Module 0 - Lesson 3 - PolicyWizard career roles

Module 0 - Lesson 3 - PolicyWizard career roles

In this lesson, we're going to look at typical career paths within GRC. Remember that no two routes are the same, your journey through the industry will look very different to mine.

Starting off, we have four entry options that are named differently, but we'll be doing very similar tasks.

A policy writer will spend most of their time collaborating and hosting policy change review meetings. They will often help within other areas of GRC, such as audit management and security awareness training. We will cover this rule in more depth during module 1.

The next three rows typically carry out the same task but are named differently. They will focus on all areas of GRC, carrying out tasks in governance such as policy writing, risk management, and evidence gathering to meet compliance requirements.

Duties might include Security Awareness Training, running phishing simulations, and carrying out remediation of suspicious emails. The roles are Information Assurance Analyst, Information Security Specialist, and GRC analyst.

As you gain experience and knowledge within the field, you might receive a promotion to senior GSE analyst. You will have more focus on one or two specific areas, but you might have knowledge of all three within GRC. You may be required to lead others within the team and provide advice and guidance to the junior members.

An Information Security Auditor typically specialises after a couple of years in GRC. They must have the soft skills to interact with people at all levels of business and have the knowledge to understand the requirements of the framework and the technical understanding to realize when something does not meet the standard.

As a security manager, you will lead a team of Junior and Senior Analysts, to ensure the focus areas are worked on. You have to understand the roles of your team members and provide advice where required. You have all the usual admin tasks that a manager has, but you will also be expected to carry out security tasks. You are a team member before you are the manager. 

As a director of Security or head of GRC, you are the puppet master for all members of your team. You'll provide expert advice where required and might deputize for the CISO when they are unavailable. 

As a Virtual CISO, you'll contract for a period, to provide expert advice to businesses that may not be able to afford a full-time CISO.

Or as a full-time CISO, you're not carrying out security-related tasks. You're more business strategy focused and ensure the security team is working with the goals of the business in mind. You'll spend most of your time in meetings with clients and other business executives. You'll work closely with the Director of Security to maintain your security strategy within the team and the business goals and your risk appetite.

The CISO is the pinnacle of the GRC career path.

Security Policy Foundations

Buy nowLearn more

Introduction - 25 minutes of free video!

  • Module 0 - Lesson 1 - PolicyWizard course introduction6
  • Module 0 - Lesson 2 - PolicyWizard instructor introduction3
  • Module 0 - Lesson 3 - PolicyWizard career roles16
  • Module 0 - Lesson 4 - PolicyWizard Qualifications & Certifications11
  • Module 0 - Lesson 5 - PolicyWizard Experience Wall6
  • Module 0 - Lesson 6 - PolicyWizard Side Hustles10
  • Module 0 - Lesson 7 - PolicyWizard Pay-it-forward promise4
  • Introduction review

Module 1 - Security Policy Foundations - 52 minutes of video!

  • Module 1 - Lesson 1 - What is Security Risk?19
  • Module 1 - Lesson 2 - What is Security Policy?4
  • Module 1 - Lesson 3 - Human Risk Management9
  • Module 1 - Lesson 4 - Security Controls & Policy4
  • Module 1 - Lesson 5 - Types of Policy10
  • Module 1 - Lesson 6 - Policy Lifecycle10
  • Module 1 - Lesson 7 - Writing styles23
  • Module 1 - Lesson 8 - Security Policy Considerations5
  • Module 1 - Lesson 9 - Policy Writer & Management Roles23
  • Module 1 - Practical Labs3
  • Module 1 - Lesson 10 - Thank you!23
  • Please review the course!4
  • Course Quiz

Webinar

  • CyBlack Talk Jul 23.mp4

17 Slide decks!

  • Module 0 - Lesson 1 - PolicyWizard course introduction.pdf
  • Module 0 - Lesson 2 - PolicyWizard instructor introduction.pdf
  • Module 0 - Lesson 3 - PolicyWizard career roles.pdf
  • Module 0 - Lesson 4 - PolicyWizard Qualifications & Certifications.pdf
  • Module 0 - Lesson 5 - PolicyWizard Experience Wall.pdf
  • Module 0 - Lesson 6 - PolicyWizard Side Hustles.pdf
  • Module 0 - Lesson 7 - PolicyWizard Pay-it-forward promise.pdf
  • Module 1 - Lesson 1 - What is Security Risk.pdf
  • Module 1 - Lesson 2 - What is Security Policy.pdf
  • Module 1 - Lesson 3 - Human Risk Management.pdf
  • Module 1 - Lesson 4 - Security Controls & Policy.pdf
  • Module 1 - Lesson 5 - Types of Policy.pdf
  • Module 1 - Lesson 6 - Policy Lifecycle.pdf
  • Module 1 - Lesson 7 - Writing styles.pdf
  • Module 1 - Lesson 8 - Security Policy Considerations.pdf
  • Module 1 - Lesson 9 - Policy Writer & Management Roles.pdf
  • Module 1 - Practical Lab - Acceptable Use Policy.pdf