GRC Analyst Jobs

Specialists who ensure organisations meet regulatory requirements and manage risk effectively. A critical role in the cyber security ecosystem, bridging the gap between IT and business.

Open roles
0
Salary range
£39k – £63k

GRC Analysts play a vital role in the cyber security landscape by ensuring that organisations comply with regulatory requirements and manage risks effectively. They work closely with IT, legal, and business teams to identify, assess, and mitigate potential threats. This role is particularly important in highly regulated industries such as finance, healthcare, and government, where compliance is non-negotiable.

What the role does

Inside the role of a GRC Analyst

A typical week for a GRC Analyst is a mix of risk assessments, compliance audits, and policy development.

  1. 01
    Conduct risk assessments and identify potential vulnerabilities.
  2. 02
    Review and update compliance policies and procedures.
  3. 03
    Collaborate with cross-functional teams to address security gaps.
  4. 04
    Prepare and present compliance reports to senior management.
  5. 05
    Stay updated on the latest regulatory changes and industry best practices.
Salary on the board

£39k – £63k

Based on advertised midpoints across the 6 UK listings priced in pounds in the last 12 months. Base salary only.

Salary visibility
50% of listings advertise a salary.
Skills & tools

What hiring managers ask for

% of 5 listings posted in the last 12 months that mention each skill, extracted from job descriptions.

Compliance
80%
ISO 27001
60%
GDPR
60%
GRC
40%
Risk Assessment
40%
Audit Support
40%
Business Continuity
20%
ITDR
20%
Technical Analysis
20%
Security Policies
20%
Third-Party Risk Assessments
20%
Security Certifications
20%
Career ladder

From Junior to Principal

A typical UK progression for grc analysts. Years are guidance — strong people move faster, and many senior folks sidestep into research, product or management.

  1. Level 1

    Junior GRC Analyst

    0–2 yrs

    Assists in risk assessments and compliance tasks, gaining foundational knowledge of regulatory requirements.

  2. Level 2

    GRC Analyst

    2–5 yrs

    Leads risk assessments and compliance audits, developing and implementing policies to mitigate risks.

  3. Level 3

    Senior GRC Analyst

    5–8 yrs

    Manages complex compliance projects, advises on regulatory changes, and mentors junior analysts.

  4. Level 4

    Principal GRC Analyst

    8+ yrs

    Strategic leader in GRC, driving organisational compliance initiatives and influencing policy at a high level.

Pathway

How to become a GRC Analyst

There's no single route, but most people follow some version of these steps.

  1. 1

    Foundational Knowledge

    Gain a solid understanding of regulatory requirements and risk management principles.

  2. 2

    Practical Experience

    Apply knowledge in real-world scenarios through risk assessments and compliance audits.

  3. 3

    Leadership Skills

    Develop leadership and project management skills to lead compliance initiatives.

  4. 4

    Specialisation

    Specialise in specific areas of GRC, such as data privacy or cybersecurity frameworks.

  5. 5

    Strategic Influence

    Influence organisational strategy and policy, ensuring alignment with regulatory requirements.

No GRC Analyst Jobs jobs right now

We don't have any matching roles at the moment, but new jobs are added daily.

Latest jobs

Cambridge University Press & Assessment (CUPA) logo

Cyber Security Lead

This role involves setting the cyber security strategy and priorities for English Learning Technology, providing expert advice on cyber risk, and leading a small security operations team. The position requires deep expertise in security governance, risk management, and cloud security, with a focus on AWS.

Cambridge University Press & Assessment (CUPA) Cambridge, Cambridgeshire, United Kingdom £71,800 – £91,600 pa
Hybrid Permanent
Darktrace logo

Frontend Software Engineer (JavaScript / TypeScript & React)

Develop and maintain dynamic, accessible user interfaces for a cutting-edge AI-driven cybersecurity platform. Collaborate with cross-functional teams to integrate frontend components with backend systems, optimise performance, and ensure scalability. Work extensively with React, TypeScript, and modern frontend tools within a security-conscious environment.

Darktrace Cambridge, CB2 3BJ, United Kingdom
Hybrid Permanent
CrowdStrike logo

Sales Development Representative , Reading)

The role involves generating and qualifying leads for CrowdStrike's SMB/Corporate sales team through outbound prospecting, lead evaluation, and scheduling product demos. The candidate will use CRM tools like Salesforce.com and run creative outreach campaigns via email and social media to identify new prospects. This position requires regular office attendance in Reading twice a week and targets individuals passionate about entering tech sales within the B2B SaaS security space.

CrowdStrike Reading, United Kingdom
Hybrid Permanent
CrowdStrike logo

Associate Platform Professional Services Consultant , GBR)

This role involves delivering and integrating Falcon Next-Gen SIEM solutions for customers, acting as a trusted technical advisor, and enabling security outcomes through log management, XDR, and SOAR capabilities. The consultant will onboard data, develop use cases, provide knowledge transfer, and collaborate with product teams to influence roadmap enhancements based on customer feedback. Work is conducted remotely with occasional travel, emphasizing hands-on technical delivery and cross-functional collaboration.

CrowdStrike United Kingdom
Remote Permanent
CrowdStrike logo

Incident Response Consultant - Weekend Shift , GBR)

Lead and conduct incident response engagements for high-profile cybersecurity breaches, performing forensic analysis across Windows, Mac, and Linux systems. Hunt for advanced threats using AI-native tools, analyze network and host data, and produce detailed reports for legal and executive stakeholders. Work weekends in a collaborative, mission-driven environment focused on stopping breaches at scale.

CrowdStrike United Kingdom
Remote Permanent Shift-work
CrowdStrike logo

Sr. Analyst, Falcon Complete , GBR)

Conduct real-time monitoring, analysis, and incident response for enterprise clients using advanced threat detection tools and AI-driven platforms. Perform malware analysis, forensic investigations, and remote remediation across Windows, Mac, and Linux environments. Develop security processes, mentor junior analysts, and contribute to thought leadership through technical communication and public speaking.

CrowdStrike United Kingdom
Remote Permanent
FAQs

Common questions

  • A degree in a relevant field such as cyber security, law, or business is typically required. Professional certifications like CRISC or CISM are also valuable.

  • Highly regulated industries such as finance, healthcare, and government are major employers of GRC Analysts.

  • Key skills include risk assessment, compliance knowledge, project management, and strong communication abilities.

  • Salary ranges can vary based on experience and location. For specific figures, refer to the salary section on this page.

Hiring grc analysts?

Post your role in 90 seconds and reach the specialist audience that already reads this page.