12 weeks·3 briefs·No code required
AI Governance & EU AI Act Practitioner
Risk classification, technical files, data governance records, human oversight design, conformity assessment, post-market monitoring. The whole evidence chain a deployer of a high-risk system has to be able to produce on demand.
Why now The bulk of the high-risk regime, including Annex III systems, starts to apply on 2 August 2026. Firms serving the EU market are hiring governance analysts, AI auditors and risk managers, and almost nobody has done the work before.
14 weeks·4 briefs·Career switchers welcome
NIS2 & Cyber GRC Practitioner
Gap assessment against ISO 27001 and NIST CSF, supplier and third-party risk under Article 21, incident reporting procedures, evidence management, and writing for a board that will not read past page two.
Why now NIS2 is being enforced nationally across the EU and has created compliance-officer and supply-chain-security roles that did not exist five years ago. Germany alone is estimated to need roughly 106,000 more cyber professionals.
10 weeks·2 briefs·Finance background helps
DORA Operational Resilience for Financial Services
ICT third-party risk registers, resilience testing, incident classification, and the register-of-information work every EU financial entity now has to keep current.
Why now DORA has applied since 17 January 2025 and the reporting burden is ongoing, not a one-off project. Regulated firms in Dublin, Frankfurt, Amsterdam and London are staffing it permanently.
10 weeks·2 briefs·No code required
Sustainability Reporting Analyst
Double materiality assessment, data collection across a messy supply chain, assurance-ready disclosure, and the spreadsheet discipline that keeps an auditor calm.
Why now Corporate sustainability reporting has moved from marketing into audited financial disclosure, which changes who companies hire and what standard the work is held to.