GRC Job Trends in the UK excluding London

Governance, Risk Management and Compliance (GRC)
UK > UK excluding London

The table below provides summary statistics and salary benchmarking for jobs advertised in the UK excluding London requiring GRC skills. It covers permanent job vacancies from the 6 months leading up to 24 January 2026, with comparisons to the same periods in the previous two years.

6 months to
24 Jan 2026
Same period 2025 Same period 2024
Rank 350 380 501
Rank change year-on-year +30 +121 +77
Permanent jobs citing GRC 182 187 113
As % of all permanent jobs in the UK excluding London 0.41% 0.53% 0.27%
As % of the Quality Assurance & Compliance category 3.71% 3.35% 1.91%
Number of salaries quoted 132 63 77
10th Percentile £45,125 £36,800 £40,000
25th Percentile £51,250 £50,000 £52,500
Median annual salary (50th Percentile) £65,000 £65,000 £65,000
Median % change year-on-year - - +12.47%
75th Percentile £75,000 £77,500 £76,250
90th Percentile £86,790 £88,500 £87,500
UK median annual salary £65,000 £69,308 £70,000
% change year-on-year -6.22% -0.99% -

All Quality Assurance and Compliance Skills
UK excluding London

GRC falls under the Quality Assurance and Compliance category. For comparison with the information above, the following table provides summary statistics for all permanent job vacancies requiring quality assurance or compliance skills in the UK excluding London.

Permanent vacancies with a requirement for quality assurance or compliance skills 4,909 5,576 5,906
As % of all permanent jobs advertised in the UK excluding London 11.10% 15.71% 13.96%
Number of salaries quoted 2,591 2,372 4,171
10th Percentile £29,000 £30,625 £26,500
25th Percentile £35,000 £40,000 £35,000
Median annual salary (50th Percentile) £50,000 £52,500 £50,000
Median % change year-on-year -4.76% +5.00% -
75th Percentile £65,640 £70,600 £65,000
90th Percentile £81,500 £83,750 £77,500
UK median annual salary £58,750 £60,000 £55,500
% change year-on-year -2.08% +8.11% -3.48%

GRC
Job Vacancy Trend in the UK excluding London

Historical trend showing the proportion of permanent IT job postings citing GRC relative to all permanent IT jobs advertised in the UK excluding London.

GRC job vacancy trend in the UK excluding London

GRC
Salary Trend in the UK excluding London

Salary distribution trend for jobs in the UK excluding London citing GRC.

Salary distribution trend for jobs in the UK excluding London citing GRC

GRC
Salary Histogram in the UK excluding London

Salary distribution for jobs citing GRC in the UK excluding London over the 6 months to 24 January 2026.

Salary histogram for GRC in the UK excluding London

GRC
Job Locations in the UK excluding London

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing GRC within the UK excluding London region over the 6 months to 24 January 2026. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
South East +58 54 £68,750 -4.51% 26
North of England -47 43 £65,000 - 21
South West +32 42 £55,000 -26.67% 4
North West -23 29 £65,000 +13.04% 12
East of England +31 14 £42,025 -15.95% 9
Yorkshire -37 13 £56,014 -17.02% 8
Wales +18 12 £63,250 -8.74% 1
Midlands +13 12 £60,000 +4.35% 8
West Midlands +33 9 £63,750 -8.02% 7
Scotland -18 4 £70,000 +9.80% 1
East Midlands -2 3 £60,000 +23.08% 1
Northern Ireland -14 1 £32,500 -53.11%
GRC
UK

GRC
Co-Occurring Skills & Capabilities in the UK excluding London by Category

The following tables expand on the one above by listing co-occurrences grouped by category. They cover the same employment type, locality and period, with up to 20 co-occurrences shown in each category:

Applications
1 1 (0.55%) MS Visio
Business Applications
1 8 (4.40%) SAP GRC
2 3 (1.65%) SAP S/4HANA
3 1 (0.55%) Integrated Workplace Management System
3 1 (0.55%) Salesforce CRM
Cloud Services
1 24 (13.19%) Azure
2 16 (8.79%) AWS
3 11 (6.04%) SaaS
4 8 (4.40%) Microsoft 365
5 4 (2.20%) GCP
6 3 (1.65%) Azure Sentinel
6 3 (1.65%) Cloud Computing
7 2 (1.10%) Amazon GuardDuty
7 2 (1.10%) Entra ID
8 1 (0.55%) Azure DevOps
8 1 (0.55%) Lucidchart
8 1 (0.55%) Mimecast
Communications & Networking
1 14 (7.69%) Firewall
2 9 (4.95%) Network Security
3 6 (3.30%) DMZ
4 2 (1.10%) HTTP
4 2 (1.10%) TCP/IP
4 2 (1.10%) VPN
5 1 (0.55%) Intrusion Detection
5 1 (0.55%) Wireless
5 1 (0.55%) Wireshark
Development Applications
1 2 (1.10%) Snyk
2 1 (0.55%) Burp Suite
2 1 (0.55%) JIRA
2 1 (0.55%) Metasploit
General
1 53 (29.12%) Social Skills
2 49 (26.92%) Finance
2 49 (26.92%) Public Sector
3 27 (14.84%) Telecoms
4 26 (14.29%) Electronics
4 26 (14.29%) Manufacturing
4 26 (14.29%) Marketing
5 21 (11.54%) Organisational Skills
6 14 (7.69%) Analytical Skills
7 11 (6.04%) Legal
8 10 (5.49%) Influencing Skills
9 6 (3.30%) Local Government
10 5 (2.75%) Inclusion and Diversity
11 3 (1.65%) Documentation Skills
12 2 (1.10%) Banking
13 1 (0.55%) Cyber-Physical System
13 1 (0.55%) Law
13 1 (0.55%) Retail
13 1 (0.55%) Social Science
Job Titles
1 60 (32.97%) Consultant
2 53 (29.12%) Security Consultant
3 32 (17.58%) Security Manager
4 29 (15.93%) Compliance Manager
5 27 (14.84%) Analyst
6 25 (13.74%) Cybersecurity Manager
7 19 (10.44%) Risk Manager
8 16 (8.79%) Security Assurance Manager
9 13 (7.14%) Security Analyst
10 12 (6.59%) Cybersecurity Consultant
11 11 (6.04%) Governance Manager
12 10 (5.49%) Senior
13 9 (4.95%) Security Compliance Manager
14 7 (3.85%) Cybersecurity Analyst
15 6 (3.30%) Head of IT
15 6 (3.30%) Principal Consultant
15 6 (3.30%) Security Engineer
16 5 (2.75%) Information Security Manager
16 5 (2.75%) Risk Analyst
16 5 (2.75%) SAP Consultant
Libraries, Frameworks & Software Standards
1 26 (14.29%) SAP CAF
2 3 (1.65%) .NET
2 3 (1.65%) SAP Basis
3 2 (1.10%) SAP Fiori
3 2 (1.10%) SLSA
4 1 (0.55%) ADO
4 1 (0.55%) EDI
4 1 (0.55%) ModSecurity
Miscellaneous
1 28 (15.38%) Security Posture
2 13 (7.14%) Cloud Native
3 11 (6.04%) Management Information System
4 10 (5.49%) Cloud Security Posture
5 7 (3.85%) Cyber Threat
6 6 (3.30%) Blog
6 6 (3.30%) Cyber Kill Chain
6 6 (3.30%) PKI
7 5 (2.75%) Public Cloud
8 4 (2.20%) Data Protection Act
8 4 (2.20%) Onboarding
8 4 (2.20%) Security Operations Centre
9 3 (1.65%) Analytical Mindset
9 3 (1.65%) NHS
9 3 (1.65%) Private Cloud
10 2 (1.10%) Cyber Defence
10 2 (1.10%) Distributed Systems
10 2 (1.10%) Mobile App
10 2 (1.10%) Self-Motivation
11 1 (0.55%) Product Ownership
Operating Systems
1 1 (0.55%) Android
1 1 (0.55%) Apple iOS
1 1 (0.55%) Linux
1 1 (0.55%) Windows
Processes & Methodologies
1 128 (70.33%) Cybersecurity
2 70 (38.46%) Risk Management
3 52 (28.57%) Information Security
4 45 (24.73%) Continuous Improvement
5 42 (23.08%) ISMS
6 30 (16.48%) Collaborative Culture
7 26 (14.29%) Business Intelligence
7 26 (14.29%) Digital Marketing
7 26 (14.29%) Programme Management
8 16 (8.79%) Security Operations
9 15 (8.24%) Roadmaps
9 15 (8.24%) Security Architecture
10 14 (7.69%) Decision-Making
10 14 (7.69%) Incident Response
10 14 (7.69%) Security Management
11 13 (7.14%) Cloud Security
12 12 (6.59%) Data Protection
12 12 (6.59%) IT Governance
12 12 (6.59%) Service Delivery
12 12 (6.59%) Vulnerability Management
Programming Languages
1 2 (1.10%) Bicep
2 1 (0.55%) ABAP
Qualifications
1 55 (30.22%) CISSP
2 53 (29.12%) CISM
3 46 (25.27%) Security Cleared
4 36 (19.78%) ISO 27001 Lead Implementer
5 34 (18.68%) SC Cleared
6 21 (11.54%) CRISC
7 17 (9.34%) CREST Certified
8 14 (7.69%) Degree
9 13 (7.14%) ISO 27001 Lead Auditor
10 12 (6.59%) DV Cleared
11 10 (5.49%) CISA
12 7 (3.85%) CISMP
13 5 (2.75%) (ISC)2 CCSP
13 5 (2.75%) Cisco Certification
14 4 (2.20%) CESG Certified Professional
15 3 (1.65%) BPSS Clearance
15 3 (1.65%) CCSP
15 3 (1.65%) CEH
15 3 (1.65%) CGEIT
15 3 (1.65%) OSCP
Quality Assurance & Compliance
1 108 (59.34%) ISO/IEC 27001
2 84 (46.15%) NIST
3 43 (23.63%) GDPR
4 41 (22.53%) Cyber Essentials
5 38 (20.88%) PCI DSS
6 28 (15.38%) NCSC
7 25 (13.74%) Cyber Essentials PLUS
8 23 (12.64%) SOC 2
9 15 (8.24%) SOC 3
10 10 (5.49%) JSP 440
11 6 (3.30%) ISO/IEC 42001
12 5 (2.75%) NIST 800
13 3 (1.65%) ISO 22301
13 3 (1.65%) Sarbanes-Oxley
14 2 (1.10%) California Consumer Privacy Act
14 2 (1.10%) Def Stans
14 2 (1.10%) QA
14 2 (1.10%) SLA
15 1 (0.55%) Accessibility
15 1 (0.55%) WCAG
System Software
1 1 (0.55%) Active Directory
Systems Management
1 2 (1.10%) RSA Archer
1 2 (1.10%) Single Sign-On
1 2 (1.10%) Terraform
2 1 (0.55%) Microsoft Intune
2 1 (0.55%) Nessus
2 1 (0.55%) Nmap
Vendors
1 35 (19.23%) SAP
2 10 (5.49%) Microsoft
3 6 (3.30%) ServiceNow
4 4 (2.20%) Google
4 4 (2.20%) Salesforce
5 3 (1.65%) Palo Alto
5 3 (1.65%) Qualys
5 3 (1.65%) Tenable
6 2 (1.10%) Checkmarx
7 1 (0.55%) Planon