⚖️ GRC / Risk & Compliance
Cybersecurity career path
Run governance programmes, manage risk and keep the organisation compliant.
Typical roles
- GRC Analyst
- Risk Manager
- Compliance Lead
Suggested certifications, by phase
Foundation
Core
- CGRC (ISC)2 Certified in Governance, Risk and Compliance
- PECB 27001LI PECB ISO/IEC 27001 Lead Implementer
- GRCP OCEG Governance, Risk, and Compliance Professional
Advanced
- CRISC ISACA Certified in Risk and Information Systems Control
- CISA ISACA Certified Information Systems Auditor
- GSLC GIAC Security Leadership Certification
Mastery
- CISM ISACA Certified Information Security Manager
- CISSP (ISC)2 Certified Information Systems Security Professional
A suggestion, not a set of prerequisites — one or two certifications per phase is plenty.