A GRC (Governance, Risk & Compliance) Analyst makes sure an organisation's security aligns with policy, risk appetite and regulation — the bridge between security and the business.
Role overview
GRC Analysts assess risk, map controls to frameworks (ISO 27001, NIST, Cyber Essentials), run audits and manage policy. It suits people who combine security understanding with strong communication and organisation.
Typical responsibilities
- Assess and document security risks and controls.
- Map controls to frameworks and support audits.
- Maintain policies, standards and evidence.
- Track remediation and report risk to stakeholders.
Required technical skills
- Security fundamentals & risk concepts
- Control frameworks (ISO 27001, NIST, Cyber Essentials)
- Identity & access governance
- Incident and vulnerability awareness
- Evidence and audit management
Required soft skills
- Excellent written communication
- Stakeholder management
- Attention to detail
- Organisation and prioritisation
- Diplomacy and influence
Recommended learning paths (vendor-neutral)
Understand a core concept
The Risk Management Lifecycle
How governance, risk and compliance turns uncertainty into decisions.
Tap or hover a part to learn more.
Find the risks.
Catalogue assets, threats and vulnerabilities. You cannot manage a risk you have not identified — asset inventories and threat modelling feed this step.
Check your understanding
1. Which risk treatment moves the risk to a third party?
2. What do you calculate when assessing a risk?
Concepts to master — your readiness map
Work through these interactive Academy guides, marking each complete to build your Job Readiness Score for this role:
- CompTIA Security+ (overview)
- Governance, Risk & Compliance
- Identity & Access Management
- Threats, Attacks & Vulnerabilities
Recommended certifications
- CompTIA Security+
- ISO 27001 Lead Implementer / CRISC — on the Academy roadmap
Technical interview preparation
- What is the difference between a risk, a threat and a vulnerability?
- How would you map controls to a framework like ISO 27001?
- How do you prioritise remediation of findings?
Behavioural interview preparation
- Describe persuading a team to fix a compliance gap.
- Tell me about presenting risk to senior leadership.
Career progression
GRC Analyst → Senior GRC / Risk Analyst → GRC Manager or Security/Compliance Lead, with CRISC, CISM or ISO 27001 credentials.
Typical UK salary
Typically £30,000–£45,000 in the UK, rising to £55,000–£75,000+ for senior and management roles.
Prepare with Missiora
- AI Interview™ — run a scored mock interview for this exact role.
- Career Coach™ — get a personalised path from where you are to this role.
- Career Passport™ — evidence your skills and earn shareable achievements as your readiness grows.
