GRC / Cybersecurity Projects for Resume & GitHub (ISO 27001, Risk Acceptance, GRC Automation)
Budget: $30 – $250 CAD
I am an entry-level cybersecurity professional transitioning into GRC and security roles. I am building high-quality, real projects for my resume and GitHub and I want to understand every decision, not just receive finished documents.
This is not a copy-paste or template job. I am looking for someone who can both build and teach.
I will provide detailed project READMEs that describe the scenarios and expectations. Your role is to implement them properly and explain the reasoning behind each decision until I clearly understand it.
Scope of Work
You will work on one or more of the following projects (starting with one, expanding if the quality is good):
ISO 27001:2022 Statement of Applicability with justified exclusions
Writing a defensible security risk acceptance document
Designing and documenting an automated GRC control (GRC engineering style)
Each project must be completed as if it were done for a real company, not a school assignment.
Required Deliverables
1. Project Implementation
Complete the project based on the provided README
Make realistic, risk-driven decisions
Avoid vague language and generic compliance filler
Clearly link business context, risk, and controls
2. GitHub-Ready Output
Clean folder structure
Professional README.md written in plain English
Clear explanation of:
business context
approach
key decisions
trade-offs
outcomes
3. Decision Justification
For every major decision, explain:
why this approach was chosen
what alternatives existed
what risks remain
what an auditor, manager, or interviewer might challenge
4. Teaching & Explanation (Mandatory)
You must explain the work to me as you go. This can be done via:
recorded screen walkthroughs, or live Zoom / Google Meet sessions, or a combination of both
Assume I am smart but new to GRC. Teach me like a junior analyst.
5. Interview Readiness
For each project, include:
a 60-second explanation I can use in interviews
common interview questions about the project
how this project maps to real GRC or security roles
Quality & Originality Requirements:
All work must be original and not reused from other clients
No AI-generated filler without review and correction
I may ask follow-up questions to verify understanding
Plagiarized or generic work will be rejected
Ideal Freelancer
You are a strong fit if you have:
Experience with GRC, audit, or security engineering
Hands-on knowledge of ISO 27001, SOC 2, or risk management
Ability to explain complex topics in simple language
Prior examples of documentation, GitHub projects, or real-world GRC work
When applying, please briefly explain:
your GRC or security background
which project you would start with
how you would explain one control exclusion or risk acceptance to a non-technical executive
Project Structure & Payment
This project will be milestone-based
Payment is tied to both delivery and explanation
If the first project goes well, there is ongoing work
This is not a copy-paste or template job. I am looking for someone who can both build and teach.
I will provide detailed project READMEs that describe the scenarios and expectations. Your role is to implement them properly and explain the reasoning behind each decision until I clearly understand it.
Scope of Work
You will work on one or more of the following projects (starting with one, expanding if the quality is good):
ISO 27001:2022 Statement of Applicability with justified exclusions
Writing a defensible security risk acceptance document
Designing and documenting an automated GRC control (GRC engineering style)
Each project must be completed as if it were done for a real company, not a school assignment.
Required Deliverables
1. Project Implementation
Complete the project based on the provided README
Make realistic, risk-driven decisions
Avoid vague language and generic compliance filler
Clearly link business context, risk, and controls
2. GitHub-Ready Output
Clean folder structure
Professional README.md written in plain English
Clear explanation of:
business context
approach
key decisions
trade-offs
outcomes
3. Decision Justification
For every major decision, explain:
why this approach was chosen
what alternatives existed
what risks remain
what an auditor, manager, or interviewer might challenge
4. Teaching & Explanation (Mandatory)
You must explain the work to me as you go. This can be done via:
recorded screen walkthroughs, or live Zoom / Google Meet sessions, or a combination of both
Assume I am smart but new to GRC. Teach me like a junior analyst.
5. Interview Readiness
For each project, include:
a 60-second explanation I can use in interviews
common interview questions about the project
how this project maps to real GRC or security roles
Quality & Originality Requirements:
All work must be original and not reused from other clients
No AI-generated filler without review and correction
I may ask follow-up questions to verify understanding
Plagiarized or generic work will be rejected
Ideal Freelancer
You are a strong fit if you have:
Experience with GRC, audit, or security engineering
Hands-on knowledge of ISO 27001, SOC 2, or risk management
Ability to explain complex topics in simple language
Prior examples of documentation, GitHub projects, or real-world GRC work
When applying, please briefly explain:
your GRC or security background
which project you would start with
how you would explain one control exclusion or risk acceptance to a non-technical executive
Project Structure & Payment
This project will be milestone-based
Payment is tied to both delivery and explanation
If the first project goes well, there is ongoing work