Infosec GRC Analyst Training

Build cybersecurity governance skills without a coding background. Learn how to assess risk, evaluate controls, identify compliance gaps, and create a NIST Cybersecurity Framework gap analysis you can discuss with employers.

Course Snapshot

Format Tuition Access Begins Schedule Focus
On-Demand
Optional Mentored Office Hour
Online Capstone Presentation
$2,190 Next session:
Dates to be announced
Future session dates
will be announced soon.
Cybersecurity risk, controls, compliance, NIST CSF gap analysis, and risk reporting

Join the Interest List

Course Overview

Infosec GRC Analyst Training prepares learners for cybersecurity governance, risk, and compliance roles. You will learn how professionals assess controls, evaluate compliance gaps, and turn findings into business recommendations.

The course focuses on the governance side of cybersecurity. You do not need coding experience to begin. You will practice the language, frameworks, and analysis skills that help organizations understand and reduce risk.

Each participant completes a NIST Cybersecurity Framework v2 gap assessment and produces a professional cybersecurity risk analysis report.

Skills You'll Gain

By the end of this course, you will be able to:

  • Conduct structured cybersecurity risk assessments.
  • Evaluate organizational security controls.
  • Identify compliance gaps and recommend practical remediation steps.
  • Communicate cybersecurity risk to technical and non-technical stakeholders.
  • Differentiate among information security frameworks, standards, and regulations.
  • Use common information security terminology to explain risk.
  • Conduct a NIST Cybersecurity Framework v2 gap assessment.
USF Bull Statue

Tools and Details

Tools You'll Use

  • NIST Cybersecurity Framework v2.
  • Gap assessment process.
  • Cybersecurity risk assessment report structure.
  • Control evaluation methods.
  • Governance, risk, and compliance terminology.
  • AI and Zero Trust Architecture concepts.

Topics You'll Cover

  • Information security fundamentals.
  • CIA triad: confidentiality, integrity, and availability.
  • Information security frameworks, standards, and regulations.
  • Security controls and compliance gaps.
  • Cybersecurity risk communication.
  • Roles and responsibilities of information security stakeholders.
  • NIST Cybersecurity Framework v2 gap assessment.

What You'll Walk Away With

  • A completed NIST Cybersecurity Framework gap analysis.
  • A professional cybersecurity risk analysis report.
  • Documented evidence of applied governance work.
  • Language and artifacts you can present in interviews.
  • Stronger confidence explaining cybersecurity risk in business terms.

Who Should Enroll

  • Professionals interested in cybersecurity governance, risk, and compliance.
  • Career changers exploring cybersecurity roles that do not require coding.
  • Working professionals who want applied, employer-aligned cybersecurity training.
  • Learners who want to assess controls, document findings, and communicate risk.

The USF Difference

No coding background required

The course teaches cybersecurity context and governance responsibilities without requiring programming experience.

Applied GRC portfolio work

Learners complete a NIST CSF gap analysis and a professional risk assessment report.

Business-focused cybersecurity training

The course helps learners translate technical findings into recommendations that leaders can use.

Join the Interest List


Participant and Client Feedback

CTPE Clients

Employees at companies like these have trusted USF Corporate Training & Professional Education with their skills training and career advancement. 

Learn more about training for your team, organization, or company 

I’ve been able to immediately apply what I’ve learned by aligning HR initiatives with business goals and enhancing the way I support associates and leaders.
I was able to support HR work tied to a company acquisition, along with onboarding, offboarding, and culture related initiatives.

Frequently Asked Questions

Do I need prior cybersecurity experience to enroll?

No. Prior cybersecurity experience is not required. The program begins with foundational information security concepts and progresses into applied governance, risk, and compliance (GRC) practices. It can be a good fit for professionals from IT, audit, compliance, operations, and other business roles who are interested in developing cybersecurity risk and governance skills.

Do I need a specific degree or certification to enroll?

No. There are no degree or certification requirements to enroll. Basic computer skills are helpful, but the program begins with cybersecurity fundamentals. Learners with previous technical, business, compliance, audit, or security experience may be familiar with some concepts, but prior experience is not required.

Are there live lectures or mandatory meetings? Can everything be completed online?

Yes. The InfoSec GRC Analyst Training program is delivered online through Canvas and is primarily asynchronous, providing flexibility for working professionals.

Optional live office hours are offered once per week, giving you an opportunity to ask questions about course material and career pathways. Attendance at office hours is not required.

The only required live component is the final capstone presentation, which is delivered online to the instructor during the final week of the program. Flexible scheduling options are available to accommodate working professionals.

Will there be homework or reading outside of class? Do I need to buy textbooks?

You will complete activities, readings, knowledge checks, and a final applied project as part of the program. All required course materials are provided digitally and included with your registration. There are no textbooks to purchase.

How do I access the course modules?

You’ll access your course modules and materials through Canvas, USF’s learning management system (LMS). After you register for the program, you will receive an email invitation to join your course in Canvas.

Be sure to accept the Canvas course invitation and confirm that you can access the course. We recommend doing this before the program begins so you’re ready to get started.

Will there be quizzes or tests?

Each module includes short knowledge checks designed to reinforce what you’ve learned. You will have multiple opportunities to complete them successfully.

Is the course content captioned?

Yes. Course videos include captions.

Is there a final exam?

No. There is no traditional final exam. Instead, you will complete an applied cybersecurity gap assessment project and course survey.

As part of the final project, you will submit a professional assessment report and present your findings to the instructor. Your completed work will be reviewed to determine successful completion of the program and eligibility for the digital badge.

Is this a technical or coding-focused program?

No. The program focuses on cybersecurity governance, risk assessment, controls, and compliance rather than programming or offensive security.

It is designed for learners who are interested in the business and governance side of cybersecurity, including assessing risk, evaluating controls, documenting findings, and communicating recommendations to technical and non-technical stakeholders.

What practical experience will I gain?

You will complete an applied gap assessment aligned with the NIST Cybersecurity Framework (CSF) 2.0. You will practice defining assessment scope, reviewing evidence, evaluating controls, identifying gaps, and communicating risk and recommendations.

By the end of the program, you will have completed a NIST CSF gap analysis and a professional cybersecurity risk assessment report, giving you examples of applied GRC work that you can discuss with prospective employers.

How does this program relate to AI and automation?

AI and automation are changing how organizations operate, but they also introduce new questions about governance, risk, security, and accountability.

The program introduces AI concepts within the broader context of information security and GRC. You will learn how governance and risk professionals evaluate technologies, consider potential risk exposure, and help organizations determine whether appropriate controls and oversight are in place.

What types of roles can this program help prepare me for?

The program is designed to build skills relevant to governance, risk, and compliance-focused cybersecurity positions. Depending on your previous education and professional experience, these may include roles such as GRC Analyst, Cybersecurity Risk Analyst, Compliance Analyst, Security Program Analyst, and IT Audit support roles.

Does this program guarantee employment?

No educational program can guarantee employment. Hiring outcomes depend on factors such as your prior experience, education, skills, market conditions, and individual job-search efforts.

This program is designed to provide applied, employer-relevant preparation for governance, risk, and compliance-focused cybersecurity roles and give you practical work that you can discuss during interviews.

What credential will I receive?

After successfully completing the program requirements, you will receive a digital badge recognizing your achievement. You will receive an email from Credly with instructions for claiming your badge.

Once claimed, your digital badge can be shared on LinkedIn and other professional platforms.

How can my employer verify my digital badge?

Your digital badge provides a verifiable record of your achievement. Employers can select the badge to view information about the credential and the skills represented by it.

Who can I contact if I still have questions?

We’re here to help! Contact Kathy Barnes at barnesk@usf.edu with questions about the InfoSec GRC Analyst Training program.

Talk to an Advsior

Not sure 
where to start?

Our advisors are here to help you compare options, understand formats, and choose a course that fits your schedule and goals.

Talk to an Advisor