Participants don't just learn about cybersecurity risk — they deliver it. Every engagement is real. Every deliverable matters. Every client is a community organization counting on your work.

You will be assigned to a team working with a real community partner. Under close supervision from experienced practitioners, you will conduct interviews, analyze risk, draft documentation, and present findings. Work product is reviewed before it goes to the client.

Engagements typically run 6–10 weeks. You may participate in multiple engagements over time, building depth across different organization types and risk domains.

GRC Vendor Risk Data Governance AI Governance Policy Writing Risk Assessment Client Communication Stakeholder Interviews

Time & commitment

—5–8 hours per week during active engagements
—Participation in team meetings and check-ins
—Timely completion of assigned tasks
—Professional conduct in all client interactions
—Commitment to confidentiality

Mentorship & support

—Direct mentorship from experienced security professionals
—Documented work product for your portfolio
—Supervised client exposure in a structured setting
—Exposure to multiple industries and organization types
—References and professional network connections

Everything you produce in an engagement is reviewed, recorded, and yours to keep. Current and accepted participants track their work and portfolio in Stepping Stone, our talent pipeline platform: Participant Login →

Faculty and workforce advisors: refer your students directly into supervised cybersecurity engagements with real community organizations.

TechStep partners with universities and academic programs to give students a structured, supervised pathway into cybersecurity practice. Faculty refer candidates through our referral process — no prior cybersecurity experience required. TechStep handles matching, supervision, and deliverable review.

For faculty & advisors

—Refer individual students using the interest form below
—For bulk referrals of 3 or more students, download the Faculty Referral Form and email it to [email protected]
—Spring 2027 referral deadline: rolling until filled — contact us to confirm current openings
—Engagements run 6–10 weeks, 5–8 hours per week

Downloads

—University Partner One-Pager ↓
Share with students — overview of the program, engagement types, and enrollment process
—Faculty Referral Form ↓
Bulk referral spreadsheet — complete and email to [email protected]

You do not need a certification to join TechStep — but these free resources will help you build confidence, speak the language, and hit the ground running from day one.

Organized by the skill tracks used in TechStep clinic engagements. All resources listed are free or freely accessible. Start anywhere — there is no required order.

GRC & Risk Assessment

—NIST Cybersecurity Framework
The exact framework TechStep uses in every clinic engagement. Free to download directly from NIST.
—CISA Free Training Library
Free GRC, risk, and infrastructure security courses from the federal agency that sets the standard.
—ISC2 Certified in Cybersecurity (CC)
A free entry-level certification with free study materials. Widely recognized and a strong first credential.

Policy & Compliance

—SANS Security Policy Templates
Free, ready-to-adapt policy templates covering incident response, acceptable use, data classification, and more.
—NIST SP 800 Series
The authoritative source for security and privacy controls. SP 800-53 and SP 800-171 are most relevant for clinic work.
—SANS Cyber Aces
Free foundational cybersecurity courses covering operating systems, networking, and system administration basics.

AI & Data Governance

—NIST AI Risk Management Framework
The federal framework for AI governance — directly relevant to TechStep AI governance engagements.
—FTC Business Privacy & Security
Plain-language guidance on data privacy, breach response, and consumer data rights — useful for nonprofit client work.
—Stanford AI Index Report
Annual free report on AI trends, governance developments, and policy — good background reading before AI governance engagements.

Career & Portfolio Building

—LinkedIn Learning
Free access available through many university libraries. Search GRC, risk management, and compliance fundamentals.
—CompTIA Security+ Overview
The most recognized entry-level security certification. Clinic experience directly supports your preparation for this exam.
—ISACA Cybersecurity Credentials
ISACA's cybersecurity credentials including CSX-P and CISM — respected GRC-aligned certifications. Review options and free study resources.

A note from TechStep: You do not need to complete any of these before applying. What matters is your commitment to doing real work, communicating professionally, and growing through the engagement. The resources above are here to support you — not to gate you out.

Tell us about yourself and your goals. We review applications on a rolling basis.

✓ Received — we will be in touch with next steps.
Something went wrong. Please try again.