Threat Modelling
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Threat Modelling skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Threat Modelling over the 6 months to 20 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
20 May 2024
Same period 2023 Same period 2022
Rank 734 540 746
Rank change year-on-year -194 +206 +10
Permanent jobs citing Threat Modelling 150 507 559
As % of all permanent jobs advertised in the UK 0.15% 0.51% 0.34%
As % of the Processes & Methodologies category 0.18% 0.53% 0.36%
Number of salaries quoted 107 265 282
10th Percentile £46,875 £45,096 £51,250
25th Percentile £57,250 £61,750 £60,000
Median annual salary (50th Percentile) £72,500 £81,928 £77,500
Median % change year-on-year -11.51% +5.71% +3.33%
75th Percentile £83,750 £100,000 £92,500
90th Percentile £102,250 £120,000 £101,250
UK excluding London median annual salary £58,750 £70,000 £70,400
% change year-on-year -16.07% -0.57% +8.31%

All Process and Methodology Skills
UK

Threat Modelling is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 85,108 95,066 155,930
As % of all permanent jobs advertised in the UK 85.18% 95.58% 95.78%
Number of salaries quoted 59,794 56,135 83,138
10th Percentile £29,071 £34,000 £33,645
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,180 £60,000
Median % change year-on-year -10.10% +1.97% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +10.53%

Threat Modelling
Job Vacancy Trend

Job postings citing Threat Modelling as a proportion of all IT jobs advertised.

Job vacancy trend for Threat Modelling in the UK

Threat Modelling
Salary Trend

3-month moving average salary quoted in jobs citing Threat Modelling.

Salary trend for Threat Modelling in the UK

Threat Modelling
Salary Histogram

Salary distribution for jobs citing Threat Modelling over the 6 months to 20 May 2024.

Salary histogram for Threat Modelling in the UK

Threat Modelling
Top 13 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Threat Modelling within the UK over the 6 months to 20 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -201 113 £70,000 -15.15% 65
UK excluding London -133 74 £58,750 -16.07% 39
London -92 45 £97,500 +14.71% 31
Work from Home -48 39 £82,500 +3.77% 30
North of England -9 27 £50,000 -28.57% 6
North West -21 20 £50,000 -28.57% 6
South West -17 14 £72,500 +11.97% 6
West Midlands +15 13 £72,500 +2.84% 7
Midlands -8 13 £72,500 +2.84% 7
South East -50 13 £59,000 -30.59% 16
Yorkshire +57 7 £50,000 -28.00%
Scotland -84 6 - - 2
East of England +5 1 - - 2

Threat Modelling
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Applications
1 12 (8.00%) Microsoft Office
2 9 (6.00%) Microsoft Excel
Cloud Services
1 81 (54.00%) AWS
1 81 (54.00%) Azure
2 32 (21.33%) GCP
3 18 (12.00%) Microsoft 365
4 15 (10.00%) Serverless
5 12 (8.00%) Power Platform
6 11 (7.33%) AWS CloudFormation
6 11 (7.33%) Virtual Private Cloud
7 10 (6.67%) Amazon CloudWatch
7 10 (6.67%) Amazon EC2
7 10 (6.67%) Amazon GuardDuty
7 10 (6.67%) Amazon S3
7 10 (6.67%) AWS CloudTrail
7 10 (6.67%) AWS Lambda
7 10 (6.67%) Cloud Computing
8 8 (5.33%) PaaS
9 6 (4.00%) Azure Service Fabric
9 6 (4.00%) Entra ID
9 6 (4.00%) IaaS
9 6 (4.00%) SaaS
Communications & Networking
1 28 (18.67%) Firewall
2 20 (13.33%) LAN
3 16 (10.67%) DNS
4 11 (7.33%) Intrusion Detection
5 10 (6.67%) Network Security
6 6 (4.00%) SSL
7 5 (3.33%) HTTP
7 5 (3.33%) Internet
7 5 (3.33%) VPN
7 5 (3.33%) WAN
8 4 (2.67%) SMTP
8 4 (2.67%) Wireless
9 2 (1.33%) 802.11
9 2 (1.33%) Bluetooth
9 2 (1.33%) Wireshark
9 2 (1.33%) ZigBee
10 1 (0.67%) IPv4
10 1 (0.67%) NGFW
10 1 (0.67%) SD-WAN
10 1 (0.67%) TCP/IP
Database & Business Intelligence
1 10 (6.67%) Amazon RDS
2 9 (6.00%) Power BI
3 6 (4.00%) Azure SQL Database
4 3 (2.00%) Data Lake
5 2 (1.33%) Big Data
Development Applications
1 19 (12.67%) Jenkins
2 8 (5.33%) Burp Suite
3 7 (4.67%) Metasploit
4 3 (2.00%) sqlmap
5 2 (1.33%) Bitbucket
6 1 (0.67%) CircleCI
6 1 (0.67%) GitLab
6 1 (0.67%) Snyk
General
1 46 (30.67%) Social Skills
2 36 (24.00%) Finance
3 16 (10.67%) Inclusion and Diversity
3 16 (10.67%) Presentation Skills
3 16 (10.67%) Public Sector
4 15 (10.00%) Banking
4 15 (10.00%) Law
5 14 (9.33%) Retail
6 10 (6.67%) Marketing
7 7 (4.67%) Analytical Skills
8 6 (4.00%) Manufacturing
9 5 (3.33%) Investment Banking
9 5 (3.33%) Legal
10 2 (1.33%) Cyber-Physical System
10 2 (1.33%) Financial Institution
10 2 (1.33%) Influencing Skills
10 2 (1.33%) Organisational Skills
11 1 (0.67%) Automotive
11 1 (0.67%) Pharmaceutical
11 1 (0.67%) Telecoms
Job Titles
1 49 (32.67%) Architect
2 42 (28.00%) Security Architect
3 40 (26.67%) Senior
4 26 (17.33%) Security Engineer
5 22 (14.67%) Cybersecurity Architect
6 18 (12.00%) Lead
7 15 (10.00%) Senior Architect
8 13 (8.67%) Consultant
8 13 (8.67%) Security Consultant
9 12 (8.00%) AWS Engineer
10 11 (7.33%) Security Technical Architect
10 11 (7.33%) Technical Architect
11 9 (6.00%) DevSecOps Engineer
11 9 (6.00%) Senior Security Architect
12 8 (5.33%) Analyst
12 8 (5.33%) Cybersecurity Engineer
12 8 (5.33%) Information Architect
12 8 (5.33%) Information Security Architect
13 7 (4.67%) Security Analyst
13 7 (4.67%) Senior Consultant
Libraries, Frameworks & Software Standards
1 13 (8.67%) Web Services
2 12 (8.00%) OAuth
3 6 (4.00%) REST
3 6 (4.00%) SAML
3 6 (4.00%) SOAP
4 4 (2.67%) JWT
5 2 (1.33%) 802.1X
5 2 (1.33%) HTML
5 2 (1.33%) Middleware
5 2 (1.33%) OAuth2
5 2 (1.33%) OpenID
6 1 (0.67%) AWS CDK
6 1 (0.67%) HTML5
6 1 (0.67%) WebSockets
Miscellaneous
1 35 (23.33%) Cyberattack
2 31 (20.67%) Management Information System
3 26 (17.33%) Cyber Threat
4 21 (14.00%) Data Centre
5 20 (13.33%) PKI
6 17 (11.33%) Security Posture
7 15 (10.00%) Onboarding
8 11 (7.33%) iPhone
9 10 (6.67%) Public Cloud
10 9 (6.00%) IoT
11 8 (5.33%) Hybrid Cloud
12 7 (4.67%) PropTech
13 6 (4.00%) Distributed Systems
14 5 (3.33%) Mobile App
14 5 (3.33%) Self-Motivation
15 3 (2.00%) Cloud Native
15 3 (2.00%) Cyber Kill Chain
15 3 (2.00%) SCADA
16 2 (1.33%) Renewable Energy
16 2 (1.33%) Security Operations Centre
Operating Systems
1 23 (15.33%) Windows
2 9 (6.00%) Kali Linux
3 7 (4.67%) Android
3 7 (4.67%) Apple iOS
4 4 (2.67%) Unix
5 3 (2.00%) Linux
5 3 (2.00%) Windows Server
6 2 (1.33%) Windows XP
7 1 (0.67%) Red Hat Enterprise Linux
Processes & Methodologies
1 103 (68.67%) Cybersecurity
2 61 (40.67%) Information Security
3 48 (32.00%) Application Security
4 47 (31.33%) Incident Response
5 40 (26.67%) Penetration Testing
6 39 (26.00%) Vulnerability Management
7 34 (22.67%) Security Architecture
8 28 (18.67%) Threat Intelligence
8 28 (18.67%) Threat Management
9 27 (18.00%) Cyber Threat Intelligence
10 26 (17.33%) Identity Access Management
10 26 (17.33%) Secure Coding
11 25 (16.67%) Cloud Security
11 25 (16.67%) Stakeholder Management
12 24 (16.00%) OWASP
13 23 (15.33%) MITRE ATT&CK
13 23 (15.33%) Roadmaps
13 23 (15.33%) SIEM
14 22 (14.67%) Problem-Solving
14 22 (14.67%) Reverse Engineering
Programming Languages
1 38 (25.33%) Python
2 11 (7.33%) Go
2 11 (7.33%) Java
3 6 (4.00%) C#
3 6 (4.00%) JavaScript
3 6 (4.00%) SQL
4 5 (3.33%) PowerShell
5 4 (2.67%) Lua
5 4 (2.67%) Ruby
5 4 (2.67%) Rust
6 2 (1.33%) Dart
6 2 (1.33%) Kotlin
6 2 (1.33%) Objective-C
6 2 (1.33%) PHP
6 2 (1.33%) Swift
7 1 (0.67%) C++
Qualifications
1 75 (50.00%) CISSP
2 56 (37.33%) CISM
3 40 (26.67%) AWS Certification
4 38 (25.33%) GIAC
5 26 (17.33%) Degree
5 26 (17.33%) OSCP
6 24 (16.00%) CREST Certified
7 23 (15.33%) Security Cleared
8 22 (14.67%) SC Cleared
9 21 (14.00%) Azure Certification
10 20 (13.33%) CRISC
11 16 (10.67%) ISSMP
12 11 (7.33%) BPSS Clearance
13 10 (6.67%) CISA
14 9 (6.00%) Computer Science Degree
15 8 (5.33%) CEH
15 8 (5.33%) Cisco Certification
15 8 (5.33%) Master's Degree
15 8 (5.33%) SANS
16 7 (4.67%) (ISC)2 CCSP
Quality Assurance & Compliance
1 46 (30.67%) NIST
2 31 (20.67%) ISO/IEC 27001
3 24 (16.00%) COBIT
4 12 (8.00%) PCI DSS
5 7 (4.67%) Cyber Essentials
5 7 (4.67%) QA
5 7 (4.67%) SOC 2
6 6 (4.00%) Web Application Security Consortium
7 5 (3.33%) Cyber Essentials PLUS
7 5 (3.33%) IASME
7 5 (3.33%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
8 4 (2.67%) GDPR
8 4 (2.67%) NCSC
8 4 (2.67%) NIST 800
9 2 (1.33%) HIPAA
9 2 (1.33%) ISO 31000
10 1 (0.67%) GRC
10 1 (0.67%) GxP
10 1 (0.67%) IEC 61508
System Software
1 20 (13.33%) Active Directory
2 4 (2.67%) Virtual Machines
3 3 (2.00%) Docker
Systems Management
1 18 (12.00%) Kubernetes
2 16 (10.67%) Ansible
3 10 (6.67%) Nessus
4 7 (4.67%) Computer Emergency Response Teams
5 5 (3.33%) Nmap
5 5 (3.33%) Suricata
6 4 (2.67%) HP Fortify
6 4 (2.67%) Single Sign-On
7 2 (1.33%) QRadar
7 2 (1.33%) Terraform
8 1 (0.67%) Anchore
8 1 (0.67%) Computer Incident Response Team
Vendors
1 26 (17.33%) Microsoft
2 16 (10.67%) Alibaba
3 13 (8.67%) Google
4 10 (6.67%) Splunk
5 7 (4.67%) Cisco
6 6 (4.00%) Palo Alto
7 5 (3.33%) Juniper
8 4 (2.67%) Qualys
9 3 (2.00%) Veracode
10 2 (1.33%) Fortinet
10 2 (1.33%) IBM
10 2 (1.33%) VMware
11 1 (0.67%) Forcepoint
11 1 (0.67%) Intel
11 1 (0.67%) Netskope
11 1 (0.67%) Okta
11 1 (0.67%) Red Hat
11 1 (0.67%) Zscaler