Cybersecurity’s talent shortage gets most of its attention pointed at penetration testers and SOC analysts, but the largest single category of unfilled cybersecurity job postings in the U.S. right now isn’t a technical role at all. It’s oversight and governance work: the analysts, auditors and compliance specialists who translate regulatory frameworks into evidence a company can actually show an auditor. BCR Cyber, a cybersecurity training and job placement provider, announced this week that it has launched a new Governance, Risk, and Compliance (GRC) Applied Fundamentals Training and Certification program, developed in partnership with defense contractor Northrop Grumman, aimed directly at that gap.
The program targets entry-to-mid-level professionals and runs 40 hours of combined online and instructor-led training, covering foundational GRC concepts, key regulatory frameworks, methodologies and the emerging technical trends reshaping the discipline. Participants come away with a working understanding of cybersecurity, cloud and AI oversight within everyday IT operations, tied explicitly to how those functions connect to business strategy, risk management and regulatory compliance, rather than treating GRC as a standalone compliance checkbox function.
That framing matters because the discipline itself has changed shape. GRC work used to mean manual compliance checklists and periodic risk assessments handled largely inside a compliance office. Michael Spector, President and CEO of BCR Cyber, described it instead as a holistic, integrated discipline that now spans auditing, legal, finance, IT, HR and executive leadership. That’s a meaningfully broader mandate than the role carried even five years ago, and it reflects how deeply governance requirements have embedded themselves into day-to-day technology operations as regulatory frameworks around AI, cloud infrastructure and data privacy have multiplied.
The labor market data backs up why that shift matters for hiring. CyberSeek’s mapping of U.S. cybersecurity job postings to the NICE Workforce Framework found the Oversight and Governance category to be the single largest segment nationally, ahead of both implementation and design-focused categories. Separately, GRC and compliance roles have shown roughly 19% year-over-year growth, and GRC analyst postings specifically rose nearly 12% year over year, according to industry job market tracking. That demand isn’t purely headcount-driven, either. ISC2’s most recent workforce research found that 59% of security teams report critical or significant skills gaps, up 15 percentage points from the prior year, a pattern industry analysts increasingly describe as a capability mismatch rather than a simple staffing shortage: organizations don’t just need more people, they need people who can actually translate a framework like NIST 800-53 into evidence an auditor will accept.
BCR Cyber’s curriculum design leans directly into that translation problem. Beyond frameworks and methodologies, the program builds technical writing and documentation skills, training participants to communicate governance and risk policies, procedures and compliance reporting clearly across the frameworks the program covers. That’s a deliberate response to a well-documented weak point in GRC hiring: candidates who understand a regulatory framework conceptually but can’t produce the documentation and reporting an audit actually requires.
Northrop Grumman’s involvement adds a signal worth noting on its own. John Robinson, the company’s Director of Network Solutions, framed the collaboration around preparing students for “today’s GRC workforce requirements” while positioning them for where the field is headed next, language that reflects a defense contractor’s particular stake in this talent pipeline. Federal contractors and defense-adjacent organizations operate under some of the most demanding compliance regimes in the private sector, and a training partner that understands those specific requirements, rather than generic private-sector GRC practices, offers a more direct pipeline into roles with federal compliance obligations baked in from day one.
The technology backdrop driving demand for this kind of training is also shifting quickly. AI, machine learning and cloud computing are increasingly embedded in the tools GRC professionals themselves rely on, enabling real-time risk insights, automation of routine compliance tasks, predictive analytics and faster decision-making. That’s changing what “GRC skills” actually means in practice: ISC2’s workforce research identifies AI oversight as the fastest-growing skills gap organizations report, ahead of cloud security, meaning a program that builds AI governance literacy directly into its foundational curriculum, rather than treating it as an advanced elective, is responding to where the actual hiring gap sits rather than where it used to sit.
For enterprise talent acquisition and HR teams building out compliance and risk functions, a structured, employer-informed entry pathway like this addresses a hiring problem that’s become increasingly acute: GRC roles frequently sit at the intersection of technical, legal and business skill sets that few individual candidates arrive with fully formed. A program explicitly co-developed with a major employer, built around federal compliance standards, offers a more credible signal of job-readiness than generic self-study certification paths, particularly for organizations competing for talent in a category where postings already outnumber qualified candidates.
Market Landscape
BCR Cyber’s GRC program enters a cybersecurity training market responding directly to one of the field’s most persistent structural gaps: a labor shortage that industry data consistently frames as a capability mismatch rather than a raw numbers problem. As major technology and cloud providers, including Microsoft, Google and Amazon, continue expanding AI governance requirements across their platforms, employer-informed training pathways that combine foundational frameworks with applied documentation skills are increasingly positioned as a faster, more targeted alternative to broad self-study certification routes.
Top Insights
- BCR Cyber launched a 40-hour GRC Applied Fundamentals Training and Certification program developed with Northrop Grumman, targeting entry-to-mid-level cybersecurity governance professionals.
- Oversight and Governance is the largest single category of U.S. cybersecurity job postings, according to CyberSeek data, reflecting acute demand for GRC-skilled professionals.
- ISC2 research shows 59% of security teams report critical or significant skills gaps, with AI oversight identified as the fastest-growing skills deficiency organizations face.
- The program builds technical writing and documentation skills alongside framework knowledge, addressing a common gap between conceptual compliance knowledge and audit-ready reporting.
- Northrop Grumman’s involvement signals direct relevance to federal compliance requirements, positioning graduates for roles with defense-sector and government contractor obligations.
Join thousands of HR leaders who rely on HRTechEdge for the latest in workforce technology, AI-driven HR solutions, and strategic insights





