Governance, Risk Management and Compliance (GRC)
UK

The following table provides summary statistics for permanent job vacancies with a requirement for GRC skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited GRC over the 6 months to 23 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
23 May 2024
Same period 2023 Same period 2022
Rank 552 600 720
Rank change year-on-year +48 +120 -80
Permanent jobs citing GRC 364 388 586
As % of all permanent jobs advertised in the UK 0.36% 0.39% 0.36%
As % of the Quality Assurance & Compliance category 2.68% 2.09% 2.10%
Number of salaries quoted 306 295 340
10th Percentile £42,500 £46,550 £42,500
25th Percentile £47,750 £54,500 £48,750
Median annual salary (50th Percentile) £57,500 £65,000 £65,000
Median % change year-on-year -11.54% - -
75th Percentile £77,500 £81,250 £81,250
90th Percentile £87,500 £93,750 £97,500
UK excluding London median annual salary £50,500 £60,000 £55,000
% change year-on-year -15.83% +9.09% -4.35%

All Quality Assurance and Compliance Skills
UK

GRC is in the Quality Assurance and Compliance category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for quality assurance or compliance skills.

Permanent vacancies with a requirement for quality assurance or compliance skills 13,561 18,525 27,926
As % of all permanent jobs advertised in the UK 13.44% 18.81% 17.05%
Number of salaries quoted 9,147 8,607 13,266
10th Percentile £26,750 £32,000 £31,250
25th Percentile £36,250 £42,500 £41,250
Median annual salary (50th Percentile) £52,500 £57,500 £55,000
Median % change year-on-year -8.70% +4.55% +4.76%
75th Percentile £70,000 £76,250 £73,750
90th Percentile £90,000 £93,750 £90,000
UK excluding London median annual salary £47,500 £50,000 £47,602
% change year-on-year -5.00% +5.04% +0.22%

GRC
Job Vacancy Trend

Job postings citing GRC as a proportion of all IT jobs advertised.

Job vacancy trend for GRC in the UK

GRC
Salary Trend

3-month moving average salary quoted in jobs citing GRC.

Salary trend for GRC in the UK

GRC
Salary Histogram

Salary distribution for jobs citing GRC over the 6 months to 23 May 2024.

Salary histogram for GRC in the UK

GRC
Top 15 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing GRC within the UK over the 6 months to 23 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England +121 351 £57,500 -11.54% 71
UK excluding London +45 229 £50,500 -15.83% 39
Work from Home +11 129 £60,000 -11.11% 36
London +78 122 £72,500 +7.41% 30
South East +68 121 £50,500 -15.83% 11
North of England +46 49 £45,000 -25.00% 17
Midlands -1 33 £55,000 -26.67% 7
North West +12 30 £40,000 -32.80% 6
West Midlands +12 28 £55,000 -26.67% 4
Yorkshire +75 16 £58,750 -2.89% 8
South West -21 16 £70,000 +12.00% 3
East of England +17 10 £72,500 +16.00% 1
East Midlands -3 4 £80,000 - 3
North East -4 3 £63,750 - 4
Scotland -82 2 £32,500 -45.40% 1

GRC
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 6 (1.65%) Microsoft Exchange
2 3 (0.82%) Confluence
3 2 (0.55%) SharePoint
4 1 (0.27%) IBM Domino
Applications
1 11 (3.02%) Microsoft Office
2 5 (1.37%) Microsoft Excel
2 5 (1.37%) Microsoft PowerPoint
3 2 (0.55%) MS Visio
4 1 (0.27%) Microsoft Project
Business Applications
1 14 (3.85%) SAP GRC
2 7 (1.92%) SAP S/4HANA
3 2 (0.55%) SAP BPC
Cloud Services
1 35 (9.62%) Microsoft 365
2 31 (8.52%) Azure
3 13 (3.57%) AWS
4 9 (2.47%) Entra ID
4 9 (2.47%) Power Platform
5 7 (1.92%) SaaS
6 6 (1.65%) Microsoft Purview
7 5 (1.37%) SuccessFactors
8 3 (0.82%) Cloud Computing
8 3 (0.82%) GCP
8 3 (0.82%) WhatsApp
9 2 (0.55%) OCI
10 1 (0.27%) IaaS
10 1 (0.27%) PaaS
10 1 (0.27%) Power Automate
Communications & Networking
1 30 (8.24%) Firewall
2 17 (4.67%) Network Security
3 9 (2.47%) Wireless
4 7 (1.92%) VPN
5 6 (1.65%) Wireshark
6 3 (0.82%) Broadband
6 3 (0.82%) NaaS
6 3 (0.82%) SSL
7 2 (0.55%) Intranet
7 2 (0.55%) Wi-Fi
8 1 (0.27%) Cisco IPT
8 1 (0.27%) Intrusion Detection
8 1 (0.27%) SAN
Database & Business Intelligence
1 9 (2.47%) Power BI
2 6 (1.65%) Metadata
2 6 (1.65%) SAP BW
3 3 (0.82%) Relational Database
4 1 (0.27%) Data Warehouse
Development Applications
1 4 (1.10%) JIRA
General
1 67 (18.41%) Finance
2 63 (17.31%) Social Skills
3 39 (10.71%) Legal
4 35 (9.62%) Analytical Skills
5 30 (8.24%) Law
6 21 (5.77%) Public Sector
7 16 (4.40%) Telecoms
8 13 (3.57%) Marketing
9 12 (3.30%) Presentation Skills
10 9 (2.47%) Influencing Skills
11 7 (1.92%) Banking
11 7 (1.92%) Inclusion and Diversity
12 6 (1.65%) Retail
13 4 (1.10%) Advertising
14 2 (0.55%) Documentation Skills
14 2 (0.55%) Financial Institution
14 2 (0.55%) Games
14 2 (0.55%) Organisational Skills
15 1 (0.27%) French Language
15 1 (0.27%) Spanish Language
Job Titles
1 86 (23.63%) Analyst
2 71 (19.51%) Security Specialist
3 70 (19.23%) Security Analyst
4 67 (18.41%) Cybersecurity Specialist
5 52 (14.29%) Information Analyst
5 52 (14.29%) Information Security Analyst
5 52 (14.29%) Security Manager
6 37 (10.16%) Consultant
7 34 (9.34%) Senior
8 30 (8.24%) Lead
9 27 (7.42%) Security Consultant
10 20 (5.49%) IT Manager
11 18 (4.95%) Information Manager
12 17 (4.67%) Information Security Manager
13 16 (4.40%) Senior Analyst
14 14 (3.85%) Cybersecurity Analyst
14 14 (3.85%) Cybersecurity Manager
14 14 (3.85%) IT Security Manager
14 14 (3.85%) Penetration Tester
14 14 (3.85%) Tester
Libraries, Frameworks & Software Standards
1 5 (1.37%) LDAP
2 4 (1.10%) CSS
2 4 (1.10%) REST
2 4 (1.10%) SAP Business Workflow
2 4 (1.10%) SOAP
3 3 (0.82%) Kafka
3 3 (0.82%) ODBC
4 2 (0.55%) AngularJS
4 2 (0.55%) HTML
4 2 (0.55%) JDBC
4 2 (0.55%) Oracle Fusion
4 2 (0.55%) SailPoint
4 2 (0.55%) Web Services
5 1 (0.27%) SAP Fiori
Miscellaneous
1 56 (15.38%) Management Information System
2 40 (10.99%) Security Posture
3 35 (9.62%) Cyber Threat
4 18 (4.95%) Self-Motivation
5 7 (1.92%) CMDB
5 7 (1.92%) Cyber Defence
5 7 (1.92%) Cyber Security Posture
5 7 (1.92%) Legacy Systems
6 6 (1.65%) Mobile App
7 5 (1.37%) Distributed Denial-of-Service
7 5 (1.37%) Onboarding
8 4 (1.10%) Data Protection Act
8 4 (1.10%) Operational Technology
8 4 (1.10%) PMI
9 3 (0.82%) TM Forum
10 2 (0.55%) Cyberattack
10 2 (0.55%) Data Structures
10 2 (0.55%) Driving Licence
10 2 (0.55%) Product Ownership
10 2 (0.55%) Public Cloud
Operating Systems
1 18 (4.95%) Windows
2 7 (1.92%) Linux
3 3 (0.82%) Windows Server
Processes & Methodologies
1 205 (56.32%) Cybersecurity
2 195 (53.57%) Information Security
3 128 (35.16%) Risk Management
4 57 (15.66%) Data Protection
5 48 (13.19%) Security Operations
6 40 (10.99%) Security Management
7 38 (10.44%) Stakeholder Management
8 33 (9.07%) Incident Response
8 33 (9.07%) ITIL
9 32 (8.79%) Vulnerability Management
10 30 (8.24%) Penetration Testing
10 30 (8.24%) Problem-Solving
11 28 (7.69%) GAP Analysis
11 28 (7.69%) ISMS
11 28 (7.69%) Roadmaps
12 27 (7.42%) Cloud Security
12 27 (7.42%) Decision-Making
12 27 (7.42%) Information Assurance
12 27 (7.42%) Risk Assessment
13 25 (6.87%) Security Architecture
Programming Languages
1 13 (3.57%) JavaScript
2 10 (2.75%) PowerShell
3 7 (1.92%) Python
4 2 (0.55%) Kusto Query Language
5 1 (0.27%) SQL
Qualifications
1 84 (23.08%) CISSP
2 74 (20.33%) CISM
3 52 (14.29%) CISA
4 41 (11.26%) CRISC
5 40 (10.99%) Security Cleared
6 35 (9.62%) Degree
7 22 (6.04%) SC Cleared
8 17 (4.67%) ISO 27001 Lead Auditor
9 16 (4.40%) PCI QSA
10 15 (4.12%) GIAC
11 14 (3.85%) OSCP
12 13 (3.57%) CREST Certified
13 8 (2.20%) CESG Certified Professional
13 8 (2.20%) CompTIA Security+
13 8 (2.20%) GPEN
14 7 (1.92%) CISMP
14 7 (1.92%) PMI Certification
15 6 (1.65%) CHECK Team Leader
15 6 (1.65%) CHECK Team Member
15 6 (1.65%) Cyber Scheme
Quality Assurance & Compliance
1 176 (48.35%) NIST
2 167 (45.88%) ISO/IEC 27001
3 67 (18.41%) Def Stans
4 58 (15.93%) GDPR
5 49 (13.46%) Cyber Essentials
6 43 (11.81%) PCI DSS
7 26 (7.14%) NCSC
8 19 (5.22%) NIST 800
9 15 (4.12%) COBIT
10 14 (3.85%) Cyber Essentials PLUS
11 11 (3.02%) ITGC
12 10 (2.75%) SOC 2
13 9 (2.47%) HMG Security Policy Framework
13 9 (2.47%) Sarbanes-Oxley
14 7 (1.92%) Data Quality
15 6 (1.65%) Actionable Recommendations
15 6 (1.65%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
15 6 (1.65%) QA
16 4 (1.10%) IASME
16 4 (1.10%) ISO 9001
System Software
1 9 (2.47%) Active Directory
2 1 (0.27%) Virtual Machines
Systems Management
1 14 (3.85%) CSIRT
2 6 (1.65%) Computer Emergency Response Teams
2 6 (1.65%) Nessus
3 3 (0.82%) RSA Archer
4 2 (0.55%) Single Sign-On
5 1 (0.27%) QRadar
Vendors
1 42 (11.54%) Microsoft
2 22 (6.04%) SAP
3 20 (5.49%) Qualys
4 18 (4.95%) ServiceNow
5 8 (2.20%) CrowdStrike
6 4 (1.10%) Workday
7 3 (0.82%) Google
7 3 (0.82%) OneTrust
8 2 (0.55%) Ariba
8 2 (0.55%) Concur
8 2 (0.55%) Oracle
8 2 (0.55%) Sophos
9 1 (0.27%) Darktrace
9 1 (0.27%) Facebook