R10: Comprehensive Role Roadmaps — Project Management & GRC Tracks
Status: Deep Dive Research Phase 8
Date: 30 April 2026
Scope: Dual-track career progressions with salary benchmarks, certification milestones, and lateral pivot options.
TABLE OF CONTENTS
- PM Track Overview
- GRC Track Overview
- Lateral Pivots & Cross-Track Transitions
- Key Role Distinctions
- Regional Salary Data
- Conference & Community Resources
- 2026 Updates & Certification Changes
- Sources
PM TRACK OVERVIEW
The Project Management career track follows a linear progression from tactical execution (Project Coordinator) through strategic portfolio leadership. Each tier builds on the previous, with distinct skill requirements and certification expectations.
ENTRY (0–3 years) — Project Coordinator / Junior PM / Business Analyst
Day-in-the-Life:
- Scheduling stakeholder meetings and sending status reports
- Maintaining RACI matrices and updating project schedules
- Collecting project artifacts (requirements, scope docs, risk registers)
- Learning to distinguish scope creep from legitimate changes
- First exposure to vendor management and escalation ladders
Required Core Skills:
- Scope, schedule, and budget estimation basics
- Stakeholder mapping and communication planning
- Risk register creation and basic mitigation strategies
- Document management and change control fundamentals
- Conflict resolution within a project team
Recommended Certifications:
| Certification | Vendor | URL | Notes |
|---|---|---|---|
| CAPM (Certified Associate in Project Management) | PMI | https://www.pmi.org/certifications/certified-associate-capm | Entry-level; no hours required; $555 exam fee; 3-year validity |
| PSM I (Professional Scrum Master I) | Scrum.org | https://www.scrum.org/professional-scrum-master-i-certification | Agile alternative; no prerequisites; $150 exam fee |
| CSM (Certified ScrumMaster) | Scrum Alliance | https://www.scrumalliance.org/get-certified/scrum-master-track/certified-scrummaster | 2-day course required; $85 exam fee; 2-year validity |
| PRINCE2 Foundation | AXELOS | https://www.axelos.com/certifications/prince2 | UK/EU standard; entry-level; no prerequisites; £98 exam fee |
| ITIL 4 Foundation | AXELOS | https://www.axelos.com/certifications/itil | IT-focused; no prerequisites; £105 exam fee |
Salary (2026 US):
Entry-level Project Coordinator: $51,000–$83,000 per year (Invensis Learning)
Free Resources:
- PMI Authorized Training Partners – official prep courses
- Scrum.org Free Scrum Guide – foundational reading
- Andrew Ramdayal YouTube PMP prep channel – high-quality free tutorials
- AXELOS free materials – PRINCE2/ITIL overviews
ASSOCIATE (3–5 years) — Project Manager (PMP)
Day-in-the-Life:
- Running weekly status meetings and escalation reviews
- Managing earned value metrics (BCWS, BCWP, ACWP)
- Handling vendor RFP processes and contract negotiation
- Managing project budgets and forecasting to completion
- Difficult stakeholder conversations and scope negotiations
- Leading root-cause analysis on schedule slips
Required Core Skills:
- PMBOK 6th or 7th Edition lifecycle management (Initiating, Planning, Executing, Monitoring, Closing)
- Earned Value Management (EVM) basics and variance analysis
- Vendor evaluation and procurement management
- Risk register at scale (20+ identified risks, mitigation ownership)
- RACI matrix enforcement and escalation paths
- Stakeholder management across competing priorities
Recommended Certifications:
| Certification | Vendor | URL | Notes |
|---|---|---|---|
| PMP (Project Management Professional) — NEW EXAM JULY 9, 2026 | PMI | https://www.pmi.org/certifications/project-management-pmp/new-exam | New format: 185 questions, 240 min; Business Environment 26%, Predictive 40%, Adaptive/Agile 60%; AI & sustainability focus; Early registration Dec 15, 2025; Pilot Jan 5–30, 2026; Live July 9, 2026. Current exam retires July 8, 2026. |
| PSM II (Professional Scrum Master II) | Scrum.org | https://www.scrum.org/professional-scrum-master-ii-certification | Advanced Scrum; PSM I prerequisite; $150 exam fee |
| A-CSM (Advanced Certified ScrumMaster) | Scrum Alliance | https://www.scrumalliance.org/get-certified/scrum-master-track/advanced-certified-scrummaster | 1-day workshop; Scrum Alliance membership $39/year |
| SSM (Scaled Agile SAFe Scrum Master) | Scaled Agile Inc. | https://scaledagile.com/certification/scrum-master/ | 8-hour course; $495; SAFe Level 2; salary bump 15–25% (StarAgile) |
| PRINCE2 Practitioner | AXELOS | https://www.axelos.com/certifications/prince2 | Advanced; Foundation prerequisite; £168 exam fee |
| ITIL 4 Specialist (Create, Deliver & Support / Drive Stakeholder Value) | AXELOS | https://www.axelos.com/certifications/itil | Multi-path specialization; £79–99 per module |
Salary (2026 US):
Project Manager (non-certified): $65,000–$109,000
Project Manager (PMP-certified): $120,000–$135,000 median; 29% premium over non-certified (Glassdoor; PMI 14th Edition Earning Power)
Senior PM (5–8 yrs exp): $115,000–$139,000 (Invensis Learning)
Salary (2026 UK):
PM (PRINCE2/PMP-certified): £42,000–£57,000; London: £62,000–£92,750 (Robert Half; APM Survey)
Salary (2026 South Africa):
IT Project Manager: R494,324–R1,078,473 (~USD $26,500–$58,000); Senior (8+ yrs): R1,245,907 (PayScale ZA; ERI SalaryExpert)
PROFESSIONAL (5–8 years) — Senior PM / Program Manager (PgMP)
Day-in-the-Life:
- Managing cross-project dependencies and resource conflicts
- Portfolio-level prioritization and benefit realization tracking
- Mentoring 2–3 junior PMs and team leads
- Executive steering committee presentations (CFO, CIO, board delegates)
- Program roadmap alignment with organizational strategy
- Managing $5M–$50M+ budgets across multiple teams
Required Core Skills:
- Program-scale dependency mapping (critical path across teams)
- Cross-functional team coordination and matrix org dynamics
- Benefits realization and value tracking (pre/post-project ROI)
- Portfolio prioritization and go/no-go governance
- Advanced stakeholder management (C-suite, business units, vendors)
- Risk and issue management at program scope
Recommended Certifications:
| Certification | Vendor | URL | Notes |
|---|---|---|---|
| PgMP (Program Management Professional) | PMI | https://www.pmi.org/certifications/program-management-professional-pgmp | 23 yrs PM exp or 16 yrs + Master's; median salary $135,000 (higher than PMP per PayScale); 4 hrs, 170 Q |
| RTE (Release Train Engineer, SAFe) | Scaled Agile | https://scaledagile.com/certification/safe-release-train-engineer/ | 16-hour course; $2,000–$2,500; salary bump $12,000–$24,000 (StarAgile) |
| SPC (Solutions Practice Consultant, SAFe) | Scaled Agile | https://scaledagile.com/certification/safe-practice-consultant/ | 5-day workshop; coach/consultant track; $4,500–$6,500 |
| TOGAF (The Open Group Architecture Framework) | The Open Group | https://www.opengroup.org/togaf | Enterprise architecture; 9.1 standard; cross-over with Program/Portfolio roles |
Key Books (Program Perspective):
- Project to Product (Mik Kersten, IT Revolution Press, 2018) – flow/value stream at scale
- Making Things Happen (Scott Berkun, O'Reilly, 2008) – stakeholder management & prioritization
- The Phoenix Project (Kim, Behr, Spafford, IT Revolution Press, 2013) – DevOps/Lean for IT ops
- Accelerate (Forsgren, Humble, Kim, IT Revolution Press, 2018) – metrics-driven delivery
Salary (2026 US):
Program Manager (PgMP-certified): $122,062–$162,803 median $135,000 (10% premium over PMP only) (PayScale)
EXPERT (8+ years) — Portfolio Manager / Director PMO / VP Delivery
Day-in-the-Life:
- Quarterly/annual portfolio review with board/C-suite
- Strategic alignment of all in-flight programs with business objectives
- Organizational restructuring and resource model design
- Benefits portfolio tracking (aggregate value realization)
- PMO governance policy and standard updates
- Talent development and succession planning for PM leaders
Required Core Skills:
- Portfolio-level governance and executive steering
- Strategic roadmap alignment and business case evaluation
- Organizational change management and capability building
- Budget/resource allocation across competing initiatives
- Stakeholder management at board level
- PMO operations and metrics design
Recommended Certifications:
| Certification | Vendor | URL | Notes |
|---|---|---|---|
| PfMP (Portfolio Management Professional) | PMI | https://www.pmi.org/certifications/portfolio-management-professional-pfmp | 15 yrs PM + 5 yrs portfolio exp or equiv.; median salary $130,000–$140,000; 10–15% premium over PMP (Invensis Learning) |
| TOGAF 9 Certified (Advanced) | The Open Group | https://www.opengroup.org/togaf | Architecture governance; enterprise-level strategic fit |
| Executive MBA (Finance + Strategy track) | Various Universities | – | Common for Director PMO / VP progression; $60K–$120K total cost |
Key Books (Portfolio + Executive Perspective):
- Project to Product (re-read for strategy section)
- Inspired (Marty Cagan, Wiley, 2017) – product strategy & portfolio thinking
- Empowered (Cagan & Jones, Wiley, 2020) – building high-performing delivery orgs
- The Lean Startup (Eric Ries, Crown Business, 2011) – iterative value delivery
Salary (2026 US):
Director PMO: $155,000–$230,000 (Glassdoor)
Senior Portfolio Manager: $180,000–$300,000+ (Invensis Learning)
VP Delivery: $200,000–$350,000+ (market-dependent)
GRC TRACK OVERVIEW
The Governance, Risk & Compliance career track progresses from technical audit execution through strategic compliance leadership. Certification is mandatory at every tier.
ENTRY (0–3 years) — IT Auditor (Junior) / Compliance Analyst
Day-in-the-Life:
- Preparing audit workpapers and evidence collection matrices
- Performing control testing (interviews, document review, test samples)
- Writing observations and rating findings (High/Medium/Low/Informational)
- Learning frameworks: NIST 800-53, ISO 27001, SOC 2, PCI-DSS, HIPAA
- Shadowing managers in client meetings and audit presentations
Required Core Skills:
- NIST SP 800-53 control mapping and assessment methodology
- ISO/IEC 27001 ISMS (Information Security Management System) structure
- SOC 2 Trust Services Criteria (CC, C, A, CO, SI, PO principals)
- PCI-DSS compliance scope and control testing
- HIPAA Security Rule and Breach Notification Rule basics
- GDPR awareness (scope, processor/controller, DPA, data subject rights)
- Audit workpaper organization and evidence standards
- Report writing and finding substantiation
Recommended Certifications:
| Certification | Vendor | URL | Notes |
|---|---|---|---|
| CISA (Certified Information Systems Auditor) | ISACA | https://www.isaca.org/credentialing/cisa | 5 yrs IT audit exp (waivable with degree + 3 yrs); median salary $107,619–$115,600 (22% premium over non-cert) (ISACA 2025 Survey; ZipRecruiter); $325 exam |
| CGRC (Certified in Governance, Risk and Compliance) | (ISC)² | https://www.isc2.org/certifications/cgrc | Entry-level GRC; no prerequisites; $225 exam; ISACA membership $75/yr |
| CIA (Certified Internal Auditor) | The IIA (Institute of Internal Auditors) | https://www.theiia.org/certifications/certified-internal-auditor-cia/ | General audit (not IT-specific); 7 yrs audit exp (waivable with degree); $250 exam per part (3 parts) |
| HCISPP (Healthcare Certified Information Security Professional) | (ISC)² | https://www.isc2.org/Certifications/HCISPP | Healthcare-specific; CISSP or equivalent required first |
Salary (2026 US):
Compliance Analyst (entry): $59,957–$72,853 (ZipRecruiter; Glassdoor)
IT Auditor (CISA-cert): $70,000–$130,000 depending on exp (Infosec Institute)
Median CISA holder: $107,619 — $115,600 (ISACA)
Free Resources:
- ISACA Online Review Courses (member benefit)
- AuditBoard / Drata Academy – free SOC 2 & ISO 27001 training modules
- NIST.gov SP 800-53 PDF (free, comprehensive)
- SANS Institute whitepapers on GRC fundamentals
ASSOCIATE (3–6 years) — Senior IT Auditor / GRC Analyst
Day-in-the-Life:
- Leading audit engagements for multiple clients/business units
- Mapping controls across 3–5 frameworks simultaneously (NIST, ISO, SOC 2, PCI, HIPAA)
- Writing audit reports and presenting findings to Audit Committee
- Developing remediation roadmaps with IT/Security teams
- Evidence management using GRC tools (Drata, Vanta, AuditBoard, etc.)
- Policy development and policy gap analysis
- Preparing organizations for external audit readiness
Required Core Skills:
- Multi-framework control mapping (NIST → ISO → SOC 2 → HIPAA alignment)
- Risk-based audit prioritization and sample selection
- Policy authoring and control design assistance
- Audit readiness planning and timeline management
- GRC tool proficiency (spreadsheet-based or software like Drata/Vanta)
- Root-cause analysis and remediation tracking
- Stakeholder communication across IT, security, and business
Recommended Certifications:
| Certification | Vendor | URL | Notes |
|---|---|---|---|
| CRISC (Certified in Risk and Information Systems Control) | ISACA | https://www.isaca.org/credentialing/crisc | 3 yrs exp in risk + controls; median salary $147,000–$151,000 (ZipRecruiter; Invensis Learning); $225 exam |
| CISM (Certified Information Security Manager) | ISACA | https://www.isaca.org/credentialing/cism | 5 yrs info security mgmt exp (waivable); salary $125,000–$160,000 global, $149,000 USD avg per ISACA (Knowledge Hut; iCert Global) |
| ISO/IEC 27001 Lead Implementer (PECB or BSI) | PECB / BSI | https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27001/iso-iec-27001-lead-implementer | 5-day course; £3,000–$4,500; salary $102,886–$135,000 USA (ZipRecruiter) |
| ISO/IEC 27001 Lead Auditor (PECB or BSI) | PECB / BSI | https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27001/iso-iec-27001-lead-auditor | 5-day course; £3,000–$4,500; leads ISO audits; 10–15% salary premium (ReadyNez) |
| ISO/IEC 27701 (Privacy) | PECB | https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27701/iso-iec-27701-lead-auditor | GDPR-aligned privacy management; 3-day course; £2,500–$3,500 |
| CIPM (Certified Information Privacy Manager) | IAPP (International Association of Privacy Professionals) | https://iapp.org/certify/cipm/ | Privacy management (GDPR/CCPA); 3 yrs exp; $400 exam |
Key Books (GRC Manager Perspective):
- How to Measure Anything in Cybersecurity Risk (Douglas W. Hubbard & Richard D. Seiersen, Wiley, 2016) – quantitative risk frameworks
- The CISO Desk Reference Guide, Vol. 1 & 2 (Bonney, Hayslip, Stamper; various editions 2018–2022) – GRC leadership playbook
- NIST Cybersecurity Framework 2.0 (NIST CSF v2.0, released Feb 2024)
- SANS Security Awareness Foundations (free SEC360 course)
Salary (2026 US):
Senior IT Auditor (CISA + CRISC): $100,000–$140,000
GRC Analyst: $94,037–$123,117 (Glassdoor)
PROFESSIONAL (6–10 years) — IT Audit Manager / GRC Manager
Day-in-the-Life:
- Managing audit teams (3–8 auditors) and external auditor relationships
- Interpreting regulations for C-suite (board compliance updates)
- Building risk dashboards for audit committee
- Leading policy & procedure updates at organizational scope
- Vendor risk assessment and third-party GRC program
- Preparing Statement on Standards for Attestation Engagements (SSAE-18 SOC 2)
- Incident investigation and breach notification coordination
Required Core Skills:
- Audit team leadership and performance management
- Regulatory landscape monitoring (new rules, standards, guidance)
- Risk quantification at organizational scope
- Governance & control documentation at portfolio level
- Executive communication and board-level reporting
- Third-party audit management (vendor assessments, auditor engagement)
- Incident response and breach procedures
Recommended Certifications:
| Certification | Vendor | URL | Notes |
|---|---|---|---|
| CGEIT (Certified in the Governance of Enterprise IT) | ISACA | https://www.isaca.org/credentialing/cgeit | Enterprise IT governance; 5 yrs IT exp + governance focus; high-earners tier per ISACA (ISACA Now Blog) |
| FAIR Practitioner (Open FAIR, FAIR Institute) | FAIR Institute | https://www.fairinstitute.org/ | Risk quantification and factor analysis; 3-day course; ~$3,000 |
| IAPP Fellow Information Privacy Professional (FIP) | IAPP | https://iapp.org/certify/fip/ | Privacy leadership; 10+ yrs exp; $2,500 exam + prerequisites |
Salary (2026 US):
IT Audit Manager: $107,550–$160,689 (PayScale; Glassdoor)
GRC Manager: $109,560–$204,511 national average $146,080 (Glassdoor)
San Francisco GRC Manager: $210,957 (+44% premium) (Glassdoor)
EXPERT (10+ years) — Director GRC / Chief Compliance Officer (CCO) / Chief Risk Officer (CRO) / CISO via GRC Route
Day-in-the-Life (Director GRC):
- Quarterly regulatory landscape brief for Board Audit Committee
- Executive risk dashboard and governance scorecard
- Building compliance roadmap aligned to 3-year business strategy
- Leading enterprise-wide incident response and crisis management
- Third-party risk program oversight (vendor assessments, audits)
- Talent pipeline for GRC leadership and specialist roles
Day-in-the-Life (Chief Compliance Officer):
- Regulatory affairs and government agency liaison
- Anti-corruption, FCPA, and sanctions compliance programs
- Policy council chair and control framework evolution
- Board-level reporting on compliance risk and maturity
- Whistleblower program and non-retaliation oversight
- Mergers & Acquisitions compliance due diligence
Day-in-the-Life (Chief Risk Officer):
- Enterprise risk register and aggregated risk appetite framework
- Business continuity and disaster recovery oversight
- Risk committee meetings with board
- Emerging risk identification (AI, geopolitics, supply chain)
- Insurance and captive management strategy
- ERM (Enterprise Risk Management) system selection and deployment
Day-in-the-Life (CISO via GRC Route):
- Information security strategy aligned to audit findings
- Security architecture and control design at enterprise scale
- CISO-level vendor risk assessment (software supply chain, cloud providers)
- Security awareness program and phishing campaign metrics
- Executive incident response and breach notification
- Cybersecurity budget and team capability roadmap
Required Core Skills (All Expert Roles):
- C-suite communication and board reporting
- Strategic planning at enterprise scope
- Regulatory interpretation and compliance modeling
- Organizational change management
- P&L ownership (budget, FTE, tools)
- Executive team collaboration (CIO, CFO, COO, CHRO)
Recommended Certifications (Expert Tier):
| Certification | Vendor | URL | Notes |
|---|---|---|---|
| CCSK (Certificate of Cloud Security Knowledge) | Cloud Security Alliance | https://cloudsecurityalliance.org/education/ccsk/ | Cloud-specific compliance; ~$250 exam; 8 hrs study |
| CRISK (Certified in Risk and Information Systems Control) | ISACA | – | No current offering (CRISC available at Associate tier) |
| Certified Compliance & Ethics Professional (CCEP) | SCCE/Compliance Certification Board | https://www.sccecompliancecertification.org/ | CCO-focused; 5 yrs compliance exp; $500 exam |
| CISSP (Certified Information Systems Security Professional) | (ISC)² | https://www.isc2.org/Certifications/CISSP | CISO-track; 5 yrs cybersecurity exp; $749 exam; also CISSP-CCSK bundle available |
| Executive MBA (Compliance, Risk, or Governance specialization) | Major universities | – | Stanford GSB, Harvard Kennedy School, Kellogg (all offer compliance/risk tracks) |
Salary (2026 US):
Director of GRC: $150,000–$220,000+
Chief Compliance Officer (F500): $181,021–$304,820 median $255,401 (Glassdoor; PayScale; Salary.com)
Chief Risk Officer (F500): $250,000–$400,000+ (market-dependent)
CISO via GRC route (US median): $321,000–$385,000 (Glassdoor); top enterprises $500,000–$1,000,000+ with equity (Cybersecurity Ventures; RSA Conference Report)
Lateral Pivots & Cross-Track Transitions
PM ↔ Program Manager ↔ Portfolio Manager (Linear Progression)
All three roles are mutually reinforcing within PMI's canon:
- PM → PgM: Focus moves from single-project delivery to multi-project coordination and dependency management.
- PgM → PfM: Scope expands to portfolio-level strategic alignment and benefit realization across the entire initiative portfolio.
Earn PMP first, then add PgMP (3–5 years later), then PfMP (3–5 years after PgMP). No lateral pivots required; each builds on the previous tier.
Scrum Master → Agile Coach → SAFe SPC → Enterprise Agile Coach
- CSM/PSM I → Technical Scrum Master (1-team scope)
- PSM II/A-CSM → Agile Coach (3–5 teams)
- SAFe RTE or SPC → Program-level agile (ART, SAFe Release Train; salary bump $12K–$24K StarAgile)
- SAFe SPC → Enterprise agile transformation consultant; highest Agile track compensation
IT Auditor → Risk Manager → Chief Risk Officer
Common transition in regulated orgs:
- Start as CISA-certified IT Auditor (technical audit)
- Move to CRISC (Risk & Control focus) as risk analyst
- Add CGEIT (Governance) for IT director roles
- Promotion to CRO (Chief Risk Officer) at C-suite level
GRC Manager → Chief Compliance Officer (CCO)
- GRC Manager (CRISC + CGEIT) → Chief Compliance Officer is a natural pipeline in regulated industries (finance, insurance, healthcare, pharma).
- Requires business acumen (P&L, strategy) + regulatory depth + board communication.
- Salary jump: GRC Manager $146K → CCO $255K–$305K (Glassdoor).
GRC Manager → Chief Information Security Officer (CISO) via GRC Route
Less traditional than security-first path, but increasingly common as:
- Boards demand governance expertise in CISO roles
- CISO role expands to include compliance (security controls = compliance controls)
- GRC background brings audit/control rigor to security architecture
Path:
IT Auditor (CISA) → GRC Manager (CRISC) → CISO (add CISSP for credibility)
Salary differential:
CISO background in GRC: $300K–$500K vs. pure security background: $250K–$400K (depends heavily on org size & maturity).
Key Role Distinctions
PM vs. PgM vs. PfM (per PMI PMBOK 7th Edition)
| Dimension | Project Manager | Program Manager | Portfolio Manager |
|---|---|---|---|
| Scope | Single project | Multiple related projects | All projects in organization |
| Timeline | Weeks–months | Months–years | Year+ (ongoing) |
| Focus | Schedule, budget, scope, quality | Cross-project dependencies, benefits realization | Strategic alignment, resource allocation, ROI |
| Team Size | 5–50 people | 50–200 people | Indirect (oversees portfolio) |
| Key Metric | On-time, on-budget delivery | Program benefits achieved, milestone cadence | Strategic value, organizational goal alignment |
| Governance | Project steering committee | Program steering & governance board | Board/exec steering committee |
CCO vs. CRO vs. CISO (Executive Risk Leadership)
| Role | Primary Focus | Reports To | Salary Range (US 2026) |
|---|---|---|---|
| Chief Compliance Officer (CCO) | Regulatory compliance (GDPR, SOX, HIPAA, FCPA, sanctions, AML) | General Counsel or CEO | $181K–$305K (Glassdoor) |
| Chief Risk Officer (CRO) | Enterprise risk management (operational, financial, strategic, supply chain) | CFO or CEO | $250K–$400K+ (market-dependent) |
| Chief Information Security Officer (CISO) | Cybersecurity strategy, incident response, security architecture | CIO or CEO | $321K–$385K median; top enterprises $500K–$1M+ (Cybersecurity Ventures) |
Overlap:
All three roles manage risk, but in different domains. In smaller orgs, a single person may hold CCO + CRO duties; in F500s, these are separate leadership positions.
Regional Salary Data
United States (2026)
| Role | Entry (0–2 yrs) | Mid (3–6 yrs) | Senior (7+ yrs) | Director+ |
|---|---|---|---|---|
| Project Coordinator | $51K–$83K | $65K–$109K | $115K–$139K | $155K–$230K |
| Project Manager (non-cert) | — | $65K–$109K | $115K–$139K | — |
| Project Manager (PMP-cert) | — | $120K–$135K | $135K–$173K | — |
| Program Manager (PgMP) | — | $122K–$162K (median $135K) | — | — |
| Portfolio Manager (PfMP) | — | — | $130K–$140K median | $180K–$300K+ |
| IT Auditor | $60K–$90K | $100K–$140K | — | — |
| CISA-certified Auditor | $70K–$130K | $100K–$150K | — | — |
| GRC Manager | — | $109K–$204K (median $146K) | — | — |
| GRC Manager (SF) | — | $210K (+44% premium) | — | — |
| IT Audit Manager | — | $117K–$160K | — | — |
| Compliance Analyst | $60K–$72K | $72K–$123K | — | — |
| Director GRC | — | — | — | $150K–$220K+ |
| Chief Compliance Officer | — | — | — | $181K–$305K |
| Chief Risk Officer | — | — | — | $250K–$400K+ |
| CISO | — | — | — | $321K–$385K median (F500: $500K–$1M+) |
United Kingdom (2026)
| Role | Entry | Mid | Senior |
|---|---|---|---|
| Project Manager | £32K–£55K | £42K–£57K | £62K–£92.75K (London) |
| PMP-certified PM | — | £42K–£57K | £50K–£100K+ |
| Programme Manager | — | £50K–£70K | £70K–£120K+ |
South Africa (2026)
| Role | Entry | Mid (3–5 yrs) | Senior (8+ yrs) |
|---|---|---|---|
| IT Project Manager | — | R494K–R1.07M (~USD $26.5K–$58K) | R1.24M (~USD $67K) |
(Bonus: R94,043 average)
(PayScale ZA; ERI SalaryExpert)
Conference & Community Resources
Project Management Conferences
- PMI Global Summit (annual, various cities) – https://www.pmi.org/summit
- Scrum Gathering (annual, multi-regional) – https://www.scrum.org/community/events
- SAFe Summit (annual) – https://scaledagile.com/events/
- Agile Alliance Agile2026 – https://agilealliance.org/
GRC & Audit Conferences
- ISACA CACS (Cybersecurity Audit, Control & Assurance Summit) – https://www.isaca.org/training-and-events/
- IIA (Institute of Internal Auditors) Audit Conference – https://www.theiia.org/
- IAPP Privacy Academy (annual) – https://iapp.org/train/
- RSA Conference (cybersecurity & risk) – https://www.rsaconference.com/
Online Communities & Free Resources
- PMI Community (members) – https://www.pmi.org/community
- Scrum.org Forum – https://www.scrum.org/community
- ISACA Community (members) – https://engage.isaca.org/
- Reddit: r/projectmanagement – https://www.reddit.com/r/projectmanagement
- Reddit: r/cybersecurity (GRC discussions) – https://www.reddit.com/r/cybersecurity/
- YouTube: Andrew Ramdayal (free PMP/CAPM prep) – https://www.youtube.com/c/andrewramdayal
2026 Updates & Certification Changes
PMI PMP Exam Update — July 9, 2026 (CRITICAL)
Current Timeline:
- Pilot Registration: December 15, 2025 opens
- Pilot Exam Window: January 5–30, 2026 (in-person only, Pearson VUE centers, English)
- Pilot Takers: Receive full PMP certification if passed; free retake at official launch if failed
- Current PMP Exam Retirement: July 8, 2026 (final day)
- New PMP Exam Launch: July 9, 2026
New Exam Format:
- Question Count: 185 questions (up from 180)
- Duration: 240 minutes (4 hours)
- Domain Weightings (Major Change):
- Business Environment: 26% (up from 8% — major expansion)
- Predictive (Waterfall) Approaches: 40% (down from ~50%)
- Adaptive/Agile Approaches: 30% (up from ~25%)
- Hybrid Approaches: 30% (up from ~25%)
- New Content Focus: AI, sustainability, value delivery
- Question Types: New graphic-based items, deeper scenario blocks, revised eligibility rules
Candidate Action:
- Take current PMP before July 8, 2026 OR register for pilot and attempt Jan 5–30, 2026
- PMBOK 8th Edition aligns with new exam; PMBOK 6 still acceptable until July 8, 2026
(PMI Official Announcement; PMI Blog)
ITIL 5 (Rumored 2026 Update)
Status: Verify with AXELOS — no confirmed 2026 launch date as of April 2026. Current ITIL 4 remains the active standard.
ISACA AAIR — Advanced in AI Risk (New 2026)
Status: Under development; expect launch mid-to-late 2026. Will complement CISM and CGEIT for AI governance and risk topics.
IAPP CIPP/E Updates (2026)
Status: GDPR, UK DPA 2018, and other privacy laws continue to evolve. IAPP updates exam domain weightings regularly. Check IAPP site for latest changes: https://iapp.org/
Sources
Certification & Exam Information
- PMI CAPM Certification
- PMI PMP – New Exam July 2026
- PMI PMP Exam Change Announcement
- PMI Program Management Professional (PgMP)
- PMI Portfolio Management Professional (PfMP)
- Scrum.org Professional Scrum Master I
- Scrum Alliance Certified ScrumMaster
- AXELOS PRINCE2
- AXELOS ITIL 4
- Scaled Agile SAFe Scrum Master (SSM)
- Scaled Agile Release Train Engineer (RTE)
- ISACA CISA Certification
- (ISC)² CGRC Certification
- ISACA CRISC Certification
- ISACA CISM Certification
- ISACA CGEIT Certification
- The IIA CIA (Certified Internal Auditor)
- PECB ISO/IEC 27001 Lead Implementer
- PECB ISO/IEC 27001 Lead Auditor
- IAPP CIPM Certification
- (ISC)² HCISPP
- (ISC)² CISSP
- The Open Group TOGAF
- FAIR Institute Open FAIR Certification
- Cloud Security Alliance CCSK
Salary & Compensation Data
- Coursera – CAPM Salary 2026
- Knowledge Hut – CAPM Certification Salary 2026
- PayScale – CAPM Salary
- ZipRecruiter – CAPM Salary
- ZipRecruiter – CISA Salary March 2026
- PayScale – CISA Salary
- ISACA – CISA Certification 2026 Salary & Trends
- Infosec Institute – Average CISA Salary 2025
- StationX – Average CISA Salary 2026
- Certification Academy – PMP Salary 2026
- Invensis Learning – PMP Certification Salary 2026
- ZipRecruiter – PMP Certified Salary
- PMI 14th Edition Earning Power: Project Management Salary Survey
- Glassdoor – Project Manager PMP Salary
- Invensis Learning – Senior Project Manager Salary 2026
- PayScale – IT Project Manager (UK) Salary
- Robert Half – Project Manager Salary (London)
- APM – Project Management Salary Survey 2025
- Glassdoor – UK Project Manager Salary
- PayScale – South Africa IT Project Manager Salary
- ERI SalaryExpert – IT Project Manager Salary South Africa
- PayScale – PgMP Salary
- Invensis Learning – PgMP Salary 2026
- Invensis Learning – PfMP Salary 2026
- PayScale – Portfolio Manager Salary
- Glassdoor – Project Portfolio Manager Salary
- Glassdoor – Principal Portfolio Manager Salary
- Knowledge Hut – CISM Salary 2026
- iCert Global – CISM Certification Salary 2026
- ZipRecruiter – CISM Salary April 2026
- Invensis Learning – CRISC Salary 2026
- ZipRecruiter – CRISC Salary February 2026
- DestCert – CRISC Salary Guide
- ZipRecruiter – ISO 27001 Lead Auditor Salary
- ReadyNez – ISO 27001 Lead Auditor Salary
- Glassdoor – Compliance Analyst Salary
- ZipRecruiter – Compliance Analyst Salary April 2026
- PayScale – Compliance Analyst Salary
- Comparably – Compliance Analyst Salary February 2026
- Glassdoor – GRC Manager Salary
- ZipRecruiter – GRC Manager Salary February 2026
- ZipRecruiter – GRC Manager Salary (SF) April 2026
- Salary.com – GRC Manager Salary
- ZipRecruiter – IT Audit Manager Salary February 2026
- Glassdoor – IT Audit Manager Salary
- PayScale – IT Audit Manager Salary
- Salary.com – IT Audit Manager Salary
- Glassdoor – Chief Compliance Officer Salary
- PayScale – Chief Compliance Officer Salary
- Salary.com – Chief Compliance Officer Salary February 2026
- ZipRecruiter – Chief Compliance Officer Salary March 2026
- Research.com – Chief Compliance Officer Salary 2026
- Robert Half – Chief Compliance Officer Salary
- Cybersecurity Ventures – 2026 CISO Salary & Compensation Data
- RSA Conference – 2026 CISO Annual Compensation Report
- Glassdoor – CISO Salary 2026
- PayScale – CISO Salary
- Salary.com – CISO Salary April 2026
- ZipRecruiter – CISO Salary April 2026
- StarAgile – SAFe Certification Salary & Cost 2026
- Scaled Agile – 2026 SAFe Careers Snapshot
Books & Academic Resources
- IT Revolution Press – Project to Product (Kersten, 2018)
- Scott Berkun – Making Things Happen (O'Reilly, 2008)
- IT Revolution Press – The Phoenix Project (Kim, Behr, Spafford, 2013)
- IT Revolution Press – Accelerate (Forsgren, Humble, Kim, 2018)
- SVPG – Inspired (Cagan, Wiley, 2017)
- SVPG – Empowered (Cagan & Jones, Wiley, 2020)
- The Lean Startup – Eric Ries (Crown Business, 2011)
- Wiley – How to Measure Anything in Cybersecurity Risk (Hubbard & Seiersen, 2016)
- SANS Institute – Free GIAC Whitepapers on GRC Fundamentals
- NIST SP 800-53 – Security and Privacy Controls (Free PDF)
- NIST Cybersecurity Framework 2.0
Communities & Events
- PMI Global Summit
- Scrum Gathering
- SAFe Summit
- Agile Alliance – Agile2026
- ISACA CACS (Cybersecurity Audit, Control & Assurance Summit)
- IIA Audit Conference
- IAPP Privacy Academy
- RSA Conference
- PMI Community
- Scrum.org Forum
- ISACA Community
- Reddit: r/projectmanagement
- Reddit: r/cybersecurity
- YouTube: Andrew Ramdayal (PMP/CAPM Prep)
Appendix: Certification Prerequisite Summary
PM Track Prerequisites
| Cert | Experience Req | Hours/Study | Cost | Notes |
|---|---|---|---|---|
| CAPM | None | 60–80 hrs | $555 | Entry-level; high pass rate |
| PMP | 3 yrs (4500 hrs) or equiv. w/ degree | 120–150 hrs | $555 | Changes July 9, 2026 |
| PgMP | 23 yrs or 16 yrs + Master's | 150–200 hrs | $555 | Higher salary tier |
| PfMP | 15 yrs PM + 5 yrs portfolio | 150–200 hrs | $555 | Executive tier |
GRC Track Prerequisites
| Cert | Experience Req | Hours/Study | Cost | Notes |
|---|---|---|---|---|
| CISA | 5 yrs (waivable w/ degree + 3 yrs) | 150–200 hrs | $325 | Gold standard; high ROI |
| CGRC | None | 50–80 hrs | $225 | Entry-level GRC |
| CIA | 7 yrs (waivable w/ degree) | 200+ hrs (3 exams) | $750 (3×$250) | General audit |
| CRISC | 3 yrs exp in risk + controls | 120–150 hrs | $225 | Risk focus; high salary |
| CISM | 5 yrs info security mgmt (waivable) | 150–200 hrs | $225 | Security management |
| ISO 27001 Lead Impl. | 2 yrs info security | 120 hrs course | $3K–$4.5K | 5-day course |
| ISO 27001 Lead Auditor | 3 yrs audit/management | 120 hrs course | $3K–$4.5K | 5-day course; audit focus |
Document History
| Version | Date | Author | Notes |
|---|---|---|---|
| 1.0 | 30 April 2026 | Deep Dive Research Phase 8 | Initial comprehensive dual-track roadmap. All URLs and salary data current as of April 30, 2026. |
Last Updated: 30 April 2026
Next Review: Q3 2026 (annual salary survey updates, Q4 certification launches)