as you are in the UK market it might be best to contact recruiters and ask for feedback on your skill
for your level of experience it is quite refreshing that you are demonstrating more than just technical how to knowledge. A lot of junior security know pfcg steps but they have no idea what to put in the fields
If you are going to invest in further training then GRC component sounds like a good progression for your background. You might need to try for audit/risk jobs on SAP systems and then move across that way. In doing this you leverage existing experience and focus on business knowledge
good luck