Makes sure an organization's security and IT practices meet laws, contracts and standards like SOC 2, ISO 27001 and NIST, and tracks risk. BLS does not publish separate figures for compliance officers; it counts them within compliance officer (SOC 13-1041), whose median pay is $80,730 a year (BLS OEWS, May 2025). Typical entry-level education: Bachelor's degree.
- SOC 13-1041
- Business and Financial Operations
- Last updated October 9, 2026
At a glance
GRC Analyst in four numbers
- Median pay
- $80,730a year, or $38.81/hrBLS OEWS, May 2025Lowest 10% $48KTop 10% $134K
US median, all jobs: $50,980
- Projected growth
- +3.8%About as fast as averageBLS EP, 2025–2035This career+3.8%All jobs+3.5%
Projected employment change, 2025–2035 Item Value This career +3.8% All jobs +3.5% - Openings a year
- 32,700436,400 jobs todayBLS EP, 2025–2035
- Jobs in 2025436.4K
- Projected 2035453.1K
Employment, 2025–2035 Item Value Jobs in 2025 436.4K Projected 2035 453.1K - Typical education
- Bachelor'sneeded to enterBLS EP, 2025–2035; mix: O*NET
Also advertised as: Governance, Risk and Compliance Analyst, IT Risk Analyst, Cybersecurity Compliance Analyst, Information Security Risk Analyst, IT Compliance Analyst.
Pay
How much do Compliance Officers make?
Every grc analyst in the US, by percentile of annual wage
Median
$80,730
Middle half earn $61,280 to $109,010
- 10th
- $48,220
- 25th
- $61,280
- 75th
- $109,010
- 90th
- $133,720
All US occupations: $50,980
| Percentile | Value |
|---|---|
| 10th | $48,220 |
| 25th | $61,280 |
| Median | $80,730 |
| 75th | $109,010 |
| 90th | $133,720 |
| All US occupations | $50,980 |
Source: BLS OEWS, May 2025
- Median annual wage
- $80,730
- Median hourly wage
- $38.81/hr
- Mean annual wage
- $88,400
- People employed
- 417,070
Versus all US occupations
At $80,730, Compliance Officers earn 58% above the $50,980 median across all US occupations, a difference of $29,750 a year.
Versus business and financial operations occupations
The median is typical for the Business and Financial Operations group, where the middle occupation pays $80,730.
Pay range
The top 10% earn $133,720 or more while the bottom 10% earn $48,220, a gap of 2.8×. That is a typical spread for a US occupation.
Rank in the bank
This median pays more than 60% of the 1,741 occupations in the NueCareer career bank.
Highest-paying state
District of Columbia pays the most at $111,030, and still leads at $101,027 once local prices are taken into account.
Pay by state
Which states pay Compliance Officers the most?
State medians come from the same OEWS release as the national figures. The cost-of-living column divides each state median by that state's BEA Regional Price Parity, restating pay in national-average dollars so a high-cost state and a low-cost one can be compared directly.
| State | Median | COL-adjusted | Employed |
|---|---|---|---|
| 1District of Columbia | $111,030 | $101,027 | 4,380 |
| 2Massachusetts | $102,060 | $96,504 | 13,190 |
| 3New Jersey | $100,000 | $91,908 | 13,310 |
| 4California | $96,980 | $87,590 | 49,880 |
| 5Connecticut | $91,810 | $88,611 | 3,610 |
| 6Delaware | $91,050 | $91,225 | 2,150 |
| 7Vermont | $90,420 | $92,305 | 1,960 |
| 8New York | $90,080 | $83,468 | 23,500 |
| 9Washington | $88,790 | $82,971 | 11,130 |
| 10Rhode Island | $87,620 | $85,667 | 970 |
Job outlook
Is GRC Analyst a growing career?
Employment change over 2025–2035, against every US occupation
About as fast as average. +3.8% projected growth vs 3.5% for all occupations.
| Item | Value |
|---|---|
| Compliance Officers | +3.8% |
| All US occupations | +3.5% |
Source: BLS EP, 2025–2035
About as fast as average
BLS projects employment of Compliance Officers to change 3.8% over 2025–2035, against 3.5% projected for all occupations. That is 16,700 more jobs.
Annual openings
About 32,700 openings are projected each year, 7.5% of the 436,400 jobs that existed in 2025. Most come from workers leaving the occupation, not from growth alone.
Getting in
How to become a GRC Analyst
A bachelor's degree in information systems, cybersecurity, business or accounting is typical. The role suits organized, detail-oriented people who can translate between technical teams and auditors, and it requires less hands-on technical work than other security jobs.
ISACA's Certified in Risk and Information Systems Control (CRISC) and Certified Information Security Manager (CISM), and ISC2's Certified in Governance, Risk and Compliance (CGRC), are respected credentials. CompTIA Security+ is a common first step. Many GRC analysts come from audit, compliance, IT support or project coordination roles.
- 1
Typical entry-level education
Bachelor's degree
- 2
Work experience in a related occupation
None
- 3
Typical on-the-job training
Moderate-term on-the-job training
- 4
Preparation needed (O*NET job zone)
Medium preparation
BLS Employment Projections, 2025–2035; job zone from O*NET 31.0 Database.
The work
What does a GRC Analyst do?
GRC analysts handle the governance, risk and compliance side of cybersecurity. Organizations must prove to customers, auditors and regulators that they protect data properly, under frameworks such as SOC 2, ISO/IEC 27001, PCI DSS, HIPAA and the NIST Cybersecurity Framework. GRC analysts map the organization's controls to those requirements, collect evidence that controls work, and coordinate with auditors.
They also run risk assessments, keep a risk register, review vendors' security, and write or update security policies. When a gap is found, they work with IT and engineering owners on a remediation plan and track it to completion. In government contracting, the role often centers on the NIST Risk Management Framework and system authorizations.
Day-to-day tasks
- Map security controls to frameworks such as SOC 2 and ISO 27001
- Collect and organize audit evidence
- Run IT and security risk assessments
- Maintain the organization's risk register
- Review vendors' security questionnaires and reports
- Write and update security policies
- Track remediation of audit findings
Typical tasks, researched by NueCareer from the sources below.
Working conditions and hours
GRC analysts work at software companies, banks, healthcare organizations, government contractors, consultancies and audit firms. The work is desk-based with many meetings and documents. It is one of the most remote-friendly roles in security. Workloads rise before annual audits and certification renewals.
Where the work happens
Indoors, climate-controlled
NeverEvery dayOutdoors in all weather
NeverEvery day
Physical demands
Sitting
NeverAlmost all the timeStanding
NeverAlmost all the timeBending or twisting
NeverAlmost all the time
Working with people
Contact with other people
NoneConstantConstant contact with other people.
Face-to-face discussions
NeverEvery dayDealing with the public
Not importantExtremely importantDealing with customers or the public is very important.
Pressure and stakes
Strict deadlines
NeverEvery dayConflict situations
NeverEvery dayHandling conflict situations at least monthly.
Cost of a mistake
Not seriousExtremely serious
Autonomy
Freedom to decide
NoneA lot
Conditions: O*NET Work Context survey. Each item has its own scale, so each dot is read against the two answers that end its own line.
Core skills
O*NET importance, 1 to 5
- Reading Comprehension4.0
- Speaking3.9
- Active Listening3.8
- Writing3.8
- Critical Thinking3.5
- Monitoring3.4
- Active Learning3.0
- Learning Strategies2.9
| Item | Value |
|---|---|
| Reading Comprehension | 4.0 |
| Speaking | 3.9 |
| Active Listening | 3.8 |
| Writing | 3.8 |
| Critical Thinking | 3.5 |
| Monitoring | 3.4 |
| Active Learning | 3.0 |
| Learning Strategies | 2.9 |
Source: O*NET 31.0 Database
Transferable skills
O*NET importance, 1 to 5
- Judgment and Decision Making3.6
- Social Perceptiveness3.5
- Persuasion3.3
- Complex Problem Solving3.3
- Time Management3.3
- Coordination3.1
- Negotiation3.1
- Service Orientation3.1
| Item | Value |
|---|---|
| Judgment and Decision Making | 3.6 |
| Social Perceptiveness | 3.5 |
| Persuasion | 3.3 |
| Complex Problem Solving | 3.3 |
| Time Management | 3.3 |
| Coordination | 3.1 |
| Negotiation | 3.1 |
| Service Orientation | 3.1 |
Source: O*NET 31.0 Database
Tools and software
- Data base user interface and query software · in demand
- Electronic mail software · in demand
- Office suite software · in demand
- Operating system software · in demand
- Presentation software · in demand
- Spreadsheet software · in demand
- Word processing software · in demand
- Computer based training software
- Graphics or photo imaging software
- Optical character reader OCR or scanning software
“In demand” marks an O*NET Employer-Based Hot Technology, software named in real job postings for this occupation.
Personality fit
What personality type suits a GRC Analyst?
NueCareer estimate (Holland code CIE) built on O*NET's Compliance Officer profile, scored 1 to 7
| Axis | GRC Analyst |
|---|---|
| Realistic | 3 |
| Investigative | 4 |
| Artistic | 1 |
| Social | 3 |
| Enterprising | 4 |
| Conventional | 6 |
Source: O*NET 31.0 Database
What the work is built around
Day to day this is work built around organising, following procedures and working precisely with data, combined with leading, persuading, selling and making decisions.
- Conventional6.3
- Enterprising4.4
- Investigative3.9
- Social3.0
- Realistic2.5
- Artistic1.0
Closest MBTI types
NueCareer fit scores: cosine similarity between each MBTI type's interest vector and this occupation's O*NET interest profile. Not a BLS or O*NET figure; the method is documented on our methodology page.
Questions
GRC Analyst: frequently asked questions
How much do Compliance Officers make?
BLS does not publish a separate wage for compliance officers. It counts them within compliance officer, whose median pay is $80,730 a year (BLS OEWS, May 2025). The middle half of that occupation earn between $61,280 and $109,010, and the top 10% earn $133,720 or more.
Do you need a degree to become a GRC Analyst?
Yes. BLS reports a bachelor's degree as the typical entry-level education for Compliance Officers, and O*NET rates the preparation needed as medium preparation. BLS also lists moderate-term on-the-job training as typical on-the-job training.
Is GRC Analyst a growing career?
It is stable rather than fast-growing: employment is projected to change 3.8% over 2025–2035, about the same as the 3.5% projected across all occupations (BLS EP, 2025–2035). BLS still projects about 32,700 openings a year, mostly from workers retiring or moving to other work.
What does a GRC Analyst do?
GRC analysts handle the governance, risk and compliance side of cybersecurity. A typical task: map security controls to frameworks such as SOC 2 and ISO 27001. Employers most often ask for Data base user interface and query software, Electronic mail software, Office suite software.
Which states pay Compliance Officers the most?
The highest state medians for Compliance Officers are District of Columbia ($111,030), Massachusetts ($102,060), New Jersey ($100,000) (BLS OEWS, May 2025).
What personality type suits a GRC Analyst?
O*NET scores Compliance Officers highest on the Conventional, Enterprising and Investigative interest areas, so the work mixes organising, following procedures and working precisely with data with leading, persuading, selling and making decisions. On NueCareer's MBTI-to-interest mapping the closest types are ESTJ, ISTJ. Personality is a fit signal, not a gate. The free NueCareer quiz scores your own profile against all 1,731 careers in the bank.






