GRC / Cybersecurity Projects for Resume & GitHub (ISO 27001, Risk Acceptance, GRC Automation)

Job ID: 40271981

Budget: $30 – $250 CAD

I am an entry-level cybersecurity professional transitioning into GRC and security roles. I am building high-quality, real projects for my resume and GitHub and I want to understand every decision, not just receive finished documents.

This is not a copy-paste or template job. I am looking for someone who can both build and teach.

I will provide detailed project READMEs that describe the scenarios and expectations. Your role is to implement them properly and explain the reasoning behind each decision until I clearly understand it.

Scope of Work

You will work on one or more of the following projects (starting with one, expanding if the quality is good):

ISO 27001:2022 Statement of Applicability with justified exclusions
Writing a defensible security risk acceptance document
Designing and documenting an automated GRC control (GRC engineering style)
Each project must be completed as if it were done for a real company, not a school assignment.

Required Deliverables

1. Project Implementation

Complete the project based on the provided README
Make realistic, risk-driven decisions
Avoid vague language and generic compliance filler
Clearly link business context, risk, and controls

2. GitHub-Ready Output

Clean folder structure
Professional README.md written in plain English

Clear explanation of:

business context
approach
key decisions
trade-offs
outcomes

3. Decision Justification
For every major decision, explain:

why this approach was chosen
what alternatives existed
what risks remain
what an auditor, manager, or interviewer might challenge

4. Teaching & Explanation (Mandatory)
You must explain the work to me as you go. This can be done via:

recorded screen walkthroughs, or live Zoom / Google Meet sessions, or a combination of both
Assume I am smart but new to GRC. Teach me like a junior analyst.

5. Interview Readiness

For each project, include:

a 60-second explanation I can use in interviews
common interview questions about the project
how this project maps to real GRC or security roles

Quality & Originality Requirements:
All work must be original and not reused from other clients
No AI-generated filler without review and correction
I may ask follow-up questions to verify understanding
Plagiarized or generic work will be rejected


Ideal Freelancer
You are a strong fit if you have:
Experience with GRC, audit, or security engineering
Hands-on knowledge of ISO 27001, SOC 2, or risk management
Ability to explain complex topics in simple language
Prior examples of documentation, GitHub projects, or real-world GRC work

When applying, please briefly explain:
your GRC or security background
which project you would start with
how you would explain one control exclusion or risk acceptance to a non-technical executive

Project Structure & Payment
This project will be milestone-based
Payment is tied to both delivery and explanation
If the first project goes well, there is ongoing work