#10 MOST IN-DEMAND BRANCH

Governance, Risk & Compliance

Every new privacy law and industry regulation creates more GRC headcount, and unlike a lot of hands-on-keyboard security work, this branch is a realistic path in for people coming from law, audit, or business backgrounds rather than IT — from day-to-day compliance tracking up through formal auditing and enterprise risk management.

Roles below are ordered most in-demand first, based on 2026 job-posting volume and pay signals from ZipRecruiter, Glassdoor, Payscale, and Salary.com — every role in this branch is included, none skipped.
Also part of this branch: these didn't get their own full write-up (either lower hiring volume today or usually folded into one of the roles above), but they're real, legitimate specialties within Governance, Risk & Compliance too.
Third-Party / Vendor Risk AnalystCyber Risk Quantification AnalystSecurity Program Manager
#1 MOST IN DEMAND

GRC Analyst

Turns laws and frameworks into policies the company can actually follow — and checks that it does.

What it's about & how to get in

You help translate security requirements, laws, industry frameworks like NIST or ISO 27001, and internal policy, into things the rest of the company can actually follow, then check that they're actually following them. Day to day that looks like running risk assessments, maintaining policy documents, tracking audit findings to resolution, and answering security questionnaires from customers and partners.

It's one of the more approachable entry points into cybersecurity for people who are strong writers and organized thinkers but aren't looking to spend their day in a terminal.

Where you can work

  • Internal GRC or security compliance teams at mid-size and large companies
  • Consulting and audit firms (including the Big Four) running compliance engagements for clients
  • Healthcare organizations managing HIPAA compliance
  • Financial services companies managing SOX, PCI-DSS, and similar frameworks
  • SaaS companies maintaining SOC 2 compliance to close enterprise sales deals

What it pays

Reported average pay is about $97,700/yr, though the range is wide, most postings fall between $55,000 and $111,000 — ZipRecruiter, September 2026, reflecting how much this role’s scope (and pay) varies by industry and company size.
#2 MOST IN DEMAND

Compliance Analyst

Focused on passing specific audits — SOC 2, ISO 27001, PCI-DSS, HIPAA.

What it's about & how to get in

A close cousin of the GRC analyst role, usually with a narrower focus on making sure the company passes specific audits and certifications, SOC 2, ISO 27001, PCI-DSS, HIPAA, rather than the broader risk-management side of GRC. You gather evidence for auditors, manage compliance tracking software, coordinate with different departments to close gaps before an audit, and keep required documentation current.

It's often the first compliance-track role someone takes, sometimes moving in from an audit, legal, or general IT background rather than a security one.

Where you can work

  • In-house compliance teams, often reporting into legal, IT, or a dedicated GRC function
  • SaaS companies pursuing SOC 2 or ISO 27001 certification for the first time
  • Healthcare providers and their business associates (HIPAA compliance)
  • Payment processors and retailers handling card data (PCI-DSS)
  • Compliance-as-a-service platforms and the consulting firms built around them

What it pays

Reported average pay is about $72,900/yr, with most postings between $57,500 and $82,000 — ZipRecruiter, September 2026.

Certifications that open doors

Where you can actually learn it

#3 MOST IN DEMAND

IT / Security Risk Manager

Owns what could actually hurt the business, and helps leadership decide what to fix first.

What it's about & how to get in

You own the process of identifying what could actually hurt the business, a vendor with weak security, an unpatched system holding sensitive data, a regulatory gap, and quantifying it well enough that leadership can decide what to fix first and what risk to formally accept.

It's a step up from GRC analyst work: less document-chasing, more judgment calls, and regular reporting to senior leadership or the board about the company's risk posture. Most risk managers have several years of GRC, audit, or security analyst experience before moving into this role.

Where you can work

  • Enterprise risk management functions at large companies, often reporting to a CISO or CRO
  • Financial services firms with formal, regulator-facing risk programs
  • Insurance companies — both managing their own risk and underwriting cyber insurance for others
  • Consulting firms running third-party/vendor risk assessment engagements
  • Healthcare and critical infrastructure organizations with regulatory risk-reporting requirements

What it pays

Reported average pay for IT risk managers broadly is about $111,600/yr, with most postings between $90,000 and $129,000 (ZipRecruiter); the more specialized "Information Security Risk Manager" title reports a higher average of about $136,100/yr — both ZipRecruiter, 2026 data.

Certifications that open doors

#4 MOST IN DEMAND

Security Auditor

Runs the SOC 2 and ISO 27001 audits that prove a company's controls actually work.

What it's about & how to get in

A Security Auditor plans and executes internal or external audits — SOC 2, ISO 27001, PCI DSS, and similar frameworks — testing whether an organization's security controls are actually designed and operating effectively, then reporting findings to leadership, auditors, or certification bodies.

This is distinct from the Compliance Analyst role already on the site, which focuses on ongoing compliance tracking and control maintenance day to day; the Security Auditor instead runs the periodic, evidence-based audit engagements that GRC Analysts and Compliance Analysts prepare evidence for, and feeds findings back to IT/Security Risk Managers.

Where you can work

  • Public accounting and audit firms (Big 4 and mid-market CPA firms performing SOC 2/ISO audits)
  • Internal audit departments at large enterprises (finance, healthcare, insurance)
  • GRC and cybersecurity consulting firms
  • Certification bodies and ISO 27001 registrars
  • Government agencies and defense contractors under FISMA/FedRAMP audit requirements

What it pays

Reported average pay is about $116,280/yr, with most postings between $87,000 and $160,000 — Glassdoor, September 2026.
← Data Security All Career Paths Offensive Security (Red Team) →