Hybrid/Remote GRC Job Trends

Governance, Risk Management and Compliance (GRC)
UK > Work from Home

The table below provides summary statistics and salary benchmarking for remote or hybrid work requiring GRC skills. It covers permanent job vacancies from the 6 months leading up to 30 December 2025, with comparisons to the same periods in the previous two years.

6 months to
30 Dec 2025
Same period 2024 Same period 2023
Rank 260 341 364
Rank change year-on-year +81 +23 +162
Permanent jobs citing GRC 118 113 112
As % of all permanent jobs with remote/hybrid work options 0.78% 0.66% 0.55%
As % of the Quality Assurance & Compliance category 4.39% 3.91% 3.61%
Number of salaries quoted 85 70 100
10th Percentile £44,000 £51,125 £50,000
25th Percentile £50,000 £61,563 £57,500
Median annual salary (50th Percentile) £60,000 £69,308 £70,000
Median % change year-on-year -13.43% -0.99% +7.69%
75th Percentile £85,000 £86,250 £83,125
90th Percentile £96,500 £91,750 £86,375
UK median annual salary £65,000 £69,308 £70,576
% change year-on-year -6.22% -1.80% +0.82%

All Quality Assurance and Compliance Skills
Work from Home

GRC falls under the Quality Assurance and Compliance category. For comparison with the information above, the following table provides summary statistics for all permanent job vacancies with remote or hybrid options requiring quality assurance or compliance skills.

Permanent vacancies with a requirement for quality assurance or compliance skills 2,690 2,890 3,102
As % of all permanent jobs with a WFH option 17.70% 16.91% 15.13%
Number of salaries quoted 1,634 1,586 2,441
10th Percentile £35,000 £36,250 £36,250
25th Percentile £47,000 £47,500 £46,250
Median annual salary (50th Percentile) £62,250 £62,500 £60,000
Median % change year-on-year -0.40% +4.17% +3.40%
75th Percentile £80,000 £77,500 £78,750
90th Percentile £97,500 £95,000 £95,000
UK median annual salary £58,000 £60,000 £60,000
% change year-on-year -3.33% - +4.35%

GRC
Job Vacancy Trend for Remote/Hybrid Jobs

Historical trend showing the proportion of permanent IT job postings citing GRC and offering remote or hybrid work options relative to all permanent IT jobs advertised.

GRC job vacancy trend for remote/hybrid jobs

GRC
Salary Trend for Remote/Hybrid Jobs

Salary distribution trend for jobs with remote/hybrid work options citing GRC.

Salary distribution trend for jobs with remote/hybrid work options citing GRC

GRC
Salary Histogram for Remote/Hybrid Jobs

Salary distribution for jobs with remote/hybrid work options citing GRC over the 6 months to 30 December 2025.

GRC salary histogram for jobs with remote/hybrid work options

GRC
Co-Occurring Skills & Capabilities in Remote/Hybrid Jobs by Category

The following tables expand on the one above by listing co-occurrences grouped by category. They cover the same employment type, locality and period, with up to 20 co-occurrences shown in each category:

Application Platforms
1 4 (3.39%) SharePoint
2 2 (1.69%) Microsoft Exchange
Applications
1 2 (1.69%) Microsoft Office
2 1 (0.85%) Microsoft Excel
Business Applications
1 5 (4.24%) SAP GRC
2 2 (1.69%) SAP S/4HANA
Cloud Services
1 24 (20.34%) Azure
2 17 (14.41%) AWS
2 17 (14.41%) SaaS
3 8 (6.78%) GCP
3 8 (6.78%) Microsoft 365
4 7 (5.93%) Power Platform
5 4 (3.39%) Entra ID
5 4 (3.39%) GitHub
5 4 (3.39%) GitHub Actions
6 3 (2.54%) Azure Sentinel
6 3 (2.54%) Cloud Computing
7 2 (1.69%) Amazon GuardDuty
7 2 (1.69%) IaaS
7 2 (1.69%) PaaS
8 1 (0.85%) Microsoft Purview
8 1 (0.85%) Mimecast
Communications & Networking
1 16 (13.56%) Firewall
2 10 (8.47%) Network Security
3 5 (4.24%) Intrusion Detection
3 5 (4.24%) TCP/IP
3 5 (4.24%) VPN
4 4 (3.39%) DMZ
5 3 (2.54%) HTTP
6 2 (1.69%) DHCP
6 2 (1.69%) DNS
6 2 (1.69%) LAN
6 2 (1.69%) WAN
7 1 (0.85%) Wireless
7 1 (0.85%) Wireshark
Database & Business Intelligence
1 7 (5.93%) Power BI
2 6 (5.08%) Tableau
Development Applications
1 4 (3.39%) TeamCity
2 3 (2.54%) Snyk
3 1 (0.85%) Burp Suite
3 1 (0.85%) Metasploit
General
1 62 (52.54%) Social Skills
2 60 (50.85%) Finance
3 44 (37.29%) Public Sector
4 26 (22.03%) Telecoms
5 25 (21.19%) Electronics
5 25 (21.19%) Manufacturing
5 25 (21.19%) Marketing
6 18 (15.25%) Analytical Skills
7 14 (11.86%) Banking
8 8 (6.78%) Financial Institution
8 8 (6.78%) Influencing Skills
8 8 (6.78%) Legal
8 8 (6.78%) Retail
9 7 (5.93%) Back Office
9 7 (5.93%) Inclusion and Diversity
9 7 (5.93%) Law
10 2 (1.69%) Local Government
10 2 (1.69%) Organisational Skills
10 2 (1.69%) Presentation Skills
11 1 (0.85%) Police
Job Titles
1 47 (39.83%) Consultant
2 38 (32.20%) Security Consultant
3 14 (11.86%) Analyst
4 12 (10.17%) Senior
5 10 (8.47%) Security Analyst
6 9 (7.63%) Security Engineer
6 9 (7.63%) Security Specialist
7 8 (6.78%) Security Manager
8 7 (5.93%) Cloud Engineer
8 7 (5.93%) Head of IT
9 6 (5.08%) Cloud Security Engineer
9 6 (5.08%) Cybersecurity Consultant
10 5 (4.24%) Cybersecurity Specialist
10 5 (4.24%) SAP Consultant
10 5 (4.24%) Senior Consultant
11 4 (3.39%) Cybersecurity Analyst
11 4 (3.39%) Information Analyst
11 4 (3.39%) Information Security Analyst
11 4 (3.39%) IT Analyst
11 4 (3.39%) Principal Consultant
Libraries, Frameworks & Software Standards
1 25 (21.19%) SAP CAF
2 3 (2.54%) SAP Basis
3 2 (1.69%) .NET
3 2 (1.69%) SAP Fiori
3 2 (1.69%) SLSA
Miscellaneous
1 18 (15.25%) Security Posture
2 16 (13.56%) Cloud Native
3 10 (8.47%) Management Information System
4 9 (7.63%) Cloud Security Posture
5 8 (6.78%) Blog
6 6 (5.08%) Analytical Mindset
6 6 (5.08%) Taxonomies
7 5 (4.24%) Public Cloud
8 4 (3.39%) Cyber Kill Chain
8 4 (3.39%) Driving Licence
8 4 (3.39%) PKI
9 3 (2.54%) Private Cloud
10 2 (1.69%) Distributed Systems
10 2 (1.69%) Onboarding
10 2 (1.69%) Replication
11 1 (0.85%) Cyber Defence
11 1 (0.85%) Operational Technology
11 1 (0.85%) Security Operations Centre
11 1 (0.85%) Self-Motivation
11 1 (0.85%) Smart City
Operating Systems
1 5 (4.24%) Windows
2 4 (3.39%) Windows Server
3 1 (0.85%) Android
3 1 (0.85%) Apple iOS
3 1 (0.85%) Linux
Processes & Methodologies
1 77 (65.25%) Cybersecurity
2 70 (59.32%) Risk Management
3 39 (33.05%) Continuous Improvement
3 39 (33.05%) ISMS
4 38 (32.20%) Information Security
5 32 (27.12%) Business Intelligence
5 32 (27.12%) Collaborative Culture
6 25 (21.19%) Digital Marketing
6 25 (21.19%) Programme Management
7 18 (15.25%) Vulnerability Management
8 16 (13.56%) Cloud Security
9 15 (12.71%) Decision-Making
9 15 (12.71%) Incident Response
9 15 (12.71%) Security Architecture
10 13 (11.02%) Risk Assessment
10 13 (11.02%) Stakeholder Engagement
11 11 (9.32%) Security Operations
12 10 (8.47%) RBAC
13 9 (7.63%) CI/CD
13 9 (7.63%) Risk Register
Programming Languages
1 4 (3.39%) Bash
1 4 (3.39%) Go
1 4 (3.39%) Python
2 2 (1.69%) Bicep
Qualifications
1 56 (47.46%) CISM
2 55 (46.61%) CISSP
3 42 (35.59%) Security Cleared
4 35 (29.66%) ISO 27001 Lead Implementer
5 34 (28.81%) SC Cleared
6 32 (27.12%) CRISC
7 24 (20.34%) CISA
8 20 (16.95%) Degree
9 15 (12.71%) ISO 27001 Lead Auditor
10 9 (7.63%) DV Cleared
11 7 (5.93%) Master's Degree
12 5 (4.24%) CISMP
12 5 (4.24%) CompTIA Security+
13 4 (3.39%) AWS Certification
14 3 (2.54%) (ISC)2 CCSP
14 3 (2.54%) CCSP
14 3 (2.54%) CEH
14 3 (2.54%) Cisco Certification
14 3 (2.54%) NVQ Level 3
14 3 (2.54%) OSCP
Quality Assurance & Compliance
1 86 (72.88%) ISO/IEC 27001
2 63 (53.39%) NIST
3 21 (17.80%) SOC 2
4 20 (16.95%) GDPR
5 18 (15.25%) PCI DSS
6 16 (13.56%) Cyber Essentials
7 13 (11.02%) NCSC
7 13 (11.02%) NIST 800
8 9 (7.63%) Cyber Essentials PLUS
9 8 (6.78%) COBIT
9 8 (6.78%) JSP 440
10 7 (5.93%) ISO/IEC 42001
11 6 (5.08%) SOC 1
12 5 (4.24%) Data Quality
12 5 (4.24%) ITGC
13 4 (3.39%) ISO 22301
13 4 (3.39%) ISO 9001
14 3 (2.54%) ISO 14001
14 3 (2.54%) ISO/IEC 27005
14 3 (2.54%) NEBOSH
System Software
1 1 (0.85%) Active Directory
Systems Management
1 7 (5.93%) RSA Archer
2 6 (5.08%) Terraform
3 4 (3.39%) Cilium
3 4 (3.39%) Kubernetes
4 2 (1.69%) Microsoft Intune
4 2 (1.69%) Single Sign-On
5 1 (0.85%) Nessus
5 1 (0.85%) Nmap
Vendors
1 30 (25.42%) SAP
2 15 (12.71%) Microsoft
3 4 (3.39%) Google
3 4 (3.39%) Qualys
4 3 (2.54%) Checkmarx
4 3 (2.54%) Palo Alto
4 3 (2.54%) Salesforce
4 3 (2.54%) Tenable
5 2 (1.69%) ServiceNow
6 1 (0.85%) Darktrace