Hybrid/Remote GRC Job Trends

Governance, Risk Management and Compliance (GRC)
UK > Work from Home

The table below provides summary statistics and salary benchmarking for remote or hybrid work requiring GRC skills. It covers permanent job vacancies from the 6 months leading up to 26 December 2025, with comparisons to the same periods in the previous two years.

6 months to
26 Dec 2025
Same period 2024 Same period 2023
Rank 261 333 369
Rank change year-on-year +72 +36 +158
Permanent jobs citing GRC 117 114 109
As % of all permanent jobs with remote/hybrid work options 0.76% 0.66% 0.53%
As % of the Quality Assurance & Compliance category 4.34% 3.94% 3.52%
Number of salaries quoted 84 71 97
10th Percentile £43,625 £51,250 £50,000
25th Percentile £50,000 £61,250 £57,500
Median annual salary (50th Percentile) £60,000 £69,308 £70,000
Median % change year-on-year -13.43% -0.99% +7.69%
75th Percentile £84,193 £85,000 £85,000
90th Percentile £96,750 £91,250 £86,750
UK median annual salary £65,000 £69,308 £70,576
% change year-on-year -6.22% -1.80% +0.82%

All Quality Assurance and Compliance Skills
Work from Home

GRC falls under the Quality Assurance and Compliance category. For comparison with the information above, the following table provides summary statistics for all permanent job vacancies with remote or hybrid options requiring quality assurance or compliance skills.

Permanent vacancies with a requirement for quality assurance or compliance skills 2,698 2,897 3,095
As % of all permanent jobs with a WFH option 17.57% 16.83% 15.15%
Number of salaries quoted 1,640 1,603 2,440
10th Percentile £35,000 £36,250 £36,250
25th Percentile £46,674 £47,500 £46,250
Median annual salary (50th Percentile) £61,000 £62,500 £60,000
Median % change year-on-year -2.40% +4.17% +3.45%
75th Percentile £80,000 £77,500 £78,750
90th Percentile £97,500 £95,000 £95,000
UK median annual salary £57,500 £60,000 £60,000
% change year-on-year -4.17% - +4.35%

GRC
Job Vacancy Trend for Remote/Hybrid Jobs

Historical trend showing the proportion of permanent IT job postings citing GRC and offering remote or hybrid work options relative to all permanent IT jobs advertised.

GRC job vacancy trend for remote/hybrid jobs

GRC
Salary Trend for Remote/Hybrid Jobs

Salary distribution trend for jobs with remote/hybrid work options citing GRC.

Salary distribution trend for jobs with remote/hybrid work options citing GRC

GRC
Salary Histogram for Remote/Hybrid Jobs

Salary distribution for jobs with remote/hybrid work options citing GRC over the 6 months to 26 December 2025.

GRC salary histogram for jobs with remote/hybrid work options

GRC
Co-Occurring Skills & Capabilities in Remote/Hybrid Jobs by Category

The following tables expand on the one above by listing co-occurrences grouped by category. They cover the same employment type, locality and period, with up to 20 co-occurrences shown in each category:

Application Platforms
1 4 (3.42%) SharePoint
2 2 (1.71%) Microsoft Exchange
Applications
1 2 (1.71%) Microsoft Office
2 1 (0.85%) Microsoft Excel
Business Applications
1 5 (4.27%) SAP GRC
2 2 (1.71%) SAP S/4HANA
Cloud Services
1 24 (20.51%) Azure
2 17 (14.53%) AWS
2 17 (14.53%) SaaS
3 8 (6.84%) GCP
3 8 (6.84%) Microsoft 365
4 7 (5.98%) Power Platform
5 4 (3.42%) Entra ID
5 4 (3.42%) GitHub
5 4 (3.42%) GitHub Actions
6 3 (2.56%) Azure Sentinel
6 3 (2.56%) Cloud Computing
7 2 (1.71%) Amazon GuardDuty
7 2 (1.71%) IaaS
7 2 (1.71%) PaaS
8 1 (0.85%) Microsoft Purview
8 1 (0.85%) Mimecast
Communications & Networking
1 16 (13.68%) Firewall
2 10 (8.55%) Network Security
3 5 (4.27%) Intrusion Detection
3 5 (4.27%) TCP/IP
3 5 (4.27%) VPN
4 4 (3.42%) DMZ
5 3 (2.56%) HTTP
6 2 (1.71%) DHCP
6 2 (1.71%) DNS
6 2 (1.71%) LAN
6 2 (1.71%) WAN
7 1 (0.85%) Wireless
7 1 (0.85%) Wireshark
Database & Business Intelligence
1 7 (5.98%) Power BI
2 6 (5.13%) Tableau
Development Applications
1 4 (3.42%) TeamCity
2 3 (2.56%) Snyk
3 1 (0.85%) Burp Suite
3 1 (0.85%) Metasploit
General
1 61 (52.14%) Social Skills
2 59 (50.43%) Finance
3 44 (37.61%) Public Sector
4 26 (22.22%) Telecoms
5 25 (21.37%) Electronics
5 25 (21.37%) Manufacturing
5 25 (21.37%) Marketing
6 18 (15.38%) Analytical Skills
7 14 (11.97%) Banking
8 8 (6.84%) Financial Institution
8 8 (6.84%) Legal
8 8 (6.84%) Retail
9 7 (5.98%) Back Office
9 7 (5.98%) Inclusion and Diversity
9 7 (5.98%) Influencing Skills
9 7 (5.98%) Law
10 2 (1.71%) Organisational Skills
10 2 (1.71%) Presentation Skills
11 1 (0.85%) Cyber-Physical System
11 1 (0.85%) Police
Job Titles
1 47 (40.17%) Consultant
2 38 (32.48%) Security Consultant
3 14 (11.97%) Analyst
4 12 (10.26%) Senior
5 10 (8.55%) Security Analyst
6 9 (7.69%) Security Engineer
6 9 (7.69%) Security Specialist
7 8 (6.84%) Security Manager
8 7 (5.98%) Cloud Engineer
9 6 (5.13%) Cloud Security Engineer
9 6 (5.13%) Cybersecurity Consultant
9 6 (5.13%) Head of IT
10 5 (4.27%) Cybersecurity Specialist
10 5 (4.27%) SAP Consultant
10 5 (4.27%) Senior Consultant
11 4 (3.42%) Cloud Automation Engineer
11 4 (3.42%) Cybersecurity Analyst
11 4 (3.42%) Information Analyst
11 4 (3.42%) IT Analyst
11 4 (3.42%) Principal Consultant
Libraries, Frameworks & Software Standards
1 25 (21.37%) SAP CAF
2 3 (2.56%) SAP Basis
3 2 (1.71%) .NET
3 2 (1.71%) SAP Fiori
3 2 (1.71%) SLSA
Miscellaneous
1 18 (15.38%) Security Posture
2 16 (13.68%) Cloud Native
3 10 (8.55%) Management Information System
4 9 (7.69%) Cloud Security Posture
5 8 (6.84%) Blog
6 6 (5.13%) Analytical Mindset
6 6 (5.13%) Taxonomies
7 5 (4.27%) Public Cloud
8 4 (3.42%) Cyber Kill Chain
8 4 (3.42%) Driving Licence
8 4 (3.42%) PKI
9 3 (2.56%) Private Cloud
10 2 (1.71%) Distributed Systems
10 2 (1.71%) Onboarding
10 2 (1.71%) Replication
11 1 (0.85%) Cyber Defence
11 1 (0.85%) Operational Technology
11 1 (0.85%) Security Operations Centre
11 1 (0.85%) Self-Motivation
11 1 (0.85%) Smart City
Operating Systems
1 5 (4.27%) Windows
2 4 (3.42%) Windows Server
3 1 (0.85%) Android
3 1 (0.85%) Apple iOS
3 1 (0.85%) Linux
Processes & Methodologies
1 77 (65.81%) Cybersecurity
2 70 (59.83%) Risk Management
3 39 (33.33%) ISMS
4 38 (32.48%) Continuous Improvement
4 38 (32.48%) Information Security
5 32 (27.35%) Business Intelligence
5 32 (27.35%) Collaborative Culture
6 25 (21.37%) Digital Marketing
6 25 (21.37%) Programme Management
7 18 (15.38%) Vulnerability Management
8 16 (13.68%) Cloud Security
9 15 (12.82%) Incident Response
9 15 (12.82%) Security Architecture
10 14 (11.97%) Decision-Making
11 13 (11.11%) Risk Assessment
11 13 (11.11%) Stakeholder Engagement
12 11 (9.40%) Security Operations
13 10 (8.55%) RBAC
14 9 (7.69%) CI/CD
14 9 (7.69%) Risk Register
Programming Languages
1 4 (3.42%) Bash
1 4 (3.42%) Go
1 4 (3.42%) Python
2 2 (1.71%) Bicep
Qualifications
1 56 (47.86%) CISM
2 55 (47.01%) CISSP
3 42 (35.90%) Security Cleared
4 35 (29.91%) ISO 27001 Lead Implementer
5 34 (29.06%) SC Cleared
6 32 (27.35%) CRISC
7 24 (20.51%) CISA
8 19 (16.24%) Degree
9 15 (12.82%) ISO 27001 Lead Auditor
10 9 (7.69%) DV Cleared
11 7 (5.98%) Master's Degree
12 5 (4.27%) CISMP
12 5 (4.27%) CompTIA Security+
13 4 (3.42%) AWS Certification
14 3 (2.56%) (ISC)2 CCSP
14 3 (2.56%) CCSP
14 3 (2.56%) CEH
14 3 (2.56%) Cisco Certification
14 3 (2.56%) NVQ Level 3
14 3 (2.56%) OSCP
Quality Assurance & Compliance
1 86 (73.50%) ISO/IEC 27001
2 63 (53.85%) NIST
3 21 (17.95%) SOC 2
4 20 (17.09%) GDPR
5 18 (15.38%) PCI DSS
6 16 (13.68%) Cyber Essentials
7 13 (11.11%) NCSC
7 13 (11.11%) NIST 800
8 9 (7.69%) Cyber Essentials PLUS
9 8 (6.84%) COBIT
9 8 (6.84%) JSP 440
10 7 (5.98%) ISO/IEC 42001
11 6 (5.13%) SOC 1
12 5 (4.27%) Data Quality
12 5 (4.27%) ITGC
13 4 (3.42%) ISO 22301
13 4 (3.42%) ISO 9001
14 3 (2.56%) ISO 14001
14 3 (2.56%) ISO/IEC 27005
14 3 (2.56%) NEBOSH
System Software
1 1 (0.85%) Active Directory
Systems Management
1 7 (5.98%) RSA Archer
2 6 (5.13%) Terraform
3 4 (3.42%) Cilium
3 4 (3.42%) Kubernetes
4 2 (1.71%) Microsoft Intune
4 2 (1.71%) Single Sign-On
5 1 (0.85%) Nessus
5 1 (0.85%) Nmap
Vendors
1 30 (25.64%) SAP
2 15 (12.82%) Microsoft
3 4 (3.42%) Google
3 4 (3.42%) Qualys
4 3 (2.56%) Checkmarx
4 3 (2.56%) Palo Alto
4 3 (2.56%) Salesforce
4 3 (2.56%) Tenable
5 2 (1.71%) ServiceNow
6 1 (0.85%) Darktrace