Penetration Testing
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Penetration Testing skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Penetration Testing over the 6 months to 18 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
18 May 2024
Same period 2023 Same period 2022
Rank 459 475 569
Rank change year-on-year +16 +94 -151
Permanent jobs citing Penetration Testing 511 619 926
As % of all permanent jobs advertised in the UK 0.51% 0.62% 0.58%
As % of the Processes & Methodologies category 0.60% 0.65% 0.60%
Number of salaries quoted 401 414 634
10th Percentile £38,750 £43,477 £37,286
25th Percentile £47,500 £50,015 £51,250
Median annual salary (50th Percentile) £65,000 £66,500 £60,569
Median % change year-on-year -2.26% +9.79% +0.95%
75th Percentile £82,500 £90,000 £78,438
90th Percentile £95,000 £103,750 £90,000
UK excluding London median annual salary £57,500 £55,000 £60,000
% change year-on-year +4.55% -8.33% +9.09%

All Process and Methodology Skills
UK

Penetration Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 85,135 94,784 153,905
As % of all permanent jobs advertised in the UK 85.22% 95.58% 95.76%
Number of salaries quoted 59,872 55,911 82,488
10th Percentile £29,089 £34,000 £33,635
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,180 £60,000
Median % change year-on-year -10.10% +1.97% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +9.38%

Penetration Testing
Job Vacancy Trend

Job postings citing Penetration Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Penetration Testing in the UK

Penetration Testing
Salary Trend

3-month moving average salary quoted in jobs citing Penetration Testing.

Salary trend for Penetration Testing in the UK

Penetration Testing
Salary Histogram

Salary distribution for jobs citing Penetration Testing over the 6 months to 18 May 2024.

Salary histogram for Penetration Testing in the UK

Penetration Testing
Top 16 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 18 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England +33 461 £65,000 -2.26% 136
UK excluding London -82 235 £57,500 +4.55% 94
London +65 226 £70,000 -14.56% 57
Work from Home -26 209 £60,000 -11.11% 82
South East -4 65 £43,750 -25.21% 24
Midlands -13 53 £57,000 -5.00% 12
North of England +28 49 £57,500 +9.52% 22
South West -15 48 £63,750 +25.00% 17
North West +11 37 £60,000 +12.15% 14
West Midlands -8 30 £55,000 -8.33% 9
East Midlands +9 23 £65,000 - 3
Yorkshire +57 12 £44,250 -14.79% 5
Scotland -80 9 £60,000 +7.75% 10
East of England -11 7 £40,000 -27.27% 3
Wales +3 3 £90,000 +55.17% 4
Channel Islands - 1 £100,000 -

Penetration Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 4 (0.78%) Microsoft Exchange
2 3 (0.59%) SharePoint
3 1 (0.20%) Apache
3 1 (0.20%) Confluence
3 1 (0.20%) IIS
3 1 (0.20%) WebSphere
Applications
1 3 (0.59%) Microsoft Office
Business Applications
1 1 (0.20%) Remedy ITSM
Cloud Services
1 109 (21.33%) Azure
2 79 (15.46%) AWS
3 49 (9.59%) Microsoft 365
4 27 (5.28%) GCP
5 22 (4.31%) Cloud Computing
6 11 (2.15%) Google Workspace
7 10 (1.96%) SaaS
8 9 (1.76%) Entra ID
9 8 (1.57%) Amazon ECS
9 8 (1.57%) Cloudflare
10 7 (1.37%) Dynamics 365
10 7 (1.37%) PaaS
11 6 (1.17%) Azure Sentinel
11 6 (1.17%) IaaS
12 4 (0.78%) Azure DevOps
12 4 (0.78%) Azure Service Bus
12 4 (0.78%) Mimecast
13 3 (0.59%) Azure Synapse Analytics
13 3 (0.59%) Power Platform
13 3 (0.59%) PowerApps
Communications & Networking
1 125 (24.46%) Firewall
2 75 (14.68%) Network Security
3 41 (8.02%) Wireless
4 31 (6.07%) DNS
5 29 (5.68%) Intrusion Detection
6 20 (3.91%) Wi-Fi
7 16 (3.13%) TCP/IP
8 13 (2.54%) VPN
9 11 (2.15%) Broadband
9 11 (2.15%) NAS
10 10 (1.96%) Internet
10 10 (1.96%) Wireshark
11 9 (1.76%) SSL
12 8 (1.57%) LAN
13 7 (1.37%) WAN
14 6 (1.17%) BGP
14 6 (1.17%) NGFW
15 5 (0.98%) IPsec
15 5 (0.98%) OSPF
15 5 (0.98%) VLAN
Database & Business Intelligence
1 9 (1.76%) SQL Server
2 6 (1.17%) MongoDB
2 6 (1.17%) NoSQL
3 4 (0.78%) InfluxDB
4 3 (0.59%) Data Lake
5 2 (0.39%) Azure SQL Database
6 1 (0.20%) Redis
Development Applications
1 40 (7.83%) Burp Suite
1 40 (7.83%) Metasploit
2 9 (1.76%) Jenkins
3 8 (1.57%) Git
4 6 (1.17%) JIRA
5 5 (0.98%) Postman
6 4 (0.78%) JMeter
6 4 (0.78%) SoapUI
7 3 (0.59%) Cucumber
7 3 (0.59%) SpecFlow
8 2 (0.39%) Bitbucket
9 1 (0.20%) GitLab
9 1 (0.20%) Selenium
9 1 (0.20%) Snyk
General
1 161 (31.51%) Social Skills
2 92 (18.00%) Analytical Skills
3 72 (14.09%) Finance
4 46 (9.00%) Legal
5 32 (6.26%) Law
6 30 (5.87%) Retail
7 29 (5.68%) Presentation Skills
8 26 (5.09%) Telecoms
9 25 (4.89%) Games
10 24 (4.70%) Banking
11 21 (4.11%) Aerospace
11 21 (4.11%) Inclusion and Diversity
12 19 (3.72%) Marketing
13 18 (3.52%) Public Sector
14 14 (2.74%) Influencing Skills
14 14 (2.74%) Military
15 9 (1.76%) Manufacturing
16 7 (1.37%) Automotive
16 7 (1.37%) Aviation
16 7 (1.37%) Pharmaceutical
Job Titles
1 135 (26.42%) Penetration Tester
1 135 (26.42%) Tester
2 70 (13.70%) Analyst
3 68 (13.31%) Senior
4 67 (13.11%) Lead
5 52 (10.18%) Security Analyst
6 37 (7.24%) Security Engineer
7 36 (7.05%) Consultant
8 32 (6.26%) Security Manager
8 32 (6.26%) Team Leader
9 26 (5.09%) Architect
10 25 (4.89%) Senior Penetration Tester
10 25 (4.89%) Senior Tester
11 23 (4.50%) Security Consultant
12 21 (4.11%) Cybersecurity Analyst
12 21 (4.11%) Security Architect
12 21 (4.11%) Test Team Leader
13 20 (3.91%) Security Tester
14 19 (3.72%) Security Penetration Tester
15 18 (3.52%) Cybersecurity Manager
Libraries, Frameworks & Software Standards
1 14 (2.74%) OAuth
2 12 (2.35%) OAuth2
3 8 (1.57%) Laravel
4 6 (1.17%) Web Services
5 4 (0.78%) EDI
5 4 (0.78%) OpenID
5 4 (0.78%) SOAP
5 4 (0.78%) XML
6 3 (0.59%) RESTful
6 3 (0.59%) WPF
7 2 (0.39%) Kafka
7 2 (0.39%) SAML
8 1 (0.20%) ARM Templates
8 1 (0.20%) JSON
8 1 (0.20%) Loki
8 1 (0.20%) React
8 1 (0.20%) SignalR
8 1 (0.20%) Spring
8 1 (0.20%) Spring Boot
8 1 (0.20%) YAML
Miscellaneous
1 53 (10.37%) Cyber Threat
2 44 (8.61%) Management Information System
2 44 (8.61%) Security Posture
3 38 (7.44%) Cyberattack
4 29 (5.68%) Mobile App
5 26 (5.09%) Onboarding
6 23 (4.50%) Self-Motivation
7 21 (4.11%) Operational Technology
8 15 (2.94%) Data Centre
8 15 (2.94%) IoT
9 14 (2.74%) Cyber Defence
10 13 (2.54%) Hybrid Cloud
11 11 (2.15%) Video Conferencing
12 9 (1.76%) Cyber Security Posture
12 9 (1.76%) Distributed Denial-of-Service
13 7 (1.37%) Analytical Mindset
13 7 (1.37%) Data Protection Act
14 6 (1.17%) Embedded Systems
15 5 (0.98%) Data Structures
15 5 (0.98%) PKI
Operating Systems
1 71 (13.89%) Windows
2 60 (11.74%) Linux
3 42 (8.22%) Kali Linux
4 25 (4.89%) Apple iOS
5 24 (4.70%) Android
6 21 (4.11%) Windows Server
7 17 (3.33%) Unix
8 12 (2.35%) Mac OS
9 3 (0.59%) Mac OS X
10 2 (0.39%) AIX
10 2 (0.39%) Red Hat Enterprise Linux
10 2 (0.39%) Windows XP
11 1 (0.20%) VMS
11 1 (0.20%) Windows 10
11 1 (0.20%) Windows Server 2012
11 1 (0.20%) Windows Server 2016
Processes & Methodologies
1 370 (72.41%) Cybersecurity
2 152 (29.75%) Information Security
3 118 (23.09%) Computer Science
4 116 (22.70%) Problem-Solving
5 105 (20.55%) Incident Response
6 93 (18.20%) Application Security
7 91 (17.81%) Vulnerability Scanning
8 90 (17.61%) Red Team
9 84 (16.44%) Security Testing
10 69 (13.50%) SIEM
11 68 (13.31%) Vulnerability Management
12 64 (12.52%) Mentoring
13 59 (11.55%) Vulnerability Assessment
14 54 (10.57%) OWASP
15 51 (9.98%) Security Operations
16 47 (9.20%) Risk Management
17 46 (9.00%) Patch Management
18 44 (8.61%) Data Protection
19 42 (8.22%) Malware Analysis
19 42 (8.22%) Reverse Engineering
Programming Languages
1 50 (9.78%) Python
2 32 (6.26%) Bash
3 14 (2.74%) Java
4 12 (2.35%) PowerShell
4 12 (2.35%) SQL
5 8 (1.57%) PHP
5 8 (1.57%) Rust
6 7 (1.37%) C#
6 7 (1.37%) Go
6 7 (1.37%) JavaScript
7 2 (0.39%) Ruby
8 1 (0.20%) C++
8 1 (0.20%) TypeScript
Qualifications
1 125 (24.46%) Degree
2 104 (20.35%) CISSP
3 89 (17.42%) CREST Certified
4 71 (13.89%) OSCP
5 68 (13.31%) Computer Science Degree
6 63 (12.33%) CISM
7 48 (9.39%) Security Cleared
8 40 (7.83%) SC Cleared
9 36 (7.05%) CEH
10 33 (6.46%) CHECK Team Member
10 33 (6.46%) CompTIA Security+
11 32 (6.26%) GIAC
12 28 (5.48%) CISA
13 26 (5.09%) CHECK Team Leader
14 21 (4.11%) Cisco Certification
15 20 (3.91%) CompTIA CySA+
16 18 (3.52%) GPEN
17 14 (2.74%) Cyber Scheme
17 14 (2.74%) Network+ Certification
18 10 (1.96%) CCSP
Quality Assurance & Compliance
1 99 (19.37%) ISO/IEC 27001
2 60 (11.74%) NIST
3 52 (10.18%) Cyber Essentials
4 30 (5.87%) GRC
5 27 (5.28%) GDPR
6 26 (5.09%) PCI DSS
7 25 (4.89%) Cyber Essentials PLUS
8 24 (4.70%) QA
9 21 (4.11%) SOC 2
10 9 (1.76%) NCSC
11 8 (1.57%) NIST 800
12 7 (1.37%) Actionable Recommendations
12 7 (1.37%) DO-254
13 6 (1.17%) COBIT
13 6 (1.17%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
14 5 (0.98%) HIPAA
15 4 (0.78%) Accessibility
15 4 (0.78%) HMG Security Policy Framework
16 3 (0.59%) JSP 440
16 3 (0.59%) JTAG
System Software
1 44 (8.61%) Active Directory
2 25 (4.89%) VMware Infrastructure
3 9 (1.76%) Virtual Machines
4 7 (1.37%) Docker
5 2 (0.39%) Virtual Servers
6 1 (0.20%) Hyper-V
Systems Management
1 21 (4.11%) Nessus
2 18 (3.52%) Kubernetes
3 12 (2.35%) WSUS
4 11 (2.15%) Ansible
4 11 (2.15%) Computer Emergency Response Teams
4 11 (2.15%) Single Sign-On
5 10 (1.96%) Nmap
6 9 (1.76%) QRadar
7 7 (1.37%) SCCM
8 6 (1.17%) CASB
8 6 (1.17%) Microsoft Intune
9 5 (0.98%) Grafana
9 5 (0.98%) HP Fortify
9 5 (0.98%) Progress Chef
9 5 (0.98%) Suricata
10 4 (0.78%) DatAdvantage
10 4 (0.78%) Terraform
11 3 (0.59%) FortiGate
12 2 (0.39%) CSIRT
13 1 (0.20%) Prometheus
Vendors
1 92 (18.00%) Microsoft
2 25 (4.89%) VMware
3 23 (4.50%) Qualys
4 22 (4.31%) Cisco
5 20 (3.91%) Google
6 15 (2.94%) Splunk
7 11 (2.15%) Apple
8 8 (1.57%) Palo Alto
9 7 (1.37%) Rapid7
10 6 (1.17%) HubSpot
10 6 (1.17%) IBM
10 6 (1.17%) Kenna
10 6 (1.17%) Oracle
11 5 (0.98%) Alibaba
11 5 (0.98%) Juniper
11 5 (0.98%) Red Hat
12 4 (0.78%) Darktrace
12 4 (0.78%) ServiceNow
12 4 (0.78%) Varonis
12 4 (0.78%) Veeam