Skip to main content
RoleCybersecurity

Risk Analyst

Risk registers, control mapping, vendor reviews. Translating security into business probabilities.

POST verdict

Underrated route into security leadership, especially if you can quantify and communicate well. Skip it if you came to security for the technical work.

Domain
Cybersecurity
Entry
£32–52k
Senior
£95–135k
Pick this if
  • You can write clearly for non-technical audiences
  • You enjoy structured thinking about probability and impact
  • You can hold a risk register honest without becoming the office pessimist
  • You're targeting risk leadership or security management within five years
Skip this if
  • You wanted hands-on security work
  • You can't bear meetings about meetings
  • You'd struggle to push back on optimistic engineering or business cases
  • Your risk register reflects reality, not preferences
  • Engineering and business owners take your assessments seriously
  • Your reports change at least one decision per quarter
  • You can quantify a risk credibly without spurious precision
The bit you're probably underestimating

Most risk analyst seats sit inside GRC and inherit its problems: under-resourced, under-empowered, and easy to ignore unless you make yourself useful. The risk people who progress treat the role as a leadership apprenticeship, build credibility with engineering and finance, and earn their seat at the table over years. The ones who treat it as filing get filed.

Hover any chip for the calibrated meaning. Ratings are directional, not absolute.

Senior Risk / GRC Manager; CISO lane possible with operational background.

  • +Audit
  • +Consulting
  • +Senior IT
  • That risk work doesn't need technical depth. The best risk analysts read architecture diagrams fluently.
  • Compliance
  • GRC
  • Security Manager

Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

You've read about the role. The harder question is whether it's the right one for you.

A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.