Penetration Testing Contracts

Penetration Testing
UK

The following table provides summary statistics for contract job vacancies with a requirement for Penetration Testing skills. Included is a benchmarking guide to the contractor rates offered in vacancies that have cited Penetration Testing over the 6 months to 20 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
20 May 2024
Same period 2023 Same period 2022
Rank 358 448 576
Rank change year-on-year +90 +128 -82
Contract jobs citing Penetration Testing 225 256 295
As % of all contract jobs advertised in the UK 0.53% 0.45% 0.33%
As % of the Processes & Methodologies category 0.61% 0.50% 0.37%
Number of daily rates quoted 164 166 192
10th Percentile £425 £450 £375
25th Percentile £504 £500 £500
Median daily rate (50th Percentile) £575 £600 £575
Median % change year-on-year -4.17% +4.35% +9.52%
75th Percentile £671 £692 £645
90th Percentile £746 £799 £725
UK excluding London median daily rate £530 £550 £575
% change year-on-year -3.64% -4.35% +20.42%
Number of hourly rates quoted 1 1 0
10th Percentile - - -
25th Percentile £81.75 - -
Median hourly rate £83.50 £80.00 -
Median % change year-on-year +4.38% - -
75th Percentile £85.25 - -
90th Percentile - - -
UK excluding London median hourly rate £83.50 - -

All Process and Methodology Skills
UK

Penetration Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all contract job vacancies with a requirement for process or methodology skills.

Contract vacancies with a requirement for process or methodology skills 36,622 51,397 80,021
As % of all contract IT jobs advertised in the UK 86.09% 89.76% 90.61%
Number of daily rates quoted 23,613 35,611 56,174
10th Percentile £300 £325 £344
25th Percentile £413 £439 £430
Median daily rate (50th Percentile) £525 £550 £530
Median % change year-on-year -4.55% +3.77% +7.07%
75th Percentile £638 £650 £638
90th Percentile £750 £750 £738
UK excluding London median daily rate £500 £500 £480
% change year-on-year - +4.17% +9.09%
Number of hourly rates quoted 2,439 1,690 1,913
10th Percentile £12.75 £10.63 £12.50
25th Percentile £16.00 £15.77 £15.50
Median hourly rate £36.50 £36.00 £25.68
Median % change year-on-year +1.39% +40.19% +7.00%
75th Percentile £60.00 £65.00 £49.50
90th Percentile £72.50 £75.00 £65.00
UK excluding London median hourly rate £38.00 £35.00 £20.00
% change year-on-year +8.57% +75.00% -6.54%

Penetration Testing
Job Vacancy Trend

Job postings citing Penetration Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Penetration Testing in the UK

Penetration Testing
Contractor Daily Rate Trend

3-month moving average daily rate quoted in jobs citing Penetration Testing.

Daily rate trend for Penetration Testing in the UK

Penetration Testing
Daily Rate Histogram

Daily rate distribution for jobs citing Penetration Testing over the 6 months to 20 May 2024.

Daily rate histogram for Penetration Testing in the UK

Penetration Testing
Contractor Hourly Rate Trend

3-month moving average hourly rates quoted in jobs citing Penetration Testing.

Hourly rate trend for Penetration Testing in the UK

Penetration Testing
Top 16 Contract Locations

The table below looks at the demand and provides a guide to the median contractor rates quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 20 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Contract
IT Job Ads
Median
Daily Rate
Past 6 Months
Median Daily Rate
% Change
on Same Period
Last Year
Live
Jobs
England +61 180 £588 -2.08% 145
London +51 100 £588 -2.08% 60
UK excluding London +60 93 £530 -3.64% 97
Work from Home +112 86 £550 -8.33% 93
North of England +32 26 £650 +23.81% 22
South West +22 23 £525 -12.50% 16
Scotland +59 22 £515 -6.36% 13
North West +23 20 £666 +26.86% 14
Midlands +14 11 £550 -24.14% 12
East of England +9 8 £700 +27.27% 3
South East +8 8 £530 -7.83% 26
West Midlands +16 7 £650 -10.34% 9
Yorkshire +12 4 £650 +23.81% 5
East Midlands - 4 £400 - 3
North East - 2 £625 - 3
Wales - 1 £363 - 4

Penetration Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 4 (1.78%) Confluence
1 4 (1.78%) IIS
1 4 (1.78%) JBoss
2 2 (0.89%) SharePoint
Applications
1 5 (2.22%) Microsoft Excel
2 3 (1.33%) Microsoft PowerPoint
2 3 (1.33%) Spreadsheet
3 1 (0.44%) Microsoft Office
Business Applications
1 4 (1.78%) Dynamics GP
2 1 (0.44%) Salesforce CRM
Cloud Services
1 44 (19.56%) Azure
2 27 (12.00%) AWS
3 13 (5.78%) GCP
4 8 (3.56%) Power Platform
5 6 (2.67%) Azure DevOps
5 6 (2.67%) Azure Sentinel
5 6 (2.67%) Microsoft 365
5 6 (2.67%) SaaS
6 5 (2.22%) CloudFront
6 5 (2.22%) Entra ID
6 5 (2.22%) Virtual Private Cloud
7 3 (1.33%) GitHub
7 3 (1.33%) GitHub Actions
8 2 (0.89%) AWS CloudFormation
8 2 (0.89%) PaaS
9 1 (0.44%) Amazon CloudWatch
9 1 (0.44%) AWS CloudTrail
9 1 (0.44%) Cloudflare
9 1 (0.44%) Mimecast
9 1 (0.44%) Oracle CX
Communications & Networking
1 58 (25.78%) Firewall
2 39 (17.33%) Network Security
3 14 (6.22%) Wireless
4 13 (5.78%) Intrusion Detection
5 12 (5.33%) WAN
6 11 (4.89%) SD-WAN
7 8 (3.56%) TCP/IP
7 8 (3.56%) VPN
8 7 (3.11%) DNS
9 6 (2.67%) SSL
10 5 (2.22%) Cisco ISE
10 5 (2.22%) tcpdump
10 5 (2.22%) Wireshark
11 3 (1.33%) NGFW
12 2 (0.89%) DHCP
12 2 (0.89%) HTTP
12 2 (0.89%) Internet
12 2 (0.89%) LAN
13 1 (0.44%) FTP
13 1 (0.44%) VoIP
Database & Business Intelligence
1 4 (1.78%) Apache Hive
1 4 (1.78%) DB2
1 4 (1.78%) Hadoop
1 4 (1.78%) Tableau
2 1 (0.44%) Oracle Database
2 1 (0.44%) Oracle Exadata
Development Applications
1 18 (8.00%) Jenkins
2 13 (5.78%) Burp Suite
3 12 (5.33%) GitLab
4 7 (3.11%) JIRA
5 4 (1.78%) IDA Disassembler
5 4 (1.78%) Vagrant
6 3 (1.33%) Metasploit
6 3 (1.33%) TeamCity
7 1 (0.44%) CircleCI
General
1 53 (23.56%) Finance
2 44 (19.56%) Social Skills
3 35 (15.56%) Public Sector
4 32 (14.22%) Analytical Skills
5 30 (13.33%) Banking
6 11 (4.89%) Retail
7 6 (2.67%) Manufacturing
8 5 (2.22%) Legal
9 4 (1.78%) Presentation Skills
10 3 (1.33%) Automotive
11 2 (0.89%) Electronics
11 2 (0.89%) Multimedia
12 1 (0.44%) Influencing Skills
12 1 (0.44%) Marketing
12 1 (0.44%) Spanish Language
Job Titles
1 37 (16.44%) Architect
2 33 (14.67%) Security Architect
3 30 (13.33%) Consultant
4 27 (12.00%) Analyst
4 27 (12.00%) Security Consultant
4 27 (12.00%) Security Engineer
5 19 (8.44%) Senior
6 17 (7.56%) Penetration Tester
6 17 (7.56%) Tester
7 16 (7.11%) Security Analyst
8 15 (6.67%) Infrastructure Engineer
9 14 (6.22%) Network Engineer
10 12 (5.33%) Cybersecurity Analyst
11 11 (4.89%) Network Infrastructure Engineer
12 8 (3.56%) SC Cleared Network Engineer
12 8 (3.56%) Security Manager
12 8 (3.56%) Security Specialist
13 7 (3.11%) Cybersecurity Specialist
13 7 (3.11%) DevSecOps Engineer
13 7 (3.11%) SOC Analyst
Libraries, Frameworks & Software Standards
1 5 (2.22%) OAuth
1 5 (2.22%) OAuth2
1 5 (2.22%) SAML
2 4 (1.78%) OLE
3 2 (0.89%) RESTful
3 2 (0.89%) Web Services
4 1 (0.44%) .NET
4 1 (0.44%) EDI
Miscellaneous
1 30 (13.33%) Cyber Threat
2 24 (10.67%) Security Posture
3 16 (7.11%) Data Centre
3 16 (7.11%) Mobile App
3 16 (7.11%) PKI
4 15 (6.67%) Management Information System
4 15 (6.67%) Private Cloud
5 11 (4.89%) Security Operations Centre
6 9 (4.00%) Operational Technology
7 8 (3.56%) Cloud Native
8 6 (2.67%) Cyber Defence
8 6 (2.67%) Cyber Kill Chain
9 4 (1.78%) Cyberattack
9 4 (1.78%) Hybrid Cloud
9 4 (1.78%) YARA
10 3 (1.33%) IoT
10 3 (1.33%) Renewable Energy
11 2 (0.89%) Algorithms
11 2 (0.89%) Data Protection Act
11 2 (0.89%) Public Cloud
Operating Systems
1 46 (20.44%) Windows
2 38 (16.89%) Linux
3 10 (4.44%) Kali Linux
4 7 (3.11%) Windows Server
5 6 (2.67%) Unix
6 4 (1.78%) AIX
6 4 (1.78%) Solaris
7 1 (0.44%) Mac OS X
Processes & Methodologies
1 115 (51.11%) Cybersecurity
2 68 (30.22%) Information Security
3 49 (21.78%) Cloud Security
4 41 (18.22%) Security Operations
4 41 (18.22%) SIEM
5 39 (17.33%) Application Security
5 39 (17.33%) Threat Modelling
6 37 (16.44%) Vulnerability Scanning
7 36 (16.00%) Incident Response
8 35 (15.56%) DevOps
8 35 (15.56%) DevSecOps
9 34 (15.11%) Vulnerability Management
10 31 (13.78%) Problem-Solving
11 30 (13.33%) CI/CD
12 29 (12.89%) Agile
12 29 (12.89%) Ethical Hacking
12 29 (12.89%) Red Team
13 28 (12.44%) Vulnerability Assessment
14 27 (12.00%) Risk Assessment
14 27 (12.00%) Security Architecture
Programming Languages
1 26 (11.56%) Python
2 14 (6.22%) Kusto Query Language
3 10 (4.44%) C++
4 7 (3.11%) JavaScript
5 6 (2.67%) PowerShell
6 5 (2.22%) C#
6 5 (2.22%) Perl
6 5 (2.22%) Search Processing Language
7 4 (1.78%) Go
7 4 (1.78%) SQL
8 3 (1.33%) C
8 3 (1.33%) Java
8 3 (1.33%) Shell Script
9 2 (0.89%) Ruby
10 1 (0.44%) Bash
Qualifications
1 54 (24.00%) Security Cleared
2 51 (22.67%) SC Cleared
3 32 (14.22%) Degree
4 23 (10.22%) OSCP
5 19 (8.44%) CREST Certified
6 16 (7.11%) Computer Science Degree
7 15 (6.67%) CISSP
8 14 (6.22%) CEH
9 12 (5.33%) CISM
9 12 (5.33%) GIAC
10 9 (4.00%) GPEN
11 8 (3.56%) ITIL Certification
11 8 (3.56%) MCSE
11 8 (3.56%) Microsoft Certification
12 7 (3.11%) CompTIA Security+
13 5 (2.22%) AWS Certification
13 5 (2.22%) DV Cleared
14 4 (1.78%) CHECK Team Leader
14 4 (1.78%) Cisco Certification
14 4 (1.78%) Master's Degree
Quality Assurance & Compliance
1 52 (23.11%) ISO/IEC 27001
2 47 (20.89%) NIST
3 17 (7.56%) GDPR
4 16 (7.11%) PCI DSS
5 12 (5.33%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
6 9 (4.00%) HMG Security Policy Framework
7 7 (3.11%) QA
8 6 (2.67%) HIPAA
9 5 (2.22%) COBIT
9 5 (2.22%) Disclosure Scotland
9 5 (2.22%) NCSC
10 4 (1.78%) SLA
11 3 (1.33%) PMO
12 2 (0.89%) Actionable Recommendations
12 2 (0.89%) Automotive SPICE
12 2 (0.89%) AUTOSAR
12 2 (0.89%) Cyber Essentials
12 2 (0.89%) ISO 22301
12 2 (0.89%) Sarbanes-Oxley
13 1 (0.44%) JSP 440
System Software
1 18 (8.00%) Active Directory
2 16 (7.11%) VMware Infrastructure
3 14 (6.22%) vSphere
4 5 (2.22%) Docker
4 5 (2.22%) Hyper-V
4 5 (2.22%) Snort
5 1 (0.44%) Terminal Services
Systems Management
1 21 (9.33%) Terraform
2 13 (5.78%) vCenter Server
3 6 (2.67%) Nessus
4 5 (2.22%) SCCM
5 4 (1.78%) Kibana
5 4 (1.78%) Tivoli
6 2 (0.89%) CASB
6 2 (0.89%) HP Fortify
6 2 (0.89%) Kubernetes
6 2 (0.89%) Microsoft Intune
7 1 (0.44%) Ansible
7 1 (0.44%) Computer Emergency Response Teams
7 1 (0.44%) CSIRT
7 1 (0.44%) Nmap
7 1 (0.44%) Single Sign-On
Vendors
1 34 (15.11%) Microsoft
2 17 (7.56%) VMware
3 16 (7.11%) Google
4 10 (4.44%) Splunk
5 9 (4.00%) Cisco
6 7 (3.11%) Qualys
7 6 (2.67%) Oracle
8 5 (2.22%) F5
8 5 (2.22%) SAP
9 4 (1.78%) AppDynamics
9 4 (1.78%) CheckPoint
9 4 (1.78%) IBM
10 3 (1.33%) Tufin
10 3 (1.33%) Zscaler
11 2 (0.89%) Checkmarx
11 2 (0.89%) Palo Alto
11 2 (0.89%) Salesforce
11 2 (0.89%) Veracode
12 1 (0.44%) BigPanda
12 1 (0.44%) Intel