Threat Modelling Jobs

Threat Modelling
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Threat Modelling skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Threat Modelling over the 6 months to 9 June 2024 with a comparison to the same period in the previous 2 years.

6 months to
9 Jun 2024
Same period 2023 Same period 2022
Rank 755 565 742
Rank change year-on-year -190 +177 +5
Permanent jobs citing Threat Modelling 167 421 604
As % of all permanent jobs advertised in the UK 0.15% 0.45% 0.35%
As % of the Processes & Methodologies category 0.19% 0.47% 0.37%
Number of salaries quoted 123 245 281
10th Percentile £46,875 £44,192 £47,500
25th Percentile £56,938 £61,750 £60,000
Median annual salary (50th Percentile) £72,500 £81,928 £77,500
Median % change year-on-year -11.51% +5.71% +1.31%
75th Percentile £83,750 £100,000 £92,500
90th Percentile £101,250 £122,000 £101,250
UK excluding London median annual salary £62,000 £70,000 £71,200
% change year-on-year -11.43% -1.69% +9.54%

All Process and Methodology Skills
UK

Threat Modelling is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 89,994 88,841 164,871
As % of all permanent jobs advertised in the UK 82.98% 95.43% 95.92%
Number of salaries quoted 62,089 53,798 83,455
10th Percentile £29,500 £33,848 £33,500
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £60,800 £60,000
Median % change year-on-year -9.54% +1.33% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +9.38%

Threat Modelling
Job Vacancy Trend

Job postings citing Threat Modelling as a proportion of all IT jobs advertised.

Job vacancy trend for Threat Modelling in the UK

Threat Modelling
Salary Trend

3-month moving average salary quoted in jobs citing Threat Modelling.

Salary trend for Threat Modelling in the UK

Threat Modelling
Salary Histogram

Salary distribution for jobs citing Threat Modelling over the 6 months to 9 June 2024.

Salary histogram for Threat Modelling in the UK

Threat Modelling
Top 13 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Threat Modelling within the UK over the 6 months to 9 June 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -170 131 £70,000 -14.86% 60
UK excluding London -125 83 £62,000 -11.43% 34
London -110 54 £82,500 -2.94% 27
Work from Home -67 38 £72,500 -9.38% 32
North of England -12 27 £50,000 -28.57% 9
North West -22 22 £50,000 -28.57% 9
West Midlands -3 18 £72,500 +6.62% 4
Midlands -27 18 £72,500 +6.62% 4
South East -22 16 £62,000 -27.06% 12
South West -23 15 £61,250 -5.41% 6
Scotland -81 6 - - 2
Yorkshire +42 5 £50,000 -28.57%
East of England -11 1 - - 1

Threat Modelling
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 1 (0.60%) OpenStack
Applications
1 12 (7.19%) Microsoft Office
2 9 (5.39%) Microsoft Excel
Cloud Services
1 85 (50.90%) AWS
2 81 (48.50%) Azure
3 32 (19.16%) GCP
4 20 (11.98%) Serverless
5 18 (10.78%) Microsoft 365
6 16 (9.58%) AWS CloudFormation
6 16 (9.58%) Virtual Private Cloud
7 15 (8.98%) Amazon CloudWatch
7 15 (8.98%) Amazon EC2
7 15 (8.98%) Amazon GuardDuty
7 15 (8.98%) Amazon S3
7 15 (8.98%) AWS CloudTrail
7 15 (8.98%) AWS Lambda
8 12 (7.19%) Power Platform
9 11 (6.59%) Cloud Computing
10 8 (4.79%) PaaS
11 7 (4.19%) AWS Control Tower
12 6 (3.59%) Azure Service Fabric
12 6 (3.59%) Entra ID
12 6 (3.59%) SaaS
Communications & Networking
1 31 (18.56%) Firewall
2 25 (14.97%) LAN
3 16 (9.58%) DNS
4 11 (6.59%) Intrusion Detection
4 11 (6.59%) SSL
5 10 (5.99%) Network Security
5 10 (5.99%) WAN
6 7 (4.19%) Internet
7 6 (3.59%) HTTP
7 6 (3.59%) Wireless
8 5 (2.99%) VPN
8 5 (2.99%) Wireshark
9 4 (2.40%) SMTP
10 2 (1.20%) 802.11
10 2 (1.20%) Bluetooth
10 2 (1.20%) SSH
10 2 (1.20%) ZigBee
11 1 (0.60%) NGFW
11 1 (0.60%) SD-WAN
11 1 (0.60%) TCP/IP
Database & Business Intelligence
1 15 (8.98%) Amazon RDS
2 9 (5.39%) Power BI
3 6 (3.59%) Azure SQL Database
4 3 (1.80%) Data Lake
5 2 (1.20%) Big Data
Development Applications
1 20 (11.98%) Jenkins
2 10 (5.99%) Burp Suite
3 9 (5.39%) Metasploit
4 3 (1.80%) sqlmap
5 2 (1.20%) Bitbucket
5 2 (1.20%) Postman
5 2 (1.20%) Visual Studio
6 1 (0.60%) CircleCI
6 1 (0.60%) GitLab
6 1 (0.60%) Snyk
General
1 51 (30.54%) Social Skills
2 39 (23.35%) Finance
3 17 (10.18%) Banking
3 17 (10.18%) Inclusion and Diversity
3 17 (10.18%) Presentation Skills
4 16 (9.58%) Law
4 16 (9.58%) Public Sector
5 14 (8.38%) Retail
6 12 (7.19%) Marketing
7 9 (5.39%) Analytical Skills
8 6 (3.59%) Investment Banking
8 6 (3.59%) Manufacturing
9 5 (2.99%) Legal
10 2 (1.20%) Advertising
10 2 (1.20%) Cyber-Physical System
10 2 (1.20%) Documentation Skills
10 2 (1.20%) Financial Institution
10 2 (1.20%) Influencing Skills
10 2 (1.20%) Organisational Skills
11 1 (0.60%) Pharmaceutical
Job Titles
1 52 (31.14%) Architect
2 45 (26.95%) Security Architect
3 41 (24.55%) Senior
4 30 (17.96%) Security Engineer
5 22 (13.17%) Cybersecurity Architect
6 18 (10.78%) Lead
7 16 (9.58%) AWS Engineer
7 16 (9.58%) Senior Architect
8 14 (8.38%) Consultant
8 14 (8.38%) DevSecOps Engineer
8 14 (8.38%) Security Consultant
9 12 (7.19%) Analyst
10 10 (5.99%) Security Analyst
10 10 (5.99%) Security Technical Architect
10 10 (5.99%) Senior Security Architect
10 10 (5.99%) Technical Architect
11 9 (5.39%) Cybersecurity Engineer
12 8 (4.79%) Information Architect
12 8 (4.79%) Information Security Architect
12 8 (4.79%) Penetration Tester
Libraries, Frameworks & Software Standards
1 13 (7.78%) Web Services
2 9 (5.39%) OAuth
3 8 (4.79%) REST
3 8 (4.79%) SOAP
4 6 (3.59%) SAML
5 2 (1.20%) .NET
5 2 (1.20%) 802.1X
5 2 (1.20%) ASP.NET
5 2 (1.20%) OAuth2
5 2 (1.20%) OpenID
5 2 (1.20%) Swagger
5 2 (1.20%) YAML
6 1 (0.60%) AWS CDK
6 1 (0.60%) HTML
6 1 (0.60%) JWT
6 1 (0.60%) Middleware
Miscellaneous
1 37 (22.16%) Cyberattack
2 31 (18.56%) Management Information System
3 28 (16.77%) Cyber Threat
4 21 (12.57%) Data Centre
5 18 (10.78%) PKI
6 16 (9.58%) Security Posture
7 14 (8.38%) Onboarding
8 12 (7.19%) PropTech
9 10 (5.99%) IoT
9 10 (5.99%) iPhone
9 10 (5.99%) Public Cloud
10 8 (4.79%) Hybrid Cloud
11 7 (4.19%) Mobile App
12 6 (3.59%) Distributed Systems
12 6 (3.59%) Self-Motivation
13 5 (2.99%) Cyber Kill Chain
14 3 (1.80%) Client/Server
14 3 (1.80%) Cloud Native
14 3 (1.80%) SCADA
15 2 (1.20%) Life Science
Operating Systems
1 28 (16.77%) Windows
2 11 (6.59%) Kali Linux
3 9 (5.39%) Unix
4 6 (3.59%) Android
4 6 (3.59%) Apple iOS
4 6 (3.59%) Linux
5 5 (2.99%) Windows Server
6 4 (2.40%) Windows XP
7 1 (0.60%) Red Hat Enterprise Linux
Processes & Methodologies
1 112 (67.07%) Cybersecurity
2 68 (40.72%) Information Security
3 59 (35.33%) Incident Response
4 46 (27.54%) Application Security
5 44 (26.35%) Penetration Testing
6 42 (25.15%) Vulnerability Management
7 34 (20.36%) Security Architecture
8 33 (19.76%) Cyber Threat Intelligence
8 33 (19.76%) Threat Intelligence
9 31 (18.56%) Threat Management
10 30 (17.96%) Stakeholder Management
11 29 (17.37%) Secure Coding
12 28 (16.77%) Cloud Security
13 27 (16.17%) OWASP
14 26 (15.57%) SIEM
15 25 (14.97%) MITRE ATT&CK
16 24 (14.37%) Problem-Solving
16 24 (14.37%) Risk Management
16 24 (14.37%) Roadmaps
17 23 (13.77%) Identity Access Management
Programming Languages
1 42 (25.15%) Python
2 9 (5.39%) Java
3 8 (4.79%) Go
4 6 (3.59%) SQL
5 5 (2.99%) C#
5 5 (2.99%) PowerShell
6 3 (1.80%) JavaScript
7 2 (1.20%) C++
8 1 (0.60%) Dart
8 1 (0.60%) Kotlin
8 1 (0.60%) Lua
8 1 (0.60%) Objective-C
8 1 (0.60%) PHP
8 1 (0.60%) Ruby
8 1 (0.60%) Rust
8 1 (0.60%) Swift
Qualifications
1 77 (46.11%) CISSP
2 57 (34.13%) CISM
3 46 (27.54%) AWS Certification
4 41 (24.55%) GIAC
5 28 (16.77%) CREST Certified
5 28 (16.77%) Degree
6 27 (16.17%) OSCP
7 22 (13.17%) Azure Certification
8 21 (12.57%) CRISC
8 21 (12.57%) Security Cleared
9 20 (11.98%) SC Cleared
10 16 (9.58%) ISSMP
11 10 (5.99%) BPSS Clearance
11 10 (5.99%) CISA
12 9 (5.39%) CEH
12 9 (5.39%) Cisco Certification
12 9 (5.39%) Computer Science Degree
13 8 (4.79%) GCFA
13 8 (4.79%) GCIH
13 8 (4.79%) Master's Degree
Quality Assurance & Compliance
1 57 (34.13%) NIST
2 36 (21.56%) ISO/IEC 27001
3 27 (16.17%) COBIT
4 12 (7.19%) PCI DSS
5 8 (4.79%) Cyber Essentials
5 8 (4.79%) QA
6 7 (4.19%) SOC 2
7 6 (3.59%) Cyber Essentials PLUS
7 6 (3.59%) IASME
7 6 (3.59%) Web Application Security Consortium
8 5 (2.99%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
8 5 (2.99%) NIST 800
9 4 (2.40%) GDPR
9 4 (2.40%) NCSC
10 2 (1.20%) HIPAA
10 2 (1.20%) ISO 31000
11 1 (0.60%) GRC
11 1 (0.60%) GxP
11 1 (0.60%) IEC 61508
System Software
1 20 (11.98%) Active Directory
2 5 (2.99%) Docker
3 2 (1.20%) Virtual Machines
Systems Management
1 18 (10.78%) Kubernetes
2 17 (10.18%) Ansible
3 12 (7.19%) Nessus
4 7 (4.19%) Computer Emergency Response Teams
4 7 (4.19%) Nmap
5 5 (2.99%) Suricata
6 4 (2.40%) HP Fortify
7 2 (1.20%) QRadar
7 2 (1.20%) Terraform
8 1 (0.60%) Anchore
8 1 (0.60%) Computer Incident Response Team
8 1 (0.60%) Single Sign-On
Vendors
1 26 (15.57%) Microsoft
2 16 (9.58%) Alibaba
2 16 (9.58%) Google
3 10 (5.99%) Cisco
4 8 (4.79%) Splunk
5 6 (3.59%) Palo Alto
5 6 (3.59%) Qualys
6 5 (2.99%) Juniper
6 5 (2.99%) VMware
7 3 (1.80%) Veracode
8 2 (1.20%) Fortinet
8 2 (1.20%) IBM
9 1 (0.60%) Forcepoint
9 1 (0.60%) Intel
9 1 (0.60%) Netskope
9 1 (0.60%) Okta
9 1 (0.60%) Red Hat
9 1 (0.60%) Zscaler