Fourth Tech GRC Cybersecurity Bootcamp
The full 9-module program: from zero to job-ready GRC analyst. Read, practice, get graded.
Tuition
$2,000
Beginner
Level
9
Modules
39
Lessons
9
Graded quizzes
9
Assignments
45 hours
Estimated time
What you will be able to do
- Explain GRC vocabulary and concepts in plain English
- Build a risk register and apply risk treatment decisions
- Categorize a system with FIPS 199 and author SSP control statements
- Test a control using Examine / Interview / Test and write findings in the 5 Cs
- Run a vendor assessment with tiering and due-diligence questionnaires
- Read a SOC 2 Type II report like a working analyst
- Write a Statement of Applicability aligned to ISO 27001:2022
- Deliver interview-ready STAR answers for entry-level GRC roles
What is inside
9 modules, 39 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Foundations of Cybersecurity & GRC
What cybersecurity actually is (not the movie version), what GRC means, and what a GRC Analyst really does Monday to Friday. You will meet Honeycomb Bakery, the fictional company we return to all course long, and learn the core vocabulary that every audit conversation is built from.
4 lessons · 18 quiz questions · assignment
- 02
Compliance & Frameworks Overview
Meet the 9 frameworks every GRC Analyst sees on job adverts: NIST CSF 2.0, ISO 27001, NIST RMF, SOC 2, UK/EU GDPR, PCI DSS, HIPAA, Cyber Essentials with NIS 2, and DORA. Learn to tell a framework from a law from a policy, drill the comparisons interviewers love, and build the one-page cheat sheet you will reference for the rest of the bootcamp.
5 lessons · 18 quiz questions · assignment
- 03
NIST RMF Part 1: Categorize, Select, Risk
The NIST Risk Management Framework, end to end. You will walk all seven steps from Prepare to Monitor, score a real system with FIPS 199 and the high-water mark, build a risk register with proper vocabulary, and write SSP control statements in the six-element shape that assessors can actually test.
4 lessons · 18 quiz questions · assignment
- 04
RMF Part 2 & IT Auditing
This module puts you in the assessor seat. You will learn the difference between an assessment and an audit, plan control tests using Examine, Interview and Test, judge evidence with the IOIR hierarchy and the four tests of evidence, and write findings in the 5 Cs format that feed a Security Assessment Report.
4 lessons · 18 quiz questions · assignment
- 05
Contingency, Incident Response & Continuous Monitoring
Bad days happen: power cuts, floods, ransomware. This module teaches you how organisations prepare for them and recover from them: contingency planning (CP-2) and testing (CP-4), the BIA with RTO and RPO, the BCP/DRP/ITCP triangle, backup strategy, the incident response lifecycle (IR-2), POA&M discipline, the four ATO outcomes, and continuous monitoring (CA-7).
5 lessons · 18 quiz questions · assignment
- 06
Third-Party Risk Management & Reading a SOC 2
For five weeks you assessed controls on systems your own organisation owns. This week the controls live on someone else's infrastructure. You will learn the 5-stage TPRM lifecycle, how to tier vendors so your effort matches the risk, and how to read a SOC 2 Type II report the way an auditor does: opinion, scope, exceptions, CUECs, carve-outs and bridge letters.
4 lessons · 18 quiz questions · assignment
- 07
ISO 27001 Part 1: ISMS & Statement of Applicability
For six weeks you have been learning the pieces: risk registers, controls, audits, vendors. This week the pieces get a home: the ISMS. You will learn what ISO 27001:2022 actually requires (Clauses 4-10), how the 93 Annex A controls are organised into 4 themes, and how to write the single most important ISMS document, the Statement of Applicability, at a standard an auditor would accept.
4 lessons · 18 quiz questions · assignment
- 08
ISO 27001 Part 2: Audit, Certification & CAPA
Last module you built the ISMS. This module you find out how someone checks it. You will learn how internal audit works under Clause 9.2, how the Stage 1 and Stage 2 certification audits run, how findings are classified, and how to write a CAPA that separates correction from corrective action using 5-whys. You finish by closing three findings from a fictional Honeycomb Bakery Stage 2 audit.
5 lessons · 18 quiz questions · assignment
- 09
Capstone, Interviews & Launching Your Career
Graduation week. You assemble the eight artefacts you built across this bootcamp into one coherent portfolio, script the 5-minute capstone walkthrough that gets you hired, drill the top 10 GRC interview questions with STAR discipline, and leave with a 90-day plan, a LinkedIn position, and a weekly job-search cadence. The module quiz is the cumulative final exam.
4 lessons · 20 quiz questions · assignment