Skip to main content
Governance & risk

GRC (Audit, Risk, Compliance)

Governance, risk and compliance. Policy, audit, evidence, frameworks. Biased toward CISA / CRISC / CISM, NOT toward OSCP.

Last reviewed May 2026Reviewed by a practitioner working in grc analyst hiringUpdated quarterly against live job listings
The verdict

The lane the technical-security crowd looks down on, and the one that quietly pays well and travels into management. Worth taking seriously if the framework work doesn't bore you.

You're comfortable with policy, audit and stakeholder management, and you'd rather write a risk paper than chase an alert. GRC is the cleanest route from non-technical backgrounds into security.

You want hands-on technical work. You'll spend most days in meetings, spreadsheets and evidence requests, and pretending otherwise leads to burnout inside a year.

Phased progression

Foundations → first role → specialisation → advanced. The realistic order, not a script.

Salary figures are POST practitioner estimates, not survey data.

  1. 01Foundations
    0–6 months

    Literacy, lab habits, the cert that opens first conversations.

    ISO 27001 Lead Implementer
  2. 02First paid role
    6–18 months

    Land a GRC Analyst. Operational time, not more certs, earns the next move.

    GRC Analyst
    £32–48k GRC analyst
  3. 03Specialisation
    1.5–3 years

    Add a specialist credential aligned to the work you're already doing.

    CRISCCGRC
    £55–80k senior
  4. 04Advanced
    3+ years

    Move into adjacent roles. Long-term credentials become worth their cost.

    Compliance SpecialistCISSP
    £85–120k GRC manager (UK; regulated firms top end)

Certification sequence

Ordered by realistic relevance, not vendor marketing.

  • CGRC

Practical projects

What to actually build, the portfolio that opens interviews.

  • Map ISO 27001 controls to a real product
  • Author a risk register with quantified risks
  • Run a tabletop exercise and write the after-action
Compliance SpecialistRisk AnalystSecurity Manager
  • ·Internal audit → security audit pivot
  • ·PM → security PM → GRC

Realistic expectations

What no recruiter will tell you.

Misconception

That GRC is the easy route. It's the easier-to-enter route, which is different. The senior end of GRC is high-stakes work with auditors, regulators and the board, and that's not a soft skill.

Honest window

Twelve to twenty-four months to first GRC role from a relevant background like audit, project management or compliance. Cold entry from a non-IT, non-business background is genuinely hard.

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

Where this fits

A pathway is a sequence, not a destination. Here are the roles and certs along it.

The next step

The pathway is plausible. Whether it holds for five years is a different question.

A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.