Governance, Risk Management and Compliance (GRC)
UK

The table below provides summary statistics for permanent job vacancies requiring GRC skills. It includes a benchmarking guide to the annual salaries offered in vacancies that cited GRC over the 6 months leading up to 31 May 2025, comparing them to the same period in the previous two years.

6 months to
31 May 2025
Same period 2024 Same period 2023
Rank 567 573 609
Rank change year-on-year +6 +36 +117
Permanent jobs citing GRC 136 359 387
As % of all permanent jobs advertised in the UK 0.24% 0.35% 0.40%
As % of the Quality Assurance & Compliance category 1.48% 2.61% 2.19%
Number of salaries quoted 100 302 294
10th Percentile £48,950 £42,500 £46,475
25th Percentile £55,875 £47,563 £54,500
Median annual salary (50th Percentile) £72,500 £57,500 £65,000
Median % change year-on-year +26.09% -11.54% -1.89%
75th Percentile £83,750 £77,500 £81,250
90th Percentile £87,625 £87,500 £93,750
UK excluding London median annual salary £62,500 £50,500 £60,000
% change year-on-year +23.76% -15.83% +9.09%

All Quality Assurance and Compliance Skills
UK

GRC falls under the Quality Assurance and Compliance category. For comparison with the information above, the following table provides summary statistics for all permanent job vacancies requiring quality assurance or compliance skills.

Permanent vacancies with a requirement for quality assurance or compliance skills 9,197 13,737 17,699
As % of all permanent jobs advertised in the UK 16.47% 13.25% 18.48%
Number of salaries quoted 4,631 9,235 8,484
10th Percentile £31,250 £26,500 £32,000
25th Percentile £45,000 £36,250 £42,500
Median annual salary (50th Percentile) £60,000 £52,500 £57,500
Median % change year-on-year +14.29% -8.70% +4.55%
75th Percentile £73,000 £70,000 £76,250
90th Percentile £90,000 £90,000 £93,750
UK excluding London median annual salary £55,000 £47,500 £50,000
% change year-on-year +15.79% -5.00% +4.17%

GRC
Job Vacancy Trend

Job postings citing GRC as a proportion of all IT jobs advertised.

Job vacancy trend for GRC in the UK

GRC
Salary Trend

3-month moving average salary quoted in jobs citing GRC.

Salary trend for GRC in the UK

GRC
Salary Histogram

Salary distribution for jobs citing GRC over the 6 months to 31 May 2025.

Salary histogram for GRC in the UK

GRC
Top 16 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing GRC within the UK over the 6 months to 31 May 2025. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -26 130 £72,500 +26.09% 222
UK excluding London +28 66 £62,500 +23.76% 92
London +46 61 £77,500 +3.33% 140
Work from Home +37 44 £75,000 +25.00% 102
Midlands +51 18 £60,000 +9.09% 13
South East -24 18 £62,500 +23.76% 21
North of England +6 16 £67,500 +50.00% 23
West Midlands +41 12 £67,500 +22.73% 5
Yorkshire +51 10 £64,125 +6.88% 11
South West +106 9 £58,750 -16.07% 14
East Midlands +45 6 £57,500 -28.13% 8
North West -23 5 £70,000 +75.00% 9
Scotland +122 2 £56,250 +73.08% 6
East of England +42 2 £50,000 -31.03% 12
North East +48 1 £72,500 +13.73% 4
Wales - 1 £52,500 -

GRC
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 3 (2.21%) Confluence
2 1 (0.74%) IBM Domino
2 1 (0.74%) SharePoint
Applications
1 6 (4.41%) Microsoft Excel
2 4 (2.94%) Microsoft Office
3 1 (0.74%) Camtasia
3 1 (0.74%) Final Cut Pro
3 1 (0.74%) Microsoft PowerPoint
3 1 (0.74%) MS Visio
Business Applications
1 7 (5.15%) SAP GRC
2 4 (2.94%) SAP S/4HANA
3 1 (0.74%) Oracle EBS R12
3 1 (0.74%) Oracle Procure-to-Pay
Cloud Services
1 13 (9.56%) Azure
2 9 (6.62%) SaaS
3 7 (5.15%) AWS
3 7 (5.15%) Microsoft 365
4 5 (3.68%) Entra ID
5 4 (2.94%) GCP
6 3 (2.21%) Azure Sentinel
6 3 (2.21%) Cloud Computing
6 3 (2.21%) Microsoft Purview
6 3 (2.21%) PaaS
6 3 (2.21%) Power Platform
7 2 (1.47%) Power Automate
8 1 (0.74%) Google Workspace
8 1 (0.74%) ShareGate
8 1 (0.74%) WhatsApp
Communications & Networking
1 5 (3.68%) Firewall
2 2 (1.47%) Network Security
3 1 (0.74%) DHCP
3 1 (0.74%) DNS
3 1 (0.74%) Intranet
Database & Business Intelligence
1 3 (2.21%) Power BI
1 3 (2.21%) SAP BW
2 1 (0.74%) Tableau
Development Applications
1 3 (2.21%) JIRA
General
1 63 (46.32%) Social Skills
2 47 (34.56%) Finance
3 32 (23.53%) Analytical Skills
4 27 (19.85%) Presentation Skills
5 16 (11.76%) Legal
6 14 (10.29%) Inclusion and Diversity
7 12 (8.82%) Banking
8 10 (7.35%) Influencing Skills
8 10 (7.35%) Law
9 8 (5.88%) Public Sector
9 8 (5.88%) Retail
10 6 (4.41%) Organisational Skills
11 4 (2.94%) Manufacturing
12 2 (1.47%) Documentation Skills
12 2 (1.47%) Dutch Language
13 1 (0.74%) Automotive
13 1 (0.74%) Military
13 1 (0.74%) Pharmaceutical
13 1 (0.74%) Telecoms
Job Titles
1 33 (24.26%) Analyst
2 18 (13.24%) Security Analyst
2 18 (13.24%) Security Manager
3 17 (12.50%) Senior
4 13 (9.56%) Consultant
4 13 (9.56%) Senior Analyst
5 12 (8.82%) Information Manager
5 12 (8.82%) Information Security Manager
5 12 (8.82%) Risk Manager
6 10 (7.35%) Information Analyst
6 10 (7.35%) Information Security Analyst
6 10 (7.35%) Lead
7 8 (5.88%) Security Engineer
7 8 (5.88%) Senior Information Analyst
7 8 (5.88%) Senior Information Security Analyst
7 8 (5.88%) Senior Security Analyst
8 7 (5.15%) IT Analyst
9 6 (4.41%) Cybersecurity Engineer
9 6 (4.41%) Risk Analyst
9 6 (4.41%) Technical Manager
Libraries, Frameworks & Software Standards
1 9 (6.62%) EDI
2 2 (1.47%) EDIFACT
2 2 (1.47%) IDoc
2 2 (1.47%) SAP Basis
2 2 (1.47%) SAP Fiori
3 1 (0.74%) ModSecurity
3 1 (0.74%) Oracle Fusion
Miscellaneous
1 17 (12.50%) Security Posture
2 16 (11.76%) Management Information System
3 7 (5.15%) Taxonomies
4 6 (4.41%) Onboarding
5 5 (3.68%) Cyber Threat
5 5 (3.68%) FMCG
5 5 (3.68%) Operational Technology
6 4 (2.94%) Analytical Mindset
7 3 (2.21%) Cyber Defence
7 3 (2.21%) Self-Motivation
8 2 (1.47%) Cyberattack
9 1 (0.74%) Animation
9 1 (0.74%) Foreign Exchange (FX)
9 1 (0.74%) Industrial Internet of Things
9 1 (0.74%) Insider Threat
9 1 (0.74%) Learning Management System
9 1 (0.74%) Life Science
9 1 (0.74%) SCADA
9 1 (0.74%) TRADACOMS
9 1 (0.74%) Video Editing
Processes & Methodologies
1 78 (57.35%) Risk Management
2 70 (51.47%) Information Security
3 67 (49.26%) Cybersecurity
4 35 (25.74%) Stakeholder Management
5 29 (21.32%) Problem-Solving
6 18 (13.24%) Continuous Improvement
7 17 (12.50%) Service Delivery
7 17 (12.50%) Vulnerability Management
8 16 (11.76%) Cloud Security
9 15 (11.03%) Incident Management
9 15 (11.03%) Security Operations
10 14 (10.29%) Incident Response
10 14 (10.29%) Information Security Governance
10 14 (10.29%) Risk Assessment
11 13 (9.56%) Agile
11 13 (9.56%) ITIL
12 12 (8.82%) IT Governance
13 11 (8.09%) Data Analysis
14 10 (7.35%) Computer Science
14 10 (7.35%) Project Management
Programming Languages
1 5 (3.68%) Python
2 4 (2.94%) PowerShell
3 3 (2.21%) JavaScript
3 3 (2.21%) R
3 3 (2.21%) SQL
4 2 (1.47%) Bash
5 1 (0.74%) Java
5 1 (0.74%) VBA
Qualifications
1 57 (41.91%) CISM
2 49 (36.03%) CISSP
3 42 (30.88%) CRISC
4 39 (28.68%) Degree
5 20 (14.71%) CISA
6 14 (10.29%) Security Cleared
7 10 (7.35%) SC Cleared
8 9 (6.62%) Master's Degree
9 6 (4.41%) ISACA
9 6 (4.41%) SANS
10 5 (3.68%) GIAC
11 4 (2.94%) Computer Science Degree
11 4 (2.94%) ISO 27001 Lead Implementer
11 4 (2.94%) PMI Certification
11 4 (2.94%) PMP
12 3 (2.21%) (ISC)2 CCSP
12 3 (2.21%) CCSP
12 3 (2.21%) Cisco Certification
12 3 (2.21%) ISO 27001 Lead Auditor
13 2 (1.47%) SAP Certification
Quality Assurance & Compliance
1 65 (47.79%) NIST
2 63 (46.32%) ISO/IEC 27001
3 24 (17.65%) PCI DSS
4 23 (16.91%) GDPR
5 14 (10.29%) Cyber Essentials
6 12 (8.82%) SOC 2
7 11 (8.09%) Cyber Essentials PLUS
8 9 (6.62%) NIST 800
9 7 (5.15%) COBIT
9 7 (5.15%) NCSC
9 7 (5.15%) SOC 1
10 6 (4.41%) JSP 440
11 5 (3.68%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
12 4 (2.94%) Sarbanes-Oxley
13 2 (1.47%) ITGC
14 1 (0.74%) AICPA
14 1 (0.74%) Data Quality
14 1 (0.74%) GxP
14 1 (0.74%) QA
System Software
1 2 (1.47%) Active Directory
Systems Management
1 11 (8.09%) RSA Archer
2 3 (2.21%) Microsoft Intune
3 2 (1.47%) Nessus
4 1 (0.74%) Computer Emergency Response Teams
4 1 (0.74%) Single Sign-On
4 1 (0.74%) Terraform
Vendors
1 17 (12.50%) Microsoft
2 15 (11.03%) ServiceNow
3 7 (5.15%) SAP
4 3 (2.21%) Google
4 3 (2.21%) Infor
5 2 (1.47%) OneTrust
5 2 (1.47%) Tenable
6 1 (0.74%) Atlassian
6 1 (0.74%) Foundry
6 1 (0.74%) Oracle
6 1 (0.74%) Palantir