Penetration Testing Contracts

Penetration Testing
UK

The following table provides summary statistics for contract job vacancies with a requirement for Penetration Testing skills. Included is a benchmarking guide to the contractor rates offered in vacancies that have cited Penetration Testing over the 6 months to 1 June 2024 with a comparison to the same period in the previous 2 years.

6 months to
1 Jun 2024
Same period 2023 Same period 2022
Rank 354 447 561
Rank change year-on-year +93 +114 -58
Contract jobs citing Penetration Testing 233 248 294
As % of all contract jobs advertised in the UK 0.54% 0.44% 0.34%
As % of the Processes & Methodologies category 0.63% 0.49% 0.37%
Number of daily rates quoted 171 162 198
10th Percentile £425 £450 £385
25th Percentile £500 £500 £500
Median daily rate (50th Percentile) £550 £588 £578
Median % change year-on-year -6.38% +1.73% +10.00%
75th Percentile £669 £688 £650
90th Percentile £725 £800 £725
UK excluding London median daily rate £530 £550 £575
% change year-on-year -3.64% -4.35% +19.79%
Number of hourly rates quoted 1 1 0
10th Percentile - - -
25th Percentile £81.75 - -
Median hourly rate £83.50 £80.00 -
Median % change year-on-year +4.38% - -
75th Percentile £85.25 - -
90th Percentile - - -
UK excluding London median hourly rate £83.50 - -

All Process and Methodology Skills
UK

Penetration Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all contract job vacancies with a requirement for process or methodology skills.

Contract vacancies with a requirement for process or methodology skills 36,802 50,277 79,372
As % of all contract IT jobs advertised in the UK 85.47% 89.69% 90.61%
Number of daily rates quoted 23,632 34,811 55,790
10th Percentile £300 £325 £345
25th Percentile £413 £438 £431
Median daily rate (50th Percentile) £525 £550 £538
Median % change year-on-year -4.55% +2.33% +7.50%
75th Percentile £638 £650 £644
90th Percentile £750 £750 £738
UK excluding London median daily rate £500 £500 £488
% change year-on-year - +2.56% +9.18%
Number of hourly rates quoted 2,530 1,673 1,868
10th Percentile £12.75 £10.63 £12.50
25th Percentile £16.00 £15.72 £15.63
Median hourly rate £36.50 £36.25 £25.68
Median % change year-on-year +0.69% +41.16% +9.74%
75th Percentile £60.75 £65.00 £50.00
90th Percentile £72.50 £75.00 £65.00
UK excluding London median hourly rate £38.12 £35.00 £20.00
% change year-on-year +8.91% +75.00% -4.76%

Penetration Testing
Job Vacancy Trend

Job postings citing Penetration Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Penetration Testing in the UK

Penetration Testing
Contractor Daily Rate Trend

3-month moving average daily rate quoted in jobs citing Penetration Testing.

Daily rate trend for Penetration Testing in the UK

Penetration Testing
Daily Rate Histogram

Daily rate distribution for jobs citing Penetration Testing over the 6 months to 1 June 2024.

Daily rate histogram for Penetration Testing in the UK

Penetration Testing
Contractor Hourly Rate Trend

3-month moving average hourly rates quoted in jobs citing Penetration Testing.

Hourly rate trend for Penetration Testing in the UK

Penetration Testing
Top 16 Contract Locations

The table below looks at the demand and provides a guide to the median contractor rates quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 1 June 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Contract
IT Job Ads
Median
Daily Rate
Past 6 Months
Median Daily Rate
% Change
on Same Period
Last Year
Live
Jobs
England +54 188 £585 +1.74% 133
London +60 103 £585 -2.50% 54
UK excluding London +46 98 £530 -3.64% 81
Work from Home +110 87 £550 - 99
North of England +23 28 £650 +23.81% 24
Scotland +54 23 £515 -8.44% 11
South West +19 23 £525 +5.00% 12
North West +27 21 £666 +21.09% 17
Midlands +19 10 £600 -17.24% 9
South East -1 10 £530 -7.42% 20
East of England +4 9 £700 +27.27% 3
West Midlands +9 7 £650 -10.34% 8
Yorkshire +10 5 £650 +23.81% 7
East Midlands - 3 £400 - 1
North East - 2 £625 -
Wales - 1 £363 - 1

Penetration Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 4 (1.72%) Confluence
1 4 (1.72%) IIS
1 4 (1.72%) JBoss
Applications
1 3 (1.29%) Microsoft Excel
2 1 (0.43%) Microsoft Office
2 1 (0.43%) Microsoft PowerPoint
2 1 (0.43%) Spreadsheet
Business Applications
1 4 (1.72%) Dynamics GP
2 1 (0.43%) Salesforce CRM
Cloud Services
1 48 (20.60%) Azure
2 26 (11.16%) AWS
3 15 (6.44%) GCP
4 9 (3.86%) Azure Sentinel
5 8 (3.43%) Entra ID
5 8 (3.43%) Power Platform
6 6 (2.58%) Microsoft 365
7 5 (2.15%) CloudFront
7 5 (2.15%) SaaS
7 5 (2.15%) Virtual Private Cloud
8 4 (1.72%) Azure DevOps
8 4 (1.72%) GitHub
9 3 (1.29%) GitHub Actions
10 2 (0.86%) AWS CloudFormation
10 2 (0.86%) PaaS
11 1 (0.43%) Azure ExpressRoute
11 1 (0.43%) Cloud Computing
11 1 (0.43%) Cloudflare
11 1 (0.43%) Mimecast
11 1 (0.43%) Oracle CX
Communications & Networking
1 64 (27.47%) Firewall
2 42 (18.03%) Network Security
3 15 (6.44%) Wireless
4 14 (6.01%) Intrusion Detection
5 12 (5.15%) WAN
6 11 (4.72%) SD-WAN
7 10 (4.29%) VPN
8 9 (3.86%) TCP/IP
9 8 (3.43%) DNS
10 6 (2.58%) SSL
11 5 (2.15%) Cisco ISE
11 5 (2.15%) tcpdump
11 5 (2.15%) Wireshark
12 3 (1.29%) NGFW
13 2 (0.86%) DHCP
13 2 (0.86%) HTTP
13 2 (0.86%) Internet
13 2 (0.86%) LAN
14 1 (0.43%) FTP
14 1 (0.43%) VoIP
Database & Business Intelligence
1 4 (1.72%) Apache Hive
1 4 (1.72%) DB2
1 4 (1.72%) Hadoop
1 4 (1.72%) Tableau
2 1 (0.43%) Oracle Database
2 1 (0.43%) Oracle Exadata
Development Applications
1 19 (8.15%) Jenkins
2 14 (6.01%) Burp Suite
2 14 (6.01%) GitLab
3 8 (3.43%) JIRA
4 4 (1.72%) IDA Disassembler
4 4 (1.72%) Vagrant
5 3 (1.29%) Metasploit
6 1 (0.43%) CircleCI
6 1 (0.43%) Git
6 1 (0.43%) Team Foundation Server
6 1 (0.43%) TeamCity
General
1 59 (25.32%) Finance
2 45 (19.31%) Social Skills
3 34 (14.59%) Public Sector
4 33 (14.16%) Analytical Skills
5 31 (13.30%) Banking
6 11 (4.72%) Retail
7 6 (2.58%) Manufacturing
8 5 (2.15%) Legal
9 4 (1.72%) Presentation Skills
10 2 (0.86%) Law
10 2 (0.86%) Multimedia
11 1 (0.43%) Automotive
11 1 (0.43%) Inclusion and Diversity
11 1 (0.43%) Influencing Skills
11 1 (0.43%) Marketing
11 1 (0.43%) Spanish Language
Job Titles
1 38 (16.31%) Architect
2 34 (14.59%) Security Architect
3 33 (14.16%) Consultant
4 31 (13.30%) Security Consultant
5 30 (12.88%) Analyst
5 30 (12.88%) Security Engineer
6 18 (7.73%) Security Analyst
6 18 (7.73%) Senior
7 17 (7.30%) Penetration Tester
7 17 (7.30%) Tester
8 15 (6.44%) Infrastructure Engineer
9 14 (6.01%) Network Engineer
10 12 (5.15%) Cybersecurity Analyst
11 11 (4.72%) Network Infrastructure Engineer
12 9 (3.86%) Security Manager
13 8 (3.43%) Azure Engineer
13 8 (3.43%) DevSecOps Engineer
13 8 (3.43%) SC Cleared Network Engineer
13 8 (3.43%) Security Specialist
14 7 (3.00%) SOC Analyst
Libraries, Frameworks & Software Standards
1 5 (2.15%) OAuth
1 5 (2.15%) OAuth2
1 5 (2.15%) SAML
2 4 (1.72%) OLE
3 2 (0.86%) RESTful
3 2 (0.86%) Web Services
4 1 (0.43%) .NET
4 1 (0.43%) ARM Templates
4 1 (0.43%) Azure Blueprints
4 1 (0.43%) EDI
4 1 (0.43%) JWT
4 1 (0.43%) OpenID
Miscellaneous
1 30 (12.88%) Cyber Threat
2 29 (12.45%) Security Posture
3 16 (6.87%) Data Centre
3 16 (6.87%) Management Information System
3 16 (6.87%) PKI
4 15 (6.44%) Mobile App
4 15 (6.44%) Private Cloud
5 12 (5.15%) Security Operations Centre
6 8 (3.43%) Cloud Native
6 8 (3.43%) Operational Technology
7 7 (3.00%) Cyber Kill Chain
8 6 (2.58%) Cyber Defence
9 5 (2.15%) Cyberattack
10 4 (1.72%) Distributed Denial-of-Service
10 4 (1.72%) Hybrid Cloud
10 4 (1.72%) YARA
11 3 (1.29%) IoT
11 3 (1.29%) Renewable Energy
12 2 (0.86%) Algorithms
12 2 (0.86%) Blockchain
Operating Systems
1 42 (18.03%) Windows
2 38 (16.31%) Linux
3 10 (4.29%) Kali Linux
4 7 (3.00%) Unix
5 6 (2.58%) Windows Server
6 4 (1.72%) AIX
6 4 (1.72%) Solaris
7 1 (0.43%) Mac OS X
7 1 (0.43%) VMS
Processes & Methodologies
1 114 (48.93%) Cybersecurity
2 67 (28.76%) Information Security
3 55 (23.61%) Cloud Security
4 46 (19.74%) SIEM
5 43 (18.45%) Vulnerability Management
5 43 (18.45%) Vulnerability Scanning
6 40 (17.17%) Application Security
6 40 (17.17%) Security Operations
6 40 (17.17%) Threat Modelling
7 38 (16.31%) DevSecOps
8 35 (15.02%) DevOps
8 35 (15.02%) Incident Response
9 33 (14.16%) Problem-Solving
10 32 (13.73%) Identity Access Management
11 30 (12.88%) CI/CD
11 30 (12.88%) Ethical Hacking
12 28 (12.02%) Agile
12 28 (12.02%) Risk Management
12 28 (12.02%) Security Architecture
13 27 (11.59%) Infrastructure as Code
Programming Languages
1 28 (12.02%) Python
2 14 (6.01%) Kusto Query Language
3 10 (4.29%) C++
4 7 (3.00%) JavaScript
5 6 (2.58%) PowerShell
6 5 (2.15%) Perl
6 5 (2.15%) Search Processing Language
7 4 (1.72%) C#
7 4 (1.72%) Java
7 4 (1.72%) SQL
8 3 (1.29%) C
8 3 (1.29%) Go
8 3 (1.29%) Shell Script
9 2 (0.86%) Bicep
9 2 (0.86%) Ruby
10 1 (0.43%) Bash
Qualifications
1 56 (24.03%) Security Cleared
2 53 (22.75%) SC Cleared
3 32 (13.73%) Degree
4 22 (9.44%) OSCP
5 18 (7.73%) CEH
5 18 (7.73%) CISSP
6 17 (7.30%) Computer Science Degree
6 17 (7.30%) CREST Certified
7 13 (5.58%) CISM
7 13 (5.58%) GIAC
8 10 (4.29%) GPEN
9 8 (3.43%) ITIL Certification
9 8 (3.43%) MCSE
9 8 (3.43%) Microsoft Certification
10 7 (3.00%) CompTIA Security+
11 5 (2.15%) AWS Certification
11 5 (2.15%) DV Cleared
12 4 (1.72%) Master's Degree
13 3 (1.29%) CCNA
13 3 (1.29%) Cisco Certification
Quality Assurance & Compliance
1 56 (24.03%) ISO/IEC 27001
2 51 (21.89%) NIST
3 20 (8.58%) GDPR
4 17 (7.30%) PCI DSS
5 12 (5.15%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
6 9 (3.86%) HMG Security Policy Framework
7 7 (3.00%) HIPAA
7 7 (3.00%) QA
8 5 (2.15%) COBIT
8 5 (2.15%) Disclosure Scotland
8 5 (2.15%) NCSC
9 4 (1.72%) SLA
10 2 (0.86%) Actionable Recommendations
10 2 (0.86%) Cyber Essentials
10 2 (0.86%) ISO 22301
10 2 (0.86%) Sarbanes-Oxley
11 1 (0.43%) Cyber Essentials PLUS
11 1 (0.43%) GRC
11 1 (0.43%) JSP 440
11 1 (0.43%) PMO
System Software
1 21 (9.01%) Active Directory
2 16 (6.87%) VMware Infrastructure
3 14 (6.01%) vSphere
4 5 (2.15%) Docker
4 5 (2.15%) Hyper-V
4 5 (2.15%) Snort
5 2 (0.86%) Firmware
6 1 (0.43%) Terminal Services
Systems Management
1 26 (11.16%) Terraform
2 13 (5.58%) vCenter Server
3 7 (3.00%) Nessus
4 6 (2.58%) SCCM
5 4 (1.72%) Kibana
5 4 (1.72%) Tivoli
6 3 (1.29%) Kubernetes
6 3 (1.29%) Microsoft Intune
7 2 (0.86%) Ansible
7 2 (0.86%) CASB
7 2 (0.86%) HP Fortify
8 1 (0.43%) Argo
8 1 (0.43%) Computer Emergency Response Teams
8 1 (0.43%) CSIRT
8 1 (0.43%) Nmap
8 1 (0.43%) OpenVAS
8 1 (0.43%) Single Sign-On
Vendors
1 35 (15.02%) Microsoft
2 18 (7.73%) Google
3 16 (6.87%) VMware
4 11 (4.72%) Splunk
5 9 (3.86%) Qualys
6 8 (3.43%) Cisco
7 6 (2.58%) Oracle
8 5 (2.15%) F5
8 5 (2.15%) SAP
9 4 (1.72%) AppDynamics
9 4 (1.72%) CheckPoint
9 4 (1.72%) IBM
10 3 (1.29%) Checkmarx
10 3 (1.29%) Tufin
10 3 (1.29%) Veracode
10 3 (1.29%) Zscaler
11 2 (0.86%) Palo Alto
11 2 (0.86%) Salesforce
12 1 (0.43%) Intel
12 1 (0.43%) Remedy