Penetration Testing
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Penetration Testing skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Penetration Testing over the 6 months to 28 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
28 May 2024
Same period 2023 Same period 2022
Rank 460 476 561
Rank change year-on-year +16 +85 -114
Permanent jobs citing Penetration Testing 511 599 950
As % of all permanent jobs advertised in the UK 0.50% 0.62% 0.57%
As % of the Processes & Methodologies category 0.59% 0.64% 0.59%
Number of salaries quoted 403 408 639
10th Percentile £38,797 £43,668 £37,411
25th Percentile £48,750 £50,015 £51,250
Median annual salary (50th Percentile) £65,000 £65,000 £63,187
Median % change year-on-year - +2.87% +3.58%
75th Percentile £82,500 £89,063 £78,750
90th Percentile £95,000 £103,750 £92,100
UK excluding London median annual salary £57,500 £55,000 £60,000
% change year-on-year +4.55% -8.33% +9.09%

All Process and Methodology Skills
UK

Penetration Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 86,445 93,025 160,114
As % of all permanent jobs advertised in the UK 84.24% 95.56% 95.90%
Number of salaries quoted 60,550 54,985 83,280
10th Percentile £29,250 £34,000 £33,500
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,000 £60,000
Median % change year-on-year -9.84% +1.67% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +9.38%

Penetration Testing
Job Vacancy Trend

Job postings citing Penetration Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Penetration Testing in the UK

Penetration Testing
Salary Trend

3-month moving average salary quoted in jobs citing Penetration Testing.

Salary trend for Penetration Testing in the UK

Penetration Testing
Salary Histogram

Salary distribution for jobs citing Penetration Testing over the 6 months to 28 May 2024.

Salary histogram for Penetration Testing in the UK

Penetration Testing
Top 16 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 28 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England +24 459 £65,000 - 128
UK excluding London -63 235 £57,500 +4.55% 81
London +88 223 £75,000 -8.46% 45
Work from Home -22 207 £60,000 -11.11% 102
South East -4 65 £43,750 -30.00% 17
Midlands -6 53 £55,000 -8.33% 7
North of England +22 48 £60,000 +14.29% 25
South West -14 48 £63,750 +25.00% 14
North West +11 36 £60,000 +12.15% 18
West Midlands -7 30 £55,000 -8.33% 6
East Midlands +2 23 £65,000 - 1
Yorkshire +52 12 £44,250 -14.79% 6
Scotland -73 10 £60,000 +7.75% 9
East of England -17 7 £40,000 -27.27% 6
Wales 0 3 £90,000 +60.71% 2
Channel Islands - 1 £100,000 -

Penetration Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 4 (0.78%) Microsoft Exchange
2 3 (0.59%) SharePoint
3 1 (0.20%) Apache
3 1 (0.20%) Confluence
3 1 (0.20%) IIS
3 1 (0.20%) WebSphere
Applications
1 3 (0.59%) Microsoft Office
2 1 (0.20%) Microsoft Excel
Business Applications
1 1 (0.20%) Remedy ITSM
Cloud Services
1 112 (21.92%) Azure
2 77 (15.07%) AWS
3 49 (9.59%) Microsoft 365
4 27 (5.28%) GCP
5 22 (4.31%) Cloud Computing
6 12 (2.35%) SaaS
7 11 (2.15%) Google Workspace
8 9 (1.76%) Entra ID
9 8 (1.57%) Amazon ECS
9 8 (1.57%) Cloudflare
10 7 (1.37%) Dynamics 365
10 7 (1.37%) PaaS
11 6 (1.17%) Azure Sentinel
11 6 (1.17%) IaaS
12 5 (0.98%) Azure DevOps
13 4 (0.78%) Azure Service Bus
13 4 (0.78%) Mimecast
14 3 (0.59%) Azure Synapse Analytics
14 3 (0.59%) Power Platform
14 3 (0.59%) PowerApps
Communications & Networking
1 124 (24.27%) Firewall
2 75 (14.68%) Network Security
3 41 (8.02%) Wireless
4 31 (6.07%) DNS
5 27 (5.28%) Intrusion Detection
6 20 (3.91%) Wi-Fi
7 16 (3.13%) TCP/IP
8 13 (2.54%) VPN
9 11 (2.15%) Broadband
9 11 (2.15%) NAS
10 10 (1.96%) Internet
10 10 (1.96%) Wireshark
11 9 (1.76%) SSL
12 8 (1.57%) LAN
12 8 (1.57%) NGFW
12 8 (1.57%) WAN
13 6 (1.17%) BGP
14 5 (0.98%) HTTP
14 5 (0.98%) IPsec
14 5 (0.98%) OSPF
Database & Business Intelligence
1 9 (1.76%) SQL Server
2 6 (1.17%) MongoDB
3 5 (0.98%) NoSQL
4 4 (0.78%) InfluxDB
5 3 (0.59%) Data Lake
6 2 (0.39%) Azure SQL Database
7 1 (0.20%) Redis
Development Applications
1 40 (7.83%) Burp Suite
1 40 (7.83%) Metasploit
2 8 (1.57%) Git
2 8 (1.57%) Jenkins
3 6 (1.17%) JIRA
4 5 (0.98%) Postman
5 4 (0.78%) JMeter
5 4 (0.78%) SoapUI
6 3 (0.59%) Cucumber
6 3 (0.59%) SpecFlow
7 2 (0.39%) Bitbucket
8 1 (0.20%) GitLab
8 1 (0.20%) Selenium
8 1 (0.20%) Snyk
General
1 158 (30.92%) Social Skills
2 89 (17.42%) Analytical Skills
3 76 (14.87%) Finance
4 45 (8.81%) Legal
5 31 (6.07%) Law
6 29 (5.68%) Retail
7 28 (5.48%) Presentation Skills
8 26 (5.09%) Telecoms
9 25 (4.89%) Games
10 24 (4.70%) Banking
11 21 (4.11%) Aerospace
12 20 (3.91%) Inclusion and Diversity
13 19 (3.72%) Marketing
14 18 (3.52%) Public Sector
15 14 (2.74%) Influencing Skills
15 14 (2.74%) Military
16 9 (1.76%) Manufacturing
17 7 (1.37%) Automotive
17 7 (1.37%) Aviation
17 7 (1.37%) Pharmaceutical
Job Titles
1 139 (27.20%) Penetration Tester
1 139 (27.20%) Tester
2 72 (14.09%) Senior
3 68 (13.31%) Analyst
4 67 (13.11%) Lead
5 50 (9.78%) Security Analyst
6 39 (7.63%) Security Engineer
7 36 (7.05%) Consultant
8 31 (6.07%) Security Manager
8 31 (6.07%) Team Leader
9 27 (5.28%) Senior Penetration Tester
9 27 (5.28%) Senior Tester
10 26 (5.09%) Architect
11 23 (4.50%) Security Consultant
12 21 (4.11%) Security Architect
13 20 (3.91%) Cybersecurity Analyst
13 20 (3.91%) Security Tester
13 20 (3.91%) Test Team Leader
14 19 (3.72%) Security Penetration Tester
15 17 (3.33%) Cybersecurity Manager
Libraries, Frameworks & Software Standards
1 14 (2.74%) OAuth
2 12 (2.35%) OAuth2
3 8 (1.57%) Laravel
4 6 (1.17%) Web Services
5 4 (0.78%) EDI
5 4 (0.78%) OpenID
5 4 (0.78%) SOAP
5 4 (0.78%) XML
6 3 (0.59%) RESTful
6 3 (0.59%) WPF
7 2 (0.39%) SAML
8 1 (0.20%) ARM Templates
8 1 (0.20%) HTML
8 1 (0.20%) JSON
8 1 (0.20%) Kafka
8 1 (0.20%) Loki
8 1 (0.20%) SignalR
8 1 (0.20%) YAML
Miscellaneous
1 47 (9.20%) Cyber Threat
2 44 (8.61%) Security Posture
3 42 (8.22%) Management Information System
4 36 (7.05%) Cyberattack
5 29 (5.68%) Mobile App
6 24 (4.70%) Onboarding
7 23 (4.50%) Self-Motivation
8 21 (4.11%) Operational Technology
9 15 (2.94%) Data Centre
9 15 (2.94%) IoT
10 14 (2.74%) Cyber Defence
11 13 (2.54%) Hybrid Cloud
12 11 (2.15%) Video Conferencing
13 8 (1.57%) Cyber Security Posture
14 7 (1.37%) Distributed Denial-of-Service
15 6 (1.17%) Analytical Mindset
15 6 (1.17%) Data Protection Act
15 6 (1.17%) Embedded Systems
16 5 (0.98%) Product Ownership
16 5 (0.98%) Virtual Team
Operating Systems
1 72 (14.09%) Windows
2 60 (11.74%) Linux
3 42 (8.22%) Kali Linux
4 25 (4.89%) Apple iOS
5 24 (4.70%) Android
6 21 (4.11%) Windows Server
7 18 (3.52%) Unix
8 12 (2.35%) Mac OS
9 3 (0.59%) Mac OS X
9 3 (0.59%) Windows XP
10 2 (0.39%) AIX
10 2 (0.39%) Red Hat Enterprise Linux
11 1 (0.20%) VMS
11 1 (0.20%) Windows 10
11 1 (0.20%) Windows Server 2016
Processes & Methodologies
1 369 (72.21%) Cybersecurity
2 149 (29.16%) Information Security
3 117 (22.90%) Computer Science
4 115 (22.50%) Problem-Solving
5 103 (20.16%) Incident Response
6 91 (17.81%) Application Security
6 91 (17.81%) Vulnerability Scanning
7 89 (17.42%) Red Team
8 83 (16.24%) Security Testing
9 70 (13.70%) SIEM
9 70 (13.70%) Vulnerability Management
10 62 (12.13%) Mentoring
11 59 (11.55%) Vulnerability Assessment
12 54 (10.57%) OWASP
13 49 (9.59%) Security Operations
14 46 (9.00%) Patch Management
14 46 (9.00%) Risk Management
15 43 (8.41%) Cloud Security
15 43 (8.41%) Data Protection
15 43 (8.41%) Malware Analysis
Programming Languages
1 53 (10.37%) Python
2 33 (6.46%) Bash
3 14 (2.74%) PowerShell
4 13 (2.54%) Java
5 11 (2.15%) SQL
6 8 (1.57%) PHP
6 8 (1.57%) Rust
7 7 (1.37%) C#
7 7 (1.37%) Go
7 7 (1.37%) JavaScript
8 2 (0.39%) Ruby
9 1 (0.20%) C++
9 1 (0.20%) TypeScript
Qualifications
1 126 (24.66%) Degree
2 100 (19.57%) CISSP
3 90 (17.61%) CREST Certified
4 72 (14.09%) OSCP
5 68 (13.31%) Computer Science Degree
6 62 (12.13%) CISM
7 49 (9.59%) Security Cleared
8 43 (8.41%) SC Cleared
9 35 (6.85%) CEH
10 34 (6.65%) CHECK Team Member
11 32 (6.26%) GIAC
12 29 (5.68%) CompTIA Security+
13 28 (5.48%) CISA
14 26 (5.09%) CHECK Team Leader
15 18 (3.52%) Cisco Certification
16 17 (3.33%) CompTIA CySA+
16 17 (3.33%) GPEN
17 14 (2.74%) Cyber Scheme
18 11 (2.15%) AWS Certification
18 11 (2.15%) Network+ Certification
Quality Assurance & Compliance
1 98 (19.18%) ISO/IEC 27001
2 58 (11.35%) NIST
3 51 (9.98%) Cyber Essentials
4 30 (5.87%) GRC
5 27 (5.28%) GDPR
6 26 (5.09%) PCI DSS
7 24 (4.70%) Cyber Essentials PLUS
8 21 (4.11%) QA
9 18 (3.52%) SOC 2
10 9 (1.76%) NCSC
11 8 (1.57%) NIST 800
12 7 (1.37%) Actionable Recommendations
12 7 (1.37%) DO-254
13 6 (1.17%) COBIT
13 6 (1.17%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
14 5 (0.98%) HIPAA
15 4 (0.78%) Accessibility
16 3 (0.59%) HMG Security Policy Framework
16 3 (0.59%) JSP 440
16 3 (0.59%) JTAG
System Software
1 44 (8.61%) Active Directory
2 25 (4.89%) VMware Infrastructure
3 10 (1.96%) Virtual Machines
4 7 (1.37%) Docker
5 2 (0.39%) Virtual Servers
6 1 (0.20%) Hyper-V
Systems Management
1 21 (4.11%) Nessus
2 19 (3.72%) Kubernetes
3 13 (2.54%) Ansible
4 12 (2.35%) WSUS
5 11 (2.15%) Computer Emergency Response Teams
5 11 (2.15%) Single Sign-On
6 10 (1.96%) Nmap
6 10 (1.96%) QRadar
7 7 (1.37%) CASB
7 7 (1.37%) SCCM
8 6 (1.17%) Microsoft Intune
8 6 (1.17%) Terraform
9 5 (0.98%) Grafana
9 5 (0.98%) Progress Chef
9 5 (0.98%) Suricata
10 4 (0.78%) DatAdvantage
10 4 (0.78%) HP Fortify
11 3 (0.59%) FortiGate
12 2 (0.39%) CSIRT
13 1 (0.20%) Prometheus
Vendors
1 94 (18.40%) Microsoft
2 25 (4.89%) VMware
3 23 (4.50%) Cisco
4 22 (4.31%) Qualys
5 20 (3.91%) Google
6 16 (3.13%) Splunk
7 11 (2.15%) Apple
8 9 (1.76%) Palo Alto
9 7 (1.37%) IBM
9 7 (1.37%) Kenna
9 7 (1.37%) Rapid7
10 6 (1.17%) HubSpot
10 6 (1.17%) Oracle
11 5 (0.98%) Alibaba
11 5 (0.98%) Juniper
11 5 (0.98%) Red Hat
12 4 (0.78%) Darktrace
12 4 (0.78%) ServiceNow
12 4 (0.78%) Varonis
12 4 (0.78%) Veeam