit and not reach their goal. But what makes it really worse is that there is a lot of hype around hacking jobs, which results in so many people chasing after a small number of ethical hacking jobs. To be honest with you, those ethical hacking jobs don't actually pay the most money.
Therefore, in this video, broken into four parts, I will show you exactly how to learn and land your first cyber security GRC job. In part one, I will show you what GRC jobs actually entail and how to start learning GRC today with no prior technical background. Then I will show you how to take that learning in a step-by-step manner and add it to your resume in a way that makes you stand out to hiring managers. But then I will reveal to you what GRC certifications to do and what GRC certifications to avoid. This is crucial because there is a lot of noise around GRC now and it's really hard to navigate through all the nonsense. And after that, I will show you how to incorporate GRC even if your goal is a technical role like a sock analyst or a penetration tester, which will open so many doors for you for jobs that expect you to have some GRC knowledge, which will maximize your chances of landing your first cyber security job.
Starting with part one, learn GRC the right way. But before we start learning GRC, we need to understand what does a cyber security GRC actually do? Because there are so many job titles out there and there are actually so many different types of jobs that fall under the umbrella of GRC. Now, to answer this question, I need to give you a bit of history. In the early 2000s and even in the early 2010s, we didn't actually used to use the term GRC. The word GRC is kind of newish to the cyber security industry. However, the job itself existed. It just looked different.
Nowadays, I can probably group GRC jobs into three groups. The first one would be broadly speaking risk management. This is where the GRC professional will perform risk assessments and risk analysis on various projects and applications and initiatives in the business. They also need to document that risk and communicate it to the relevant stakeholders. Now, under that, there are actually so many specialties such as line one risk management, line two risk management, and so on and so forth. But don't worry, we'll cover all of this later in the video.
Now, the second group of roles in GRC are usually referred to as auditor. So, as a cyber security auditor, you could be performing audits on a cyber security program for an organization. You could be performing it as part of an internal audit program. You could be an external auditor or you could be performing audits against certain cyber security frameworks. Now, I know this might not be super clear to you, but trust me, we will dissect this later in the video. For now, just know that being an auditor is one of the cyber security jobs that fall under GRC.
And the third type of cyber security GRC jobs is usually consulting or senior management or cyber security strategy and even architecture in a sense can fall under the umbrella of GRC. Those type of jobs are usually a bit more senior. You have more responsibility, but this is where you can look at the big picture for an organization. You can design a long-term strategy. You can perform architectural assessment. Those type of jobs are not technical in a sense that you're not configuring the tools, but you're developing plans, you're conducting meetings, and you're developing strategy. This is actually the type of job that I currently do, and this is something that you can aspire to do because it takes years of experience, but it is essentially a GRC type of role. In fact, what most people don't know is that the Chief Information Security Officer, which is the top job in cyber security, is really a GRC job with some people management duties. Now, these are not all the roles that fall under GRC, but these can cover the majority of GRC jobs.
Now, in part two of the video, I will actually show you all the possible job titles for GRC jobs. But now, the question is, how do you even begin to learn cyber security GRC when there are so many things that fall under the umbrella of GRC? Now, to be honest with you, this is a question that I've struggled to answer up until two years ago. As part of my job in cyber security consulting, I need to coach junior consultants and tell them what training to do in order for them to develop their cyber security skills, but also their GRC skills. We had good trainings for things like blue teaming and ethical hacking. But when it came to GRC, what I found is the training that was labeled GRC was highly theoretical, full of mistakes. It was also lacking in so many areas that reflected what we do in GRC. And add to that, the online courses that I saw were simply some guy reading slides that he doesn't even understand.
Therefore, to solve this problem, I actually spent an entire year developing a comprehensive end-to-end cyber security GRC that actually covers every single area in GRC from a practical point of view that actually gives you the skills of GRC and it includes projects and certifications that you can showcase in your resume. The training is GRC Mastery.
Now, let me show you the actual things that you will learn in GRC Mastery in order for you to build your GRC skills with absolutely no technical background whatsoever. Looking through the modules of GRC Mastery, which you can see if you go to grcmastery.com, scroll down, there is a video where I show you all the modules, but let's go through them in detail. We start off with welcoming you to the course and showing you how to study for the training. And then in module one, we explain to you what GRC is. Now, whether you're familiar with this or not, it's really important for me that you don't have any gaps in your knowledge when it comes to GRC.
Next, we start with cyber security risk management. This will be your first long module. We tell you what the purpose of risk management is, how you identify cyber security threats, and then how to conduct cyber security risk assessment. We take you through important topics like risk registers, frameworks, CIA triad, OWASP Top 10, and privacy. And the most important part, we actually tell you where most organizations go wrong with cyber security risk management. This is the gold in this training because it comes straight from the real world from me actually helping hundreds of big organizations with their cyber security problems. This will actually give you great talking points in any interview. And then finally, at the end of each module, you have a knowledge check, which is multiple-choice questions. And then you have a practical assessment that will be your first practical project. And if that wasn't enough, we even have practical case studies in between modules. This is something you'll never see in any GRC training because these practical case studies actually include reports from real companies with real problems. So you get to read the reports, understand it, and then answer a few questions about those reports.
Then module three, we cover cyber security audit, which is a huge area of cyber security and frankly speaking, a lot of you will end up working as cyber security auditors. So we tell you what audit is. We explain to you the three lines of defense model that most organizations use when it comes to auditing, and of course, you have your practical assessments and knowledge check, and then you have a practical case study for cyber security audit.
Next, we go over asset management. Now, asset management itself, it could actually be a full-time job. So you could be hired as an asset management analyst for cyber security. Now, this is an important foundational topic that you need to understand really well because we're going to be building on this knowledge for later modules. So we start with asset management, what type of assets we have. Then we take you through the process of identifying assets, classifying them, and also we take you through the most common problems that organizations face with asset management.
Now, the majority of the training is actually videos that are succinct and straight to the point. We waste no time. There is also some images and some text wherever appropriate. Module five, we go through identity and access management. Another foundational topic that you will never see in any other GRC training. We explain to you the role of identity within GRC. It's really important. We're not trying to be Windows engineers or Active Directory engineers here. We're trying to learn things from a GRC point of view so that when you land your first GRC job, you can actually perform these activities with confidence and with knowledge. So, we explain to you the most common areas of identity and access management including authentication, multi-factor authentication, password authorization, and of course, we end it with knowledge check and practical assessment.
Next, we have security education and awareness. Again, this is an entire career on its own, and we cover it in a module within GRC Mastery. In fact, at least I know two people who watch my videos who've done GRC Mastery and they landed their first cyber security job in the area of security education and awareness. So, every module here is actually a job on its own. So in module six, we take you through all the foundational topics when it comes to security education and awareness. And of course, we have knowledge check and practical assessment. And then you have another practical case study. This time for education and awareness, where you get to see an actual education awareness program for a real company and you will perform an assessment on it.
Module seven, we cover data loss protection and data security, which, as you may have guessed, is also a job on its own. But here we tackle it from a GRC point of view. We cover all the important foundational topics such as data classification, data labeling. Believe it or not, these topics are actually common interview questions. So, when you get to do them in the training, this will help you a lot when you're answering questions in interviews. And of course, we have your knowledge check and practical assessment. Now, these practical assessments are actually mini projects that we will add together in the resume. So, don't stress, we will get to that.
Then module eight, we have cyber security detection and incident response, which is actually a really technical topic. However, I'm giving you what you need from a GRC point of view. This includes tasks that you would actually be performing as a GRC professional that require knowledge in detection and response. Here, we cover all your bases. We cover the role of SIEM. We cover managed security service providers, which most of you will run into in the real world. We cover incident response, the MITRE framework. And of course, you have practical assessments and knowledge check. And then you actually have another practical case study for detection and response. As you can see, the training is full of practical case studies and practical assessments. The goal is for you to come out of this training confident, knowing exactly how we perform GRC tasks in the real world. There is no theory in this training. You will finish it more than prepared.
Then module nine, we cover third-party risk management. Again, this is a career on its own, and I know at least of one person who emailed me who have landed his first cyber security job as a third-party risk analyst. So, it's a universe on its own. We cover everything that you need here. In fact, here we also give you spreadsheets and workbooks that you can use in your job as a third-party risk analyst. And of course, the practical case study will be a project that you can showcase in your portfolio as you truly land your first cyber security GRC job.
And then we cover penetration testing and vulnerability management. Believe it or not, penetration testing, ethical hacking, and vulnerability management. They have a role to play within an overall cyber security program. Here, you'll get to see exactly what role they play, why we need them, how they are useful, but also why we don't need them in some instances. You will cover all of that from a GRC point of view. And of course, you've got your practical assessments and knowledge check. And then you get to put all of this into practice in a capstone project. Now, the capstone project itself is actually longer than the majority of the previous modules because here we will use the NIST cyber security framework to conduct an end-to-end assessment on an entire organization. Now, GRC Mastery is appropriate for someone with no background and no experience. However, by this stage, this type of task is actually an intermediate to advanced task. But don't stress. I will actually go with you through every line in the NIST cyber security framework and show you the type of rationale that I use in order to solve this intermediate to advanced problem. And of course, we will be putting this project as a major project in our resume, which will make you stand out. This is not the type of thing that beginners have when they apply to cyber security GRC jobs.
But that's not the end of the training. In fact, that's almost 50% of the training. The next part of the training, we cover the Certified ISO 27001 Lead Auditor. This next part could very well be its own training course, and organizations actually charge thousands of dollars just for this training course. However, you're going to get it at no additional cost with GRC Mastery. Not only that, but by this stage, you will get a Credly badge from GRC Mastery that can prove and document the skills that you've learned in GRC Mastery, which you can share on your LinkedIn profile. In fact, in the training, I will show you also how to add things into your LinkedIn profile to make it more attractive for hiring managers.
Now, with the ISO 27001 Lead Auditor training, we actually do things different. You see, I was never happy with the existing ISO 27001 Lead Auditor training because it was either a some guy reading slides with zero practical application or a $5,000-$6,000, five-day training where they throw everything at you and you end up again with theoretical multiple-choice questions. That is not what we do in this training. I will give you all the theoretical knowledge. I'll explain the framework for you line by line. But I will also give you the spreadsheets and the workbooks that you can use in order to certify an organization for ISO 27001. Not only that, but you will also get policy documents and procedure documents that we will use in the practical project. In this training, you see, in this part of the training, we will actually create an Information Security Management System, or an ISMS, from scratch for an organization where I will build every document that's needed to certify an organization for ISO 27001.
Now, I know these are not the typical content for your run-of-the-mill ISO 27001 training. And if you've actually done any low-quality ISO 27001 training and you have on your LinkedIn keywords like "ISO 27001 training" or "lead auditor," trust me, when you do this training, you will actually learn how to do these things practically, which means you will actually be able to answer things in the interview. And as always, I'll show you how to do things without memorizing anything. If other ISO trainings made you memorize each clause and each control, none of that nonsense is something we do here. I'll teach you how to think, read, and interpret not just the ISO 27001 framework, but any cyber security framework. And of course, within that training, we include a couple of practical case studies with actual real-world ISO certificates that you will analyze, but also we have an end exam that when you pass it, you will become a Certified ISO 27001 Lead Auditor.
Now, I know some of you will be wondering about accreditation bodies. This is a huge misconception in the industry. There are accreditation bodies, which are private organizations such as BSI or TUV. There are accreditation bodies that certify organizations. So they can issue an organization a certificate that says this organization has an ISMS that is ISO certified. However, yes, they do run their own training. But the training they have is not a license for you to practice. In the tech world, in the IT and cyber security and programming, we don't have such a thing as a license to practice. For example, when you pass your CompTIA Security+, CompTIA is a private organization owned by a private equity firm. When they give you a certificate, it's not really a license for you to practice. It's just a certificate that proves that you've passed the exam designed by CompTIA. Likewise, when you pass the exam designed by GRC Mastery, we followed everything in the ISO.org framework, which is an international standard. Therefore, the certificate that you get will be valid and recognized, and you will get a Credly badge that you can share on your LinkedIn profile. So many people have finished this training, they successfully landed jobs, and some are still learning to land jobs. But everyone who has done this training speaks of the practical value and all the learning and knowledge and confidence that they gained from GRC Mastery. And of course, at the end, we give you a resume that includes everything that you've done in order for you to apply to cyber security jobs. Now, this resume alone, some people sell it for $100 or $200. And even the ISO documentations that you will get, I know organizations that sell them for thousands of dollars. So, you'll get all of that at no additional cost.
But now, the question is, with all of these projects and things that we cover in GRC Mastery, how do we add all of this to our resume? And more importantly, what if my hiring manager doesn't recognize GRC Mastery? What if my HR department doesn't know about GRC Mastery? Well, the way I've solved it for people who have done GRC Mastery and landed a cyber security GRC is that I provided them with a resume that includes all of these projects added in such a way that covers everything that you've learned, and we package them in a way that any hiring manager and any HR department will be able to recognize it. And it includes all the keywords that HR is looking for when they are hiring for cyber security GRC jobs, which is what we will cover in part two of this video.
GRC resume. Now, in order for you to follow through with part two, please go to unixgu.com/free and download my free cyber security resume template. It actually includes all of these projects added for you so you can follow through with us in this video. Now, let me show you how I'm going to add GRC projects into the resume. Now, this is how I will add everything that you've learned in GRC Mastery in the resume in a way that includes all the keywords that make it recognizable for any HR or hiring manager. So, under "Training and Certification," I'll just say "ISO 27001 Certified Lead Auditor." You could add your Credly badge, but I think it's redundant. If they ask you for proof of this certificate, simply email them the Credly badge if they ask for it. Can I say "Cyber Security Governance Risk Compliance GRC Mastery"? Yes, I didn't just type GRC Mastery. I prefer to type the entire word. This way, if there is an AI system scanning the resume, it can read "governance system compliance." So this way, if it's not designed well, some AI detection systems don't treat resumes well. This way, we make sure that it's actually read and interpreted. And then I'll have a bullet point that includes the skills. This is important because your hiring manager may have not heard of GRC Mastery yet, but they most definitely heard of cyber security risk management, audit, asset management, identity and access, education and awareness, and all of the other things that you've learned in the training. Those are keywords that are globally recognized by any hiring manager and any HR department. And then I added Qualys vulnerability management foundation. Now, this is not part of GRC Mastery. However, when you do module 10, I actually tell you, "Go and do that free training." It's two and a half hours. Most of you will do it anyway. I add it here as a keyword because Qualys is a really popular tool. This way, you're actually qualifying for more jobs.
Now, in the practical project section, I don't want you to add every single practical assessment. However, I want to be a little bit strategic. So I'll start with the most important ones and then I'll add some at the end. So, first thing, I'll say, "Completed the ISO 27001 Lead Auditor training through GRC Mastery." The next part is the most important part: "Building a full ISMS from scratch." This way, they know exactly what you've done. You didn't just pass a quick multiple-choice exam without knowing anything. No, you've actually built an ISMS and you can prove that knowledge. We say, "This includes developing risk assessments, statement of applicability, and drafting all core security policies and procedures required for certification." So, any organization that's looking for someone who knows ISO 27001, they will be really curious to meet you to see if you can do these things. And if you've done that training, you definitely can do these things. Not only that, but for any GRC job, they want someone who knows how to write policy, how to do risk assessments. So these skills actually transfer to other frameworks. So don't think that this is just ISO. No, it applies to any other framework.
Second bullet point will be about our capstone project. So we say, "Conducted a security assessment using the NIST CSF framework." And then after that, I'll add some of the practical assessments. So we start with the third-party risk assessment. This project is really important because as a hiring manager, I've interviewed hundreds of candidates over the years, and I really struggle to find anyone who knows anything about third-party risk assessment. So, trust me, this alone will make you stand out. And there is a reason why a few people have managed to land jobs in that area because there are no good training courses that cover this. So, trust me, you will stand out with this bullet point. Then I talked about asset management. "Designed a process to capture assets and maintain CMDB." Now, why did I single out asset management? Again, it's one of those rare skills, and it's an important project in a practical assessment that you've done. Now, you could add more of the practical projects. However, I truly believe this is well and truly enough because these four lines that we added actually include so many keywords. So, you cover all your bases this way.
Now that you have your resume ready with all of the keywords that hiring managers and HR departments recognize, the next question is, how do you apply to cyber security GRC jobs and what job titles should you be targeting? Let me show you how. Now, when we look for cyber security GRC jobs, there is something crazy that most people don't know, which is the majority of cyber security GRC jobs don't actually have the word GRC in the job title. I know this is crazy. Imagine telling a nurse that the nursing jobs that they will be looking at don't have the word nursing in the title. It's not ideal, but this is the world we live in. So, I'm going to give you a few tricks that you can use to look specifically for cyber security GRC jobs.
The first one is we can look for the name of the framework. For example, I can just type NIST in the job title and I hit enter. This will give me all the jobs that have NIST in the description of the job. Not all of them are going to be GRC, but a good portion of them will be GRC jobs. Another example will be I can just look for ISO 27001. This is a framework that we've covered in our training, and chances are when you type ISO, the majority of the jobs will be GRC jobs. Another good keyword to use is "cyber security risk" and "cyber security audit."
Now, is that all of the jobs? Absolutely not. The next thing that you need to do is just type the word "cyber" and hit enter. Now, this will be time-consuming because it will give you every job that has the word "cyber" in it, and a lot of them are not going to be GRC. However, some of them will be, and trust me, those jobs that you find that have just the word "cyber" and they are GRC jobs, you will find that not many people have applied to them because they simply can't find them.
Now, as to where to look for jobs, this will depend on where you live. However, I say use LinkedIn because LinkedIn is quite universal. So chances are jobs in your city will exist on LinkedIn. Now, in addition to LinkedIn, usually there is a website that's tailored to the specific country that you live in. For example, in Australia, we have seek.com.au. In the US, there is Indeed and there is Dice. So, pick the platform that's actually relevant to where you live. I think in the UK, there is Monster Jobs and other websites. So, just find at least LinkedIn and something in addition to LinkedIn. This way, you will cover the majority of cyber security jobs.
Now, as an example, let's use LinkedIn and let's look for cyber security GRC jobs in New York. So, the first thing I'm going to do is I'm just going to type NIST. I'm going to hit enter. Let's see what we get. You go. I think the next one is a really good one. It says "Information System Security Officer." As you can see, the title is really strange. "Information System Security Officer" could mean many things. Now, when we look through the description, actually, it's a bit vague. We say, "We review systems to identify potential weaknesses." So that could be vulnerability assessment. "Manage cyber security risk. Prioritize risk. Use the NIST framework." So it does look like a GRC job. Now, it's quite normal that you see so many requirements and you feel like maybe I only know 50% or 60%. Honestly, as a rule, if you think that you qualify for 20% of what they're asking for, hit apply. You would be surprised. Job descriptions are actually a wish list. They don't want you to be an expert in all of that. So, hit apply. Worst thing that can happen, they can reject you. Do not reject yourself. Apply, and you would be surprised. I was never hired to a job where I met everything they wanted. Hit apply. Go to the interview. Demonstrate the skills and let them know that you're someone who's willing to learn. That good attitude has gotten so many people jobs. So, trust me with this one. Apply and see what happens.
Now, let's look at another example. And here I'm going to type ISO 27001. Then I hit enter and I'm filtering for jobs in New York. Again, the first one actually looks good. "Information Security Officer" in a healthcare organization. As you can see, this one actually has GRC in the job description, which is really great. And the third bullet point, it says, "Drive all activities to achieve high trust are two certifications, map controls to SOC 2, NIST, and ISO, and HIPAA." This is a really good job because some people think that ISO 27001 is a framework just for Europe or that NIST is only for the US or my country is a special snowflake and none of this apply to me. Yes, it all applies to you. Here's a little secret about cyber security frameworks: they are all the same. All these frameworks work in pretty much the same way. Therefore, when you learn one framework, your knowledge will apply to every other framework. So, in this case, it's a healthcare organization in the US, and they have a standard called HIPAA, which is a standard for healthcare in the US. Now, if you actually download the standard and read the controls, and you finish GRC Mastery, you will find that each and every control has already been covered in GRC Mastery. You will see controls that cover asset management, vulnerability management, identity and access. And you will see that the language is very similar to NIST and ISO. Therefore, again, you may feel like you don't know everything that they're asking for, but trust me, when you apply and actually go to the interview, you will be so much better than all of these candidates that come to the job with things like nothing but multiple-choice theoretical exams and low-quality Udemy classes that don't teach you anything. So, trust me with this one and apply.
But now, the big question is, what else should you do after GRC Mastery? Should you stop learning and just sleep, or should you go and chase every single training that has the word GRC in it and fill your resume with nonsense? Well, in the next part of this video, I will reveal to you the cyber security certifications that are actually relevant to GRC. But I will also tell you what cyber security GRC certifications to absolutely avoid, which is part three of this video.
GRC certifications. But before I tell you about certifications, I want you to have the mindset that you are chasing a long-term career in cyber security. This is not a get-rich-quick scheme. This is a career that you hopefully will do long-term, where you have career progression and higher salary and a much better lifestyle. Therefore, I want you to ditch the mentality that you should do the absolute minimum amount of work and expect everything to happen quickly. This is not how the world works, and this is not how you get to your goal. Instead, the mindset that you need to have, you should continue learning until you reach your goal. This way, reaching your goal will become inevitable. It's just a matter of time.
Now, the challenge is, what certifications should you do? Unfortunately, I've seen a rise in certifications that has the word GRC or G in it, but they all seem to have two things in common. Number one, they are all painfully theoretical. They'll get you to memorize things that has nothing to do with the job. In fact, when you do GRC Mastery, you will learn that there is nothing to memorize, which is really problematic. And as a hiring manager, I interview so many candidates who memorize things but fail to answer any question in the interview. But the second problem is that the cyber security GRC industry actually doesn't care about those certifications. So, you need to ask yourself that question: If doing those certifications don't teach you anything and no one cares about them in the industry, why should you waste time and money on them? You need to be a lot more strategic about your learning plan.
But before I tell you what certifications to avoid, let me tell you what certifications that will actually help you on your journey to landing your first cyber security GRC job. The really important certifications that I want you to do in addition to GRC Mastery, whether you land a job with just GRC Mastery or whether you would like to do more and continue learning beyond GRC Mastery, my first recommendation will always be the Google Cyber Security Certificate. Now, if you look at the description, you will find that actually a lot of the topics you may have learned in GRC Mastery. However, the Google Cyber Security Certificate is actually a good broad introduction to every area we touch on in cyber security. Therefore, it will be a good review for you, but it will also make sure that you actually understood everything that goes beyond GRC. It's not targeted at GRC professionals, but the knowledge is nice to have for GRC.
A quick look at the table of contents. You start with foundations, and then you talk about risks, which you will be more than familiar with because of GRC Mastery, and then it goes over network security and network protocols. We may not need that for GRC, but it's always good to go over them at least from a foundational introduction point of view, which is what the Google Cyber Security Cert is. And then it will teach you tools like Linux and SQL, and you'll even get a chance to practice this in a practical hands-on. Don't be scared. I know we don't need coding or Linux or SQL for GRC, but what they will give you here is a very, very basic introduction. So, do it. Have fun with it. Don't memorize anything, and don't freak out if you find that you don't like them because we don't actually need that for GRC. Then we go over assets, threats, and vulnerabilities, which is something that you'll be more than familiar with from GRC Mastery. And you will see that the introduction here is pretty rudimentary for someone like you who have done GRC Mastery. Then they talk about detection response and even automation with Python. Now, like I said, Python is a programming language, and yes, you will do some practical basic coding here. Don't be scared of it. And if you find it's difficult, you can simply just skip over it quickly. It's not something that you'll ever need. However, if you find that you're interested in this and you like to automate tasks, there's a very small number of GRC jobs where you could be an automation specialist, automating some GRC tasks. If that's something you want to do, go for it. However, it's definitely not a priority for someone who's targeting GRC jobs that focuses on risk management and audit. And then they show you how to search for jobs and be job-ready, which is nice to go over. And they even give you a basic introduction to AI, which is always nice to have.
Now, the good news is, when you finish the Google Cyber Security Certificate, they'll give you a 30% discount code to do CompTIA Security+. CompTIA Security+ is absolutely not a must. However, it is nice to have because it again covers everything from a foundation and definition point of view. Now, is GRC Mastery and Google Cyber Security enough preparation for the CompTIA Security+ exam? I would say no. Especially that that exam is very particular multiple-choice exams. So, you need to actually learn in a way that enables you to pass multiple-choice exams. And as you may have guessed, I'm not a fan of it. However, if you want to do something that's relevant to GRC, I think CompTIA Security+ is probably the closest thing to that. The other advantage of Security+ is that if you are a US citizen and you absolutely want to work in a government agency that's under the Department of Defense, Security+ is actually a DoD requirement. But if you want to work in the private sector, it's not required.
Now, there are many resources online that will help you pass the CompTIA Security+ exam, but what I'm about to tell you now will probably upset some people. I don't like the majority of these resources. I don't like any Udemy course that teaches you Security+ and I don't like any of those free videos that claim to give you Security+ knowledge. A, because I found that they have so many mistakes. B, I found that the instructors tend to go on tangents that have nothing to do with Security+. They give you things outside of the scope of Security+ and they actually skip things that are important in Security+. These are all a sign of a bad instructor. However, the best resource that I found, which is surprisingly the one that I used in 2006 when I passed my Security+, is the Sybex book. Strangely so, it remains the best resource out there. So, have a look at the Sybex book. I will leave a link to it in the description box below. And the good thing about this book is that it actually includes practice exams. So, you don't need to look anywhere else. Go through the book. Go through the multiple-choice exam practice. Once you're confident, go ahead and take the Security+ exam. But the good news is, when you do it after the Google Cyber Set and after GRC Mastery, you will not be just memorizing things just because. No, you will have that practical perspective that actually makes a lot of these topics make sense, so you're not just bluntly memorizing.
Now, the next certification that I actually recommend is one that most people tend to skip, which is the Microsoft Cyber Security Analyst Certificate. And the important reason why I want you to do it is because it actually covers the Microsoft Azure cloud, which is a really, really important piece of technology that you will 100% run into in any cyber security job, including GRC. So, it's really important to have at least an introduction to the Azure cloud. Now, I'm not going to go over every topic for the Microsoft Cyber Analyst Set. I'll leave a link to it in the description box below along with all the other resources. However, just like the Google Cyber Security Set gave you a discount with CompTIA Security+, the Microsoft Cyber Analyst will actually give you a discount for the Microsoft exam SC900, which is the Microsoft Security, Compliance, and Identity Fundamentals. This is probably the closest thing that Microsoft has to a GRC, and it will teach you things from the perspective of Microsoft cloud technologies, which is a focus on a certain vendor, which is really good because it will give you a chance to bring the fundamental things that you've learned in GRC Mastery into the Microsoft cloud. You will also get a practice exam with the Microsoft Cyber Analyst Set for the SC900. This way, by the end of it, you actually have four additional qualifications to add to your resume. You've got the Google Cyber Set, CompTIA Security+, Microsoft Cyber Analyst, and SC900. This will be a resume that's actually targeted and focused on GRC jobs, and it will definitely make you stand out from the majority of entry-level candidates who come to me with CompTIA A+, Network+, and Security+ without knowing anything practical. You will definitely stand out.
Now, as for the resume, I will actually add four bullet points for each of these certificates because these are certificates where people will just look for the name of the certificate. So, they'll look for Microsoft Azure or they look for Security+. So, you don't actually need to elaborate too much on the things that you've learned in these certificates. So, this is how I will have them in the resume as bullet points, and when you download the resume, this will all be ready and done for you.
But now, the question that all of you may be asking, what about these additional GRC certificates? There is GRCP and OIG and BIG and G. Some, please do not waste any time or money on this nonsense. These are highly theoretical exams that have nothing to do with reality, and these big companies are certification factories, and they just want to print anything and call it GRC. I have yet to see anyone who benefited from these certifications because A, they teach you nothing practical, and B, as industry practitioners and as hiring managers, when we see them on resumes and we ask basic, basic questions to candidates, they actually fail to answer them. Therefore, they actually have a really bad reputation in the industry. So, please don't waste your time.
Now, if you're someone with five years of experience in the industry and you want to add more GRC stuff, then look into something like ISACA CISA or ISACA CISM or even something like (ISC)² CISSP. Now, none of those are actually GRC specific. However, if you're bored and you have extra time and you just want to do things just because, then I'd rather you do these certificates than go through the rabbit hole of OIG and BC and GIP and all of these G+ certificate names that will teach you nothing. This also goes for platforms like Udemy and Cybrary and all of that stuff that's historically low in quality and it's just a flat-out waste of time.
Now, by this step, a lot of you would have landed your first cyber security GRC job. But whether you landed your first cyber security GRC job or you're still learning in order to land your first cyber security GRC job, the question is, what is the thing that will slow you down as a cyber security GRC professional or as someone who's still learning in order to land your first cyber security GRC job? Is it the lack of search? Now, the answer is not what you think. Picture this. You are a cyber security GRC professional, and you were given a task of conducting a cyber security risk assessment on an application, but that application lives in Amazon AWS cloud. With the knowledge that you've gained from GRC Mastery, you'll actually know how to perform the risk assessment, what to look for, what questions to ask, and what to document. But if you want to take it a step further and become the absolute expert on the topic, then the thing that will actually make you a more efficient cyber security GRC professional is more knowledge of cloud technologies. You see, after GRC Mastery, you don't need more GRC knowledge, but it's a great idea to have more technical knowledge. Therefore, in the next part, I will give you a list of cyber security training that you can do that will make you a much more efficient cyber security GRC professional, but it will also open more doors for you as you're trying to land your first cyber security job, which is part four of this video.
Technical skills for GRC. Now, first, we need to define what we mean by technical. Yes, GRC is a non-technical cyber security job in the sense that the GRC professional is not the person who configures the firewall. They are also not the person who performs the malware reverse engineering. However, they are expected to know what a firewall does and why we need it in an organization. They also need to know why we need malware analysis and how it fits within an overall cyber security program. Therefore, the more technical knowledge you have, the more effective of a cyber security GRC professional you will be. So, let me take you through additional cyber security training that will make you unstoppable.
Now, these are the certificates that I would do even after I land my GRC job because these will be complimentary to my GRC skills. And the first area that I will look into is the cloud. So, we have Microsoft Azure and Amazon AWS. You don't need to become a cloud engineer. However, the basic introduction to cloud technology is usually good. So, from Microsoft Azure, I will look at the Microsoft Azure Fundamentals. And from Amazon AWS, I would be looking at the Amazon AWS Cloud Practitioner. I don't necessarily need to go all the way to something like an Amazon AWS Security Specialty unless you want to become a security engineer or a cloud security engineer. This is not really required for GRC professionals. Now, I know some GRC professionals go all the way and do all the cloud certificates. That would be a personal choice for you. However, I would personally stick to just the basic introduction to cloud security to cover all my bases as a cyber security GRC professional.
Now, the next step from there, and I want to stress that it's absolutely optional, is adding SOC analyst skills. SOC analyst, or Security Operations Center analyst, or cyber analyst, is really the technical individual who analyzes and responds to cyber security incidents. Now, this is a highly technical role. It's definitely not a GRC role. But if you want to learn something technical, or if you want to learn additional things instead of wasting time on random GRC stuff, then I'd rather you learn something that could actually open more doors for you. Now, there are so many platforms to learn the skills of a SOC analyst. So, the platform that I recommend is LetsDefend, or also you could use TryHackMe. From LetsDefend, you can pick the SOC Analyst pathway, and from TryHackMe, you can pick the SOC 1 pathway. Both are valid, both are highly practical, and they will give you more than enough knowledge that you will need as a cyber security professional, and you may even land a job as a generalist where you will be performing GRC tasks alongside some SOC analyst tasks, but really basic, because the focus of the resume here is GRC, and this is how I will add it to my resume. It will be a simple bullet point that showcases some of the tools and some of the things that I learned from the pathway.
And now, if you actually follow everything that I've said in this video, you will not only qualify for cyber security GRC jobs, you will actually qualify for so much more. You see, small to medium-sized organizations, they can't usually afford specialists. Therefore, they're looking for someone who's more of a generalist, meaning they can perform more than one task. They can perform risk assessment, they can perform auditing, but they can also respond to a phishing attack or even be a SOC analyst to some extent. But as a priority, if you're trying to land your first cyber security GRC job or any cyber security job and you have no technical skills or any technical background whatsoever, the absolute best starting point for you is GRC Mastery. So, go to grcmastery.com and start your learning journey.