GRC Training Options - Training for a Governance, Risk, and Compliance (GRC) Career in Cybersecurity

Ken Underhill - Cybersecurity Training
19 Jan 202406:57

Summary

TLDRThe video discusses GRC (Governance, Risk, and Compliance) training options for those interested in entering the field. It highlights a training bundle from EC-Council covering security risk management and frameworks like NIST RMF. The speaker emphasizes the importance of connecting theoretical knowledge to real-world scenarios by creating case studies based on actual companies' challenges. He also mentions another GRC masterclass and offers advice on showcasing skills on LinkedIn and in interviews. The video provides affiliate links for discounted training but encourages using free resources if on a budget.

Takeaways

  • πŸ“š GRC (Governance, Risk, and Compliance) is a popular career field, and many viewers are interested in related training.
  • πŸ“– Jerry's GRC Masterclass is recommended, and it might still be available for free or at a nominal fee.
  • πŸ’Ό EC Council offers training on security risk management, including three courses covering the fundamentals of risk management, auditing, and frameworks like NIST RMF.
  • πŸ”— The speaker advises using training to learn fundamentals and then applying this knowledge to real-world scenarios, such as analyzing case studies from companies.
  • πŸ’‘ Building your own case studies from company examples can demonstrate practical knowledge and help with job applications, especially on platforms like LinkedIn.
  • πŸ’» Practical application of training is key for getting noticed by hiring managers, who are more impressed by those who can 'connect the dots' between training and real-world use cases.
  • πŸ“Š Certifications and degrees are helpful, but connecting theoretical knowledge to practical experience can make a candidate stand out even more.
  • 🎯 The speaker emphasizes that many job listings are automated or fake, so it's important to focus on building skills and showcasing them instead of mass job applications.
  • πŸ’Ό The speaker is an EC Council affiliate, and any purchases through their links offer a discount, typically around $79 (compared to $200), though prices may vary by region.
  • 🀝 The speaker uses affiliate income to support community initiatives like providing scholarships and sending people to conferences, rather than for personal luxury.

Q & A

  • What is the primary focus of the video?

    -The video focuses on GRC (Governance, Risk, and Compliance) training opportunities for individuals seeking to enter the GRC field, including courses and strategies to enhance job prospects.

  • What training does the speaker recommend for learning GRC fundamentals?

    -The speaker recommends a bundle of three courses from EC Council that cover the fundamentals of security risk management, auditing, and the application of frameworks like NIST RMF. Additionally, they mention Jerry aer's GRC master class as another useful resource.

  • What advice does the speaker give for applying the knowledge from GRC training?

    -The speaker suggests applying the knowledge gained from GRC training to real-world scenarios by studying case studies of companies you want to work for, creating hypothetical solutions for their challenges, and sharing this work on platforms like LinkedIn.

  • Why does the speaker emphasize 'connecting the dots' in the job application process?

    -The speaker believes that being able to apply learned knowledge to real-world situations and demonstrating this understanding to potential employers is crucial. They argue that connecting theoretical knowledge to practical scenarios is often more valuable than having numerous certifications or degrees.

  • What is the benefit of using the speaker’s affiliate link for the EC Council training?

    -Using the speaker’s affiliate link provides a discount on the EC Council training, reducing the price from around $200 to $79 for U.S. customers. The speaker also mentions that the earnings from the affiliate link help fund scholarships and other opportunities for the community.

  • How does the speaker suggest showcasing the knowledge gained from GRC training?

    -The speaker recommends showcasing knowledge by creating case studies, applying the learning to real or hypothetical company scenarios, and then sharing these examples on social media platforms, especially LinkedIn, to attract the attention of hiring managers.

  • What is the significance of case studies according to the speaker?

    -Case studies are significant because they provide real-world examples of how companies solve security challenges. The speaker advises using these to demonstrate the application of learned concepts and to help connect theoretical knowledge to practical, real-world problems.

  • What alternative does the speaker offer for those who may not have the budget for paid courses?

    -For those who cannot afford paid courses, the speaker suggests utilizing free content like YouTube videos to learn GRC fundamentals and then applying this knowledge in the same way as with paid coursesβ€”by creating case studies and demonstrating practical understanding.

  • What does the speaker say about the job market and hiring process in cybersecurity?

    -The speaker highlights that many job listings are not real (referred to as 'fake jobs') and emphasizes that showcasing practical knowledge and the ability to connect concepts to real-world applications is more effective in getting interviews than blindly applying to numerous jobs.

  • Why does the speaker recommend fixing your LinkedIn profile?

    -The speaker advises fixing your LinkedIn profile to better showcase your skills, knowledge, and ability to apply GRC concepts. A well-optimized LinkedIn profile can help make a strong impression on hiring managers and improve the chances of landing interviews.

Outlines

00:00

πŸ“š GRC Training Overview and Resources

The speaker introduces the topic of Governance, Risk, and Compliance (GRC) training, emphasizing its importance for those interested in a career in GRC. They mention popular videos on the channel that focus on GRC and recommend Jerry Aer's GRC Master Class, which might still be free or available for a nominal fee. Additionally, they highlight a training bundle from EC Council, which includes three courses related to security risk management, fundamentals of auditing, and organizational risk management. The speaker discusses the importance of applying this knowledge in practical ways by studying real-world case studies from companies like Splunk or eSentire, suggesting that learners create hypothetical case studies based on what they have learned to demonstrate their ability to apply GRC concepts in a professional context.

05:00

πŸ’‘ How to Leverage GRC Training for Job Applications

The speaker continues by advising viewers on how to maximize the benefits of GRC training for career advancement. They suggest showcasing knowledge gained through these courses on LinkedIn, resumes, and during job interviews. Emphasizing the value of connecting theoretical knowledge to real-world applications, the speaker advises learners to create case studies from their training and use them as portfolio pieces. The focus is on demonstrating one's ability to solve real problems, which can impress hiring managers even if the candidate doesn't meet every qualification listed on the job description. This strategy is portrayed as a more effective way to stand out compared to simply collecting certifications.

Mindmap

Keywords

πŸ’‘GRC

GRC stands for Governance, Risk, and Compliance. It encompasses the practices and tools used to ensure that an organization meets its legal and regulatory obligations while managing risk and ensuring governance processes are in place. In the video, the speaker emphasizes that many viewers are interested in GRC and are seeking employment in this field, making it a focal point of the discussion.

πŸ’‘Risk Management

Risk management involves identifying, assessing, and controlling threats to an organization's capital and earnings. This concept is essential for GRC professionals, as it helps protect organizations from uncertainties and vulnerabilities. The video mentions fundamental training around security risk management, suggesting it as a critical skill for those starting in the GRC field.

πŸ’‘EC-Council

EC-Council is a global leader in cybersecurity certification, including the Certified Ethical Hacker (CEH) and other security-related training programs. The video discusses an EC-Council training bundle focused on security risk management, which provides foundational knowledge for those interested in the field. The speaker also mentions being on their Global Advisory Board, highlighting their connection to the organization.

πŸ’‘Certification

Certifications, such as those offered by EC-Council, validate an individual's expertise in specific areas, like ethical hacking or risk management. In the video, the speaker talks about different certifications that can help viewers enter the GRC field, emphasizing the importance of having certified skills to improve job prospects.

πŸ’‘Jerry Aer's GRC Master Class

This is a specific training course mentioned in the video, aimed at providing comprehensive knowledge in the GRC domain. The speaker suggests this as a valuable resource for viewers wanting to start their GRC journey, noting that it was previously free but might now have a nominal fee.

πŸ’‘Fundamentals

Fundamentals refer to the basic principles and concepts in a given field. The speaker stresses the importance of learning the fundamentals of GRC and risk management to build a solid foundation before applying these skills to real-world scenarios. This includes understanding frameworks like NIST RMF (Risk Management Framework) and applying them to practical cases.

πŸ’‘Case Studies

Case studies are real-world examples used to illustrate how theories and methods are applied in practice. The speaker advises viewers to study case studies of companies they want to work for and create their own hypothetical case studies to demonstrate their knowledge and application skills. This strategy can be a powerful tool in job applications and interviews.

πŸ’‘NIST RMF

NIST RMF stands for the National Institute of Standards and Technology's Risk Management Framework. It provides guidelines for managing and reducing cybersecurity risk. The video mentions this framework as part of the training content, which helps professionals understand and implement risk management practices in their organizations.

πŸ’‘LinkedIn

LinkedIn is a professional networking platform where individuals showcase their skills, experiences, and professional achievements. The speaker encourages viewers to post their learning outcomes and case studies on LinkedIn to attract potential employers and demonstrate their ability to connect theoretical knowledge with real-world applications.

πŸ’‘Affiliate Link

An affiliate link is a URL that tracks sales or traffic generated by someone promoting a product or service. The speaker discloses that they use affiliate links for EC-Council training, which means they earn a small commission on sales made through those links. They clarify that these commissions help fund community initiatives, such as providing scholarships, rather than personal gain.

Highlights

Discusses GRC-related training options for those seeking jobs in the GRC field.

Mentions Jerry Aer's GRC Master Class as a recommended training resource.

Highlights the benefits of EC Council's training bundle focused on security risk management fundamentals.

Emphasizes the importance of understanding fundamental concepts like risk management and auditing for aspiring GRC professionals.

Encourages learners to create their own case studies based on real-world companies they want to work for, using knowledge from the training.

Advises using case studies to showcase the ability to apply GRC concepts to real-world scenarios on platforms like LinkedIn and resumes.

Highlights the EC Council's courses as a valuable resource for understanding frameworks like NIST RMF.

Clarifies that the provided link is an affiliate link and that discounts are available for the training bundle.

Encourages investing in training if it fits within one's budget, but warns against spending excessively or taking loans for it.

Mentions potential price variations based on geographic location for EC Council courses.

Stresses the importance of connecting the dots between training and real-world applications to stand out in job applications.

Describes the significance of showcasing practical application of skills rather than just listing certifications or degrees.

Suggests utilizing hypothetical case studies as a way to demonstrate problem-solving skills and industry knowledge.

Mentions the importance of a well-optimized LinkedIn profile and provides guidance on finding relevant resources on their channel.

Encourages engaging with the community and sharing insights gained from training on social media platforms.

Transcripts

play00:02

hey everyone in this video I just want

play00:03

to talk about some GRC related training

play00:06

I know a lot of you um like GRC you're

play00:08

trying to get a job in the GRC realm in

play00:10

fact those are some of the most popular

play00:11

videos on this channel so in addition to

play00:14

Jerry aer's GRC master class which I'll

play00:16

put in the description below as well

play00:18

link to that and I think his course is

play00:19

still free but he may be charging a

play00:22

nominal fee for that but anyways it'll

play00:23

be a link um so that Link's not an

play00:25

affiliate link this this uh training

play00:27

here is from EC console so if any of you

play00:30

ever heard of the certified ethical

play00:31

hacker examination or the c um that's

play00:34

one of the many certifications that EC

play00:35

Council offers I sit on their Advisory

play00:38

board for the ethical hacking stuff

play00:39

their Global Advisory Board um it's a

play00:42

volunteer thing and they don't pay me

play00:43

any money for that um however they do

play00:45

have this kind of uh fundamental for

play00:47

those of you kind of starting out out

play00:48

there they have this fundamental

play00:49

training around uh security risk

play00:51

management and so you basically get

play00:53

three courses in this uh you know 10

play00:55

plus hours whatever um but basically

play00:57

kind of walks you through some of the

play00:58

fundamentals of risk management

play00:59

fundamentals of auditing things like

play01:01

that kind of understanding really that

play01:03

top level view for organizations why

play01:06

would you care about you know going

play01:07

through a training like this um first

play01:09

off it will help you kind of you know of

play01:11

course get the fundamentals down right

play01:13

some of the basic stuff in addition to

play01:14

that you can then take what you've

play01:16

learned here grab an example from like

play01:19

the company you want to work at like

play01:20

let's say for example um there uh let's

play01:24

just say Splunk right very easy one uh

play01:27

basically Sim solution they've got a

play01:28

variety of things but basically simu

play01:30

solution or you know what let's do eent

play01:32

tire with your their xdr MDR Solutions

play01:34

so basically they're they they host

play01:36

based Solutions right so

play01:37

anyways let's say that you want to work

play01:39

at e sentire so what you do take

play01:42

training like this or Jerry AZ or do it

play01:44

on your own whatever you want to do but

play01:46

then once you got the fundamentals down

play01:48

then go look at some of the case studies

play01:50

on East cti's website for clients

play01:53

they've worked with and how they've

play01:54

helped them and then build your own case

play01:56

study with a hypothetical company

play01:58

showing that you can actually apply all

play02:00

this stuff that you're learning from you

play02:02

know these various courses you've gone

play02:03

through and then that is the type of

play02:05

stuff that you show on like LinkedIn you

play02:07

talk about in your resume if you get an

play02:09

interview with a place you talk about it

play02:11

in that interview right that's what we

play02:13

talk about especially myself when I talk

play02:15

about you need to connect the dots you

play02:17

need to connect what you're learning to

play02:19

the real world that's how you do that

play02:20

stuff but it all starts with

play02:22

understanding some of the fundamentals

play02:24

and this is just one way that you can

play02:26

learn the fundamentals with this

play02:27

training from EC Council now full

play02:28

disclaimer am an EC Council affiliate so

play02:31

any links I share out for them I get a

play02:34

few bucks on the back end if I ever get

play02:36

enough to buy a yacht I'll invite all of

play02:38

you to the yacht party but um let's be

play02:40

realistic it's an affiliate stuff uh

play02:42

it's not going to be trillions of

play02:43

dollars or anything like that but the

play02:45

good news for you because I'm an

play02:46

affiliate you basically get it's a

play02:48

roughly half off or so there you you get

play02:50

it for about $79 us and it's normally

play02:53

about $200 us so um again this this

play02:57

particular bundle comes with three

play02:58

courses around essentially risk

play03:00

management and understanding how to

play03:02

apply uh frame Frameworks like nist RMF

play03:07

to actual like use cases right so again

play03:11

don't look at this training essentially

play03:13

as like the Holy Grail like oh I just

play03:14

got to do this what I want all of you to

play03:16

do if you decide to invest in this

play03:17

training and a link will be right below

play03:20

in the description but if you decide to

play03:21

invest in it take the training the

play03:23

knowledge that you've gained and then go

play03:25

find a real company you want to work at

play03:27

look at their case studies from their

play03:28

marketing team of ask clients they've

play03:30

helped and then figure out how you can

play03:32

plug in what you've learned into that

play03:34

and that helps you connect the dots

play03:36

that's that's kind of that magical

play03:39

formula that helps you not have to have

play03:41

a bunch of certifications and not have

play03:43

to have a bunch of college degrees and

play03:45

all this other stuff that everybody else

play03:46

collects you can literally just show hey

play03:48

look I understand how to connect the

play03:49

dots and you're much more likely to

play03:51

actually get an interview than all these

play03:53

other people applying to thousands and

play03:55

thousands of jobs right and by the way

play03:56

like half the jobs out there are fake

play03:58

anyway so you spend all this time doing

play03:59

all that when you could just learn the

play04:01

fundamentals apply to the real world

play04:03

show that on social media especially

play04:05

LinkedIn talk about here's you know I

play04:07

learned this in this training and I

play04:09

decided to take this case study and

play04:11

here's you know I created a fictitious

play04:13

Healthcare company for example unless is

play04:15

a problem they were struggling with and

play04:17

this is how I you know I would help them

play04:19

solve that that is huge for a hiring

play04:22

manager unless you're an idiot but for

play04:23

most hiring managers out there they're

play04:25

not idiots that's why they're a hiring

play04:26

manager in a management position um and

play04:29

so that's really powerful at least

play04:31

especially for myself like if I'm hiring

play04:34

and I see somebody that can connect the

play04:35

dots even if they don't have all the

play04:37

check boxes in the job description for

play04:39

skills and CTS and all the other crazy

play04:41

things we all want to gatekeep with if

play04:44

they can connect the dots they're 99% of

play04:46

the way there in my mind right I just

play04:48

got to train them a little bit for my

play04:50

particular company and the particular

play04:51

problems that we're trying to solve so

play04:52

anyways all that being said um I will

play04:55

link two trainings below one is going to

play04:57

be Jerry aer's training again I don't

play04:59

know if it's still still free or not but

play05:00

it used to be a free JC Master Class

play05:02

many of you might have already taken it

play05:04

and then I'm also going to put my um

play05:06

again it's an affiliate link full

play05:07

disclaimer so if you don't want to click

play05:08

my affiliate link um your security

play05:11

people you should know how to remove an

play05:13

affiliate link from a URL uh if not just

play05:15

let me know but anyways anything I earn

play05:17

through that just really supports me um

play05:19

getting people like try hack me vouchers

play05:21

and scholarships and paying for people

play05:22

to go to conferences and all all these

play05:24

other things that you all see me doing

play05:25

or sometimes you don't even know I'm

play05:26

doing behind the scenes um so that's

play05:28

really I'm like I said I'm not going to

play05:30

buy a yacht with this stuff so anyways I

play05:32

digress the link for this will be below

play05:34

but definitely something worth checking

play05:35

out if you have it in your budget uh

play05:37

don't go like take out a loan at the

play05:39

bank to buy this that's silly right you

play05:41

can you know you can take like free

play05:43

content or YouTube videos and kind of

play05:45

craft it yourself um but if you've got

play05:48

the budget here for this uh again $79 us

play05:51

um and I don't know they pricing in

play05:52

other countries if you open up this URL

play05:54

it could it might give you less a lower

play05:56

price based on where you are I don't

play05:58

know if they have that um set up with

play06:00

EAS console or not so um it could be

play06:03

cheaper you might see it as a cheaper

play06:04

price based on where you are or it might

play06:06

be that same price across the board um

play06:08

they are a global organization so again

play06:10

they might have it a lower price

play06:12

elsewhere but basically again you get

play06:13

these three courses here walk you

play06:15

through some of the fundamentals and

play06:16

then what I want all of you to do though

play06:18

if you decide to invest in this training

play06:20

and or if you go through Jerry's

play06:21

training is actually go apply it like

play06:24

because you want to be in GRC show that

play06:27

on social media show how you can

play06:28

actually connect the dots apply it to

play06:30

the real world and that's going to help

play06:32

you quite a bit of course you need to

play06:34

fix your LinkedIn profile which I've

play06:35

already got videos about how to do that

play06:37

here on this channel just search for

play06:39

LinkedIn and it should pull up for you

play06:41

so anyways check Below in the

play06:42

description of this video you'll find

play06:43

all the links you need let let me know

play06:45

in the comments if you have any trouble

play06:47

with links or if you have additional

play06:49

questions around um either GRC related

play06:51

careers or cyber security careers in

play06:55

general

Rate This
β˜…
β˜…
β˜…
β˜…
β˜…

5.0 / 5 (0 votes)

Related Tags
GRC trainingCybersecurityRisk managementEthical hackingCareer tipsEC CouncilJob preparationCertificationsLinkedIn profileCase studies