Nicole Whatley
GRC Analyst
My path into cybersecurity began with a strong foundation in quality assurance and project management, where I developed skills in process improvement, compliance, and risk awareness. Over time, I realized that these strengths aligned closely with the principles of governance, risk, and compliance (GRC)—a field that bridges business operations with cybersecurity protection.
I earned my CompTIA Security+ certification to build a technical foundation and validate my knowledge of security principles. From there, I deepened my expertise by pursuing the Certified in Governance, Risk, and Compliance (CGRC) certification and training in NIST CSF, NIST RMF, AI compliance, and AI security frameworks. These steps allowed me to connect my process-driven background with structured cybersecurity governance.
Today, as an aspiring GRC Analyst, I bring together a unique mix of project leadership, quality assurance discipline, and cybersecurity expertise. I am happy to share with other my journey and speak about the exciting options in cybersecurity careers.