GRC Contracts

Governance, Risk Management and Compliance (GRC)
UK

The table below provides summary statistics for contract job vacancies requiring GRC skills. It includes a benchmarking guide to the contractor rates offered in vacancies that cited GRC over the 6 months leading up to 2 July 2025, comparing them to the same period in the previous two years.

6 months to
2 Jul 2025
Same period 2024 Same period 2023
Rank 364 474 513
Rank change year-on-year +110 +39 +143
Contract jobs citing GRC 167 113 174
As % of all contract jobs advertised in the UK 0.54% 0.26% 0.31%
As % of the Quality Assurance & Compliance category 3.30% 1.90% 2.29%
Number of daily rates quoted 95 81 128
10th Percentile £350 £400 £377
25th Percentile £418 £475 £475
Median daily rate (50th Percentile) £550 £575 £588
Median % change year-on-year -4.35% -2.13% -
75th Percentile £675 £703 £713
90th Percentile £745 £888 £850
UK excluding London median daily rate £409 £575 £600
% change year-on-year -28.87% -4.17% +7.14%
Number of hourly rates quoted 3 0 1
10th Percentile £37.49 - -
25th Percentile £47.81 - -
Median hourly rate £65.00 - £70.00
75th Percentile £82.50 - -
90th Percentile £93.00 - -
UK excluding London median hourly rate £66.37 - -

All Quality Assurance and Compliance Skills
UK

GRC falls under the Quality Assurance and Compliance category. For comparison with the information above, the following table provides summary statistics for all contract job vacancies requiring quality assurance or compliance skills.

Contract vacancies with a requirement for quality assurance or compliance skills 5,063 5,937 7,593
As % of all contract IT jobs advertised in the UK 16.32% 13.68% 13.61%
Number of daily rates quoted 3,247 3,687 5,184
10th Percentile £280 £282 £300
25th Percentile £400 £401 £413
Median daily rate (50th Percentile) £500 £510 £525
Median % change year-on-year -1.96% -2.86% -
75th Percentile £613 £625 £650
90th Percentile £725 £750 £750
UK excluding London median daily rate £475 £475 £495
% change year-on-year - -4.04% +7.03%
Number of hourly rates quoted 211 432 253
10th Percentile £14.78 £11.07 £14.00
25th Percentile £18.50 £13.50 £19.50
Median hourly rate £30.00 £23.80 £38.00
Median % change year-on-year +26.05% -37.37% +40.74%
75th Percentile £63.75 £50.27 £63.23
90th Percentile £83.41 £70.00 £79.95
UK excluding London median hourly rate £28.18 £21.06 £37.50
% change year-on-year +33.84% -43.85% +66.67%

GRC
Job Vacancy Trend

Job postings citing GRC as a proportion of all IT jobs advertised.

Job vacancy trend for GRC in the UK

GRC
Contractor Daily Rate Trend

3-month moving average daily rate quoted in jobs citing GRC.

Daily rate trend for GRC in the UK

GRC
Daily Rate Histogram

Daily rate distribution for jobs citing GRC over the 6 months to 2 July 2025.

Daily rate histogram for GRC in the UK

GRC
Contractor Hourly Rate Trend

3-month moving average hourly rates quoted in jobs citing GRC.

Hourly rate trend for GRC in the UK

GRC
Hourly Rate Histogram

Hourly rate distribution of jobs citing GRC over the 6 months to 2 July 2025.

Hourly rate histogram for GRC in the UK

GRC
Top 16 Contract Locations

The table below looks at the demand and provides a guide to the median contractor rates quoted in IT jobs citing GRC within the UK over the 6 months to 2 July 2025. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Contract
IT Job Ads
Median
Daily Rate
Past 6 Months
Median Daily Rate
% Change
on Same Period
Last Year
Live
Jobs
England +102 139 £550 -4.35% 788
UK excluding London +83 73 £409 -28.87% 341
London +52 72 £640 +11.30% 477
Work from Home +48 46 £550 - 391
Midlands +22 25 £400 -20.00% 37
East Midlands +15 16 £400 +3.43% 13
North of England +7 14 £409 -16.53% 84
North West +10 11 £359 -26.79% 51
Scotland +13 10 £425 -28.57% 24
South East +55 9 £523 -11.06% 98
West Midlands +14 9 £625 -7.37% 24
East of England +27 7 £550 - 39
South West +40 6 £416 -37.05% 47
North East - 2 £525 - 7
Northern Ireland - 2 - - 8
Yorkshire -6 1 £525 +13.15% 27

GRC
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Applications
1 3 (1.80%) Microsoft Excel
2 1 (0.60%) Camtasia
2 1 (0.60%) Final Cut Pro
2 1 (0.60%) Microsoft Office
Business Applications
1 15 (8.98%) SAP GRC
2 14 (8.38%) SAP S/4HANA
3 2 (1.20%) SAP BPC
3 2 (1.20%) SAP CO
3 2 (1.20%) SAP ECC
3 2 (1.20%) SAP ERP
3 2 (1.20%) SAP FI
3 2 (1.20%) SAP FI/CO
4 1 (0.60%) Oracle EBS
Cloud Services
1 24 (14.37%) Azure
2 17 (10.18%) AWS
3 13 (7.78%) GCP
4 6 (3.59%) SaaS
5 4 (2.40%) Akamai
5 4 (2.40%) Entra ID
5 4 (2.40%) Google Kubernetes Engine
5 4 (2.40%) Power Platform
5 4 (2.40%) SuccessFactors
6 2 (1.20%) Azure Logic Apps
6 2 (1.20%) Azure Sentinel
6 2 (1.20%) Microsoft 365
6 2 (1.20%) Miro
7 1 (0.60%) Amazon GuardDuty
7 1 (0.60%) AWS Control Tower
7 1 (0.60%) Azure Key Vault
7 1 (0.60%) GitHub
7 1 (0.60%) GitHub Actions
7 1 (0.60%) IaaS
7 1 (0.60%) PaaS
Communications & Networking
1 13 (7.78%) Network Security
2 11 (6.59%) Firewall
3 5 (2.99%) SD-WAN
3 5 (2.99%) WAN
4 4 (2.40%) DNS
5 2 (1.20%) Intrusion Detection
6 1 (0.60%) DMZ
6 1 (0.60%) HTTPS
6 1 (0.60%) SNMP
6 1 (0.60%) SSH
6 1 (0.60%) Telnet
6 1 (0.60%) VLAN
6 1 (0.60%) VPN
Database & Business Intelligence
1 4 (2.40%) Power BI
1 4 (2.40%) SAP BW
2 3 (1.80%) SAP HANA
3 2 (1.20%) BigQuery
3 2 (1.20%) Tableau
4 1 (0.60%) Data Lake
Development Applications
1 1 (0.60%) CircleCI
1 1 (0.60%) GitLab
1 1 (0.60%) Jenkins
1 1 (0.60%) JIRA
1 1 (0.60%) Snyk
1 1 (0.60%) SonarQube
General
1 67 (40.12%) Social Skills
2 37 (22.16%) Finance
3 17 (10.18%) Analytical Skills
4 16 (9.58%) Banking
4 16 (9.58%) Public Sector
5 12 (7.19%) Legal
6 10 (5.99%) Retail
7 9 (5.39%) Presentation Skills
8 7 (4.19%) Telecoms
9 5 (2.99%) Organisational Skills
10 4 (2.40%) Documentation Skills
11 2 (1.20%) Manufacturing
11 2 (1.20%) Marketing
11 2 (1.20%) Military
11 2 (1.20%) Public Speaking
12 1 (0.60%) Aerospace
12 1 (0.60%) Games
12 1 (0.60%) International Banking
12 1 (0.60%) Law
12 1 (0.60%) Publishing
Job Titles
1 40 (23.95%) Analyst
2 31 (18.56%) Architect
2 31 (18.56%) Consultant
3 24 (14.37%) Security Architect
4 17 (10.18%) Security Consultant
5 16 (9.58%) Security Analyst
6 14 (8.38%) Senior
7 12 (7.19%) Information Analyst
7 12 (7.19%) Information Security Analyst
7 12 (7.19%) Lead
8 11 (6.59%) Governance Analyst
8 11 (6.59%) Risk Analyst
9 10 (5.99%) Solutions Architect
10 9 (5.39%) SAP Consultant
11 8 (4.79%) Business Analyst
11 8 (4.79%) Developer
12 7 (4.19%) SAP Security Consultant
12 7 (4.19%) ServiceNow Developer
13 6 (3.59%) Security Solutions Architect
14 5 (2.99%) Senior Security Architect
Libraries, Frameworks & Software Standards
1 11 (6.59%) SailPoint
2 5 (2.99%) CSS
2 5 (2.99%) HTML
2 5 (2.99%) REST
3 4 (2.40%) AngularJS
3 4 (2.40%) HTML5
3 4 (2.40%) jQuery
3 4 (2.40%) SOAP
4 3 (1.80%) SAP Fiori
5 2 (1.20%) SAML
6 1 (0.60%) JSON
6 1 (0.60%) OAuth
6 1 (0.60%) OpenID
6 1 (0.60%) XML
Miscellaneous
1 14 (8.38%) Security Posture
2 13 (7.78%) Product Ownership
3 11 (6.59%) Management Information System
4 5 (2.99%) Cloud Native
4 5 (2.99%) Security Operations Centre
5 4 (2.40%) Cyber Threat
5 4 (2.40%) Operational Technology
5 4 (2.40%) Self-Motivation
5 4 (2.40%) Virtual Team
6 3 (1.80%) Greenfield Project
6 3 (1.80%) Onboarding
7 2 (1.20%) Blog
7 2 (1.20%) CMDB
7 2 (1.20%) Cyber Kill Chain
7 2 (1.20%) Data Centre
7 2 (1.20%) Data Protection Act
7 2 (1.20%) Hybrid Cloud
7 2 (1.20%) Insider Threat
7 2 (1.20%) Shadow IT
7 2 (1.20%) YARA
Processes & Methodologies
1 66 (39.52%) Risk Management
2 61 (36.53%) Cybersecurity
3 45 (26.95%) Information Security
4 28 (16.77%) Stakeholder Management
5 27 (16.17%) Agile
6 26 (15.57%) Problem-Solving
7 25 (14.97%) Incident Response
8 21 (12.57%) Roadmaps
8 21 (12.57%) Security Operations
9 19 (11.38%) Cloud Security
9 19 (11.38%) DevSecOps
9 19 (11.38%) Security Architecture
10 18 (10.78%) Data Protection
10 18 (10.78%) Stakeholder Engagement
11 17 (10.18%) ITSM
12 16 (9.58%) Continuous Improvement
12 16 (9.58%) Identity Access Management
13 14 (8.38%) Business Continuity
13 14 (8.38%) Penetration Testing
14 13 (7.78%) Vulnerability Management
Programming Languages
1 9 (5.39%) JavaScript
2 4 (2.40%) Python
3 3 (1.80%) Bash
4 2 (1.20%) Kusto Query Language
4 2 (1.20%) SQL
5 1 (0.60%) ABAP
5 1 (0.60%) Go
5 1 (0.60%) Java
5 1 (0.60%) PowerShell
Qualifications
1 32 (19.16%) CISSP
2 26 (15.57%) CISM
3 17 (10.18%) Security Cleared
4 15 (8.98%) SC Cleared
5 13 (7.78%) CRISC
5 13 (7.78%) Degree
6 9 (5.39%) CISA
7 5 (2.99%) Master's Degree
8 4 (2.40%) CEH
8 4 (2.40%) ISO 27001 Lead Auditor
8 4 (2.40%) ISO 27001 Lead Implementer
9 3 (1.80%) (ISC)2 CCSP
9 3 (1.80%) Cisco Certification
9 3 (1.80%) Computer Science Degree
10 2 (1.20%) AWS Certification
10 2 (1.20%) CCSP
10 2 (1.20%) DV Cleared
10 2 (1.20%) GCIA
10 2 (1.20%) GCIH
10 2 (1.20%) SAP Certification
Quality Assurance & Compliance
1 49 (29.34%) NIST
2 45 (26.95%) ISO/IEC 27001
3 29 (17.37%) GDPR
4 13 (7.78%) PCI DSS
4 13 (7.78%) Sarbanes-Oxley
5 9 (5.39%) Cyber Essentials
5 9 (5.39%) NIST 800
6 8 (4.79%) SOC 2
7 7 (4.19%) HIPAA
7 7 (4.19%) NCSC
8 4 (2.40%) Cyber Essentials PLUS
8 4 (2.40%) ISO/IEC 27005
9 3 (1.80%) California Consumer Privacy Act
10 2 (1.20%) COBIT
10 2 (1.20%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
10 2 (1.20%) ITGC
10 2 (1.20%) JSP 440
10 2 (1.20%) PMO
10 2 (1.20%) PSD2
10 2 (1.20%) SOX 404
System Software
1 4 (2.40%) Active Directory
2 3 (1.80%) IAG
2 3 (1.80%) Virtual Machines
3 1 (0.60%) Firmware
Systems Management
1 4 (2.40%) Kubernetes
1 4 (2.40%) Terraform
2 2 (1.20%) RSA Archer
3 1 (0.60%) Istio
3 1 (0.60%) Jamf Pro
3 1 (0.60%) linkerd
3 1 (0.60%) Microsoft Intune
3 1 (0.60%) Nessus
3 1 (0.60%) OPNET
3 1 (0.60%) Single Sign-On
Vendors
1 29 (17.37%) Microsoft
2 28 (16.77%) ServiceNow
3 20 (11.98%) SAP
4 10 (5.99%) Google
4 10 (5.99%) Qualys
5 5 (2.99%) Ariba
5 5 (2.99%) IBM
5 5 (2.99%) OneTrust
6 4 (2.40%) F5
6 4 (2.40%) Snow
6 4 (2.40%) Splunk
6 4 (2.40%) Zscaler
7 3 (1.80%) Concur
7 3 (1.80%) ForgeRock
7 3 (1.80%) Okta
8 2 (1.20%) Cisco
8 2 (1.20%) CyberArk
8 2 (1.20%) Palo Alto
9 1 (0.60%) Intel
9 1 (0.60%) Oracle