Static Application Security Testing Contracts

Static Application Security Testing (SAST)
UK

The following table provides summary statistics for contract job vacancies with a requirement for Static Application Security Testing skills. Included is a benchmarking guide to the contractor rates offered in vacancies that have cited Static Application Security Testing over the 6 months to 27 April 2024 with a comparison to the same period in the previous 2 years.

6 months to
27 Apr 2024
Same period 2023 Same period 2022
Rank 505 629 765
Rank change year-on-year +124 +136 -117
Contract jobs citing Static Application Security Testing 93 90 84
As % of all contract jobs advertised in the UK 0.21% 0.15% 0.095%
As % of the Processes & Methodologies category 0.25% 0.17% 0.10%
Number of daily rates quoted 77 61 60
10th Percentile £540 £463 £459
25th Percentile £613 £513 £550
Median daily rate (50th Percentile) £650 £625 £650
Median % change year-on-year +4.00% -3.85% +23.81%
75th Percentile £675 £738 £700
90th Percentile £760 £800 £739
UK excluding London median daily rate £613 £625 £427
% change year-on-year -2.00% +46.37% +6.75%
Number of hourly rates quoted 0 0 2
10th Percentile - - £41.00
25th Percentile - - £42.50
Median hourly rate - - £45.00
75th Percentile - - £47.50
90th Percentile - - £49.00
UK excluding London median hourly rate - - -

All Process and Methodology Skills
UK

Static Application Security Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all contract job vacancies with a requirement for process or methodology skills.

Contract vacancies with a requirement for process or methodology skills 37,374 53,774 80,482
As % of all contract IT jobs advertised in the UK 86.31% 89.91% 90.60%
Number of daily rates quoted 24,095 37,304 56,474
10th Percentile £300 £325 £340
25th Percentile £413 £438 £425
Median daily rate (50th Percentile) £525 £550 £525
Median % change year-on-year -4.55% +4.76% +8.25%
75th Percentile £638 £650 £638
90th Percentile £750 £750 £738
UK excluding London median daily rate £500 £500 £475
% change year-on-year - +5.26% +9.20%
Number of hourly rates quoted 2,422 1,763 1,928
10th Percentile £12.75 £11.00 £12.50
25th Percentile £16.00 £16.25 £15.25
Median hourly rate £35.00 £37.34 £25.00
Median % change year-on-year -6.27% +49.36% -
75th Percentile £59.44 £65.00 £49.25
90th Percentile £72.50 £75.00 £63.75
UK excluding London median hourly rate £36.00 £36.00 £20.00
% change year-on-year - +80.00% -8.17%

Static Application Security Testing
Job Vacancy Trend

Job postings citing Static Application Security Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Static Application Security Testing in the UK

Static Application Security Testing
Contractor Daily Rate Trend

3-month moving average daily rate quoted in jobs citing Static Application Security Testing.

Daily rate trend for Static Application Security Testing in the UK

Static Application Security Testing
Daily Rate Histogram

Daily rate distribution for jobs citing Static Application Security Testing over the 6 months to 27 April 2024.

Daily rate histogram for Static Application Security Testing in the UK

Static Application Security Testing
Contractor Hourly Rate Trend

3-month moving average hourly rates quoted in jobs citing Static Application Security Testing.

Hourly rate trend for Static Application Security Testing in the UK

Static Application Security Testing
Top 11 Contract Locations

The table below looks at the demand and provides a guide to the median contractor rates quoted in IT jobs citing Static Application Security Testing within the UK over the 6 months to 27 April 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Contract
IT Job Ads
Median
Daily Rate
Past 6 Months
Median Daily Rate
% Change
on Same Period
Last Year
Live
Jobs
England +130 74 £650 +4.00% 20
London +110 63 £650 +4.00% 12
Work from Home +128 39 £650 - 6
UK excluding London +64 14 £613 -2.00% 7
South West +26 6 £550 -12.00% 2
Scotland - 4 £494 -
South East +27 2 £650 -13.33% 2
North of England +30 1 £750 +50.00% 2
West Midlands +23 1 £750 +3.45% 1
Midlands +16 1 £750 +3.45% 1
North West +15 1 £750 +33.33% 2

Static Application Security Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 2 (2.15%) Confluence
2 1 (1.08%) Microsoft Exchange
2 1 (1.08%) SAS
Applications
1 5 (5.38%) Microsoft Office
1 5 (5.38%) Microsoft Project
Business Applications
1 3 (3.23%) Dynamics GP
Cloud Services
1 29 (31.18%) Azure
2 28 (30.11%) AWS
3 13 (13.98%) Azure DevOps
3 13 (13.98%) GitHub
4 12 (12.90%) GitHub Actions
4 12 (12.90%) PaaS
4 12 (12.90%) SaaS
5 10 (10.75%) IaaS
6 8 (8.60%) GCP
7 3 (3.23%) Azure AKS
7 3 (3.23%) Microsoft 365
7 3 (3.23%) Miro
7 3 (3.23%) Power Platform
8 2 (2.15%) Amazon EKS
8 2 (2.15%) Amazon S3
8 2 (2.15%) Azure Sentinel
8 2 (2.15%) OpenShift
9 1 (1.08%) Amazon EC2
9 1 (1.08%) CloudFront
9 1 (1.08%) Route 53
Communications & Networking
1 5 (5.38%) Firewall
2 3 (3.23%) SSL
3 1 (1.08%) HTTP
3 1 (1.08%) HTTPS
3 1 (1.08%) Intrusion Detection
3 1 (1.08%) Kerberos
3 1 (1.08%) TCP/IP
3 1 (1.08%) Wi-Fi
Database & Business Intelligence
1 3 (3.23%) SQL Server
2 1 (1.08%) Amazon RDS
2 1 (1.08%) Data Lake
2 1 (1.08%) DynamoDB
2 1 (1.08%) MySQL
Development Applications
1 12 (12.90%) SonarQube
2 10 (10.75%) GitLab
3 9 (9.68%) Jenkins
4 4 (4.30%) JIRA
5 3 (3.23%) Snyk
6 1 (1.08%) Burp Suite
6 1 (1.08%) Selenium
General
1 43 (46.24%) Finance
2 12 (12.90%) Financial Institution
3 11 (11.83%) Social Skills
4 10 (10.75%) Banking
5 7 (7.53%) Public Sector
6 5 (5.38%) Documentation Skills
7 3 (3.23%) Retail
8 1 (1.08%) Health Technology
8 1 (1.08%) Telecoms
Job Titles
1 30 (32.26%) Project Manager
2 27 (29.03%) Security Manager
2 27 (29.03%) Security Project Manager
3 15 (16.13%) Security Engineer
4 12 (12.90%) Consultant
4 12 (12.90%) IT Manager
4 12 (12.90%) IT Project Manager
4 12 (12.90%) IT Security Manager
4 12 (12.90%) IT Security Project Manager
5 11 (11.83%) Cybersecurity Manager
5 11 (11.83%) Project Manager - Cybersecurity
5 11 (11.83%) Security Consultant
6 10 (10.75%) Contracts Manager
6 10 (10.75%) IT Services Manager
6 10 (10.75%) Service Security Manager
7 9 (9.68%) CISSP Manager
8 8 (8.60%) Senior
9 6 (6.45%) Vulnerability Management Manager
9 6 (6.45%) Vulnerability Management Project Manager
9 6 (6.45%) Vulnerability Manager
Libraries, Frameworks & Software Standards
1 10 (10.75%) ARM Templates
1 10 (10.75%) Azure Blueprints
2 3 (3.23%) GraphQL
2 3 (3.23%) Java EE
2 3 (3.23%) REST
2 3 (3.23%) SOAP
2 3 (3.23%) Spring
2 3 (3.23%) Spring Boot
3 2 (2.15%) Kafka
4 1 (1.08%) AWS CDK
4 1 (1.08%) JSON
4 1 (1.08%) RESTful
4 1 (1.08%) YAML
Miscellaneous
1 24 (25.81%) Management Information System
2 11 (11.83%) Onboarding
3 6 (6.45%) Security Posture
4 4 (4.30%) Cyber Threat
4 4 (4.30%) PKI
5 3 (3.23%) Foreign Exchange (FX)
5 3 (3.23%) PMI
5 3 (3.23%) Public Cloud
6 2 (2.15%) Cloud Native
6 2 (2.15%) Cyber Kill Chain
7 1 (1.08%) Cyber Security Posture
7 1 (1.08%) Cyberattack
7 1 (1.08%) Data Protection Act
7 1 (1.08%) IoT
Operating Systems
1 8 (8.60%) Windows
2 6 (6.45%) Linux
3 3 (3.23%) Windows Server
4 2 (2.15%) Unix
4 2 (2.15%) zOS
Processes & Methodologies
1 80 (86.02%) Dynamic Application Security Testing
2 41 (44.09%) Cybersecurity
3 37 (39.78%) Application Security
3 37 (39.78%) Security Testing
4 35 (37.63%) DevOps
4 35 (37.63%) Vulnerability Management
5 32 (34.41%) Project Management
6 28 (30.11%) DevSecOps
7 25 (26.88%) CI/CD
8 21 (22.58%) Test Automation
8 21 (22.58%) Threat Modelling
9 17 (18.28%) Project Delivery
10 16 (17.20%) Agile
11 15 (16.13%) Information Security
11 15 (16.13%) SDLC
11 15 (16.13%) Software Engineering
12 14 (15.05%) Containerisation
13 13 (13.98%) Security Operations
14 12 (12.90%) Deployment Automation
14 12 (12.90%) Enterprise Architecture
Programming Languages
1 6 (6.45%) Java
2 5 (5.38%) PowerShell
3 4 (4.30%) Bash
3 4 (4.30%) C#
3 4 (4.30%) Python
4 3 (3.23%) SQL
5 2 (2.15%) Bicep
5 2 (2.15%) C++
6 1 (1.08%) Perl
Qualifications
1 19 (20.43%) CISSP
2 17 (18.28%) CISM
3 15 (16.13%) SC Cleared
3 15 (16.13%) Security Cleared
4 13 (13.98%) CISA
5 11 (11.83%) BPSS Clearance
6 4 (4.30%) CRISC
6 4 (4.30%) Degree
7 3 (3.23%) ITIL Certification
7 3 (3.23%) MCSE
7 3 (3.23%) Microsoft Certification
7 3 (3.23%) PMI Certification
8 2 (2.15%) Cisco Certification
9 1 (1.08%) AWS Certification
9 1 (1.08%) CCNP
9 1 (1.08%) CEH
9 1 (1.08%) GCIA
9 1 (1.08%) GCIH
9 1 (1.08%) GIAC
9 1 (1.08%) GSEC
Quality Assurance & Compliance
1 10 (10.75%) NCSC
2 8 (8.60%) NIST
3 6 (6.45%) ISO/IEC 27001
4 2 (2.15%) Disclosure Scotland
4 2 (2.15%) GDPR
4 2 (2.15%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
4 2 (2.15%) PCI DSS
5 1 (1.08%) HIPAA
5 1 (1.08%) ISO 31000
5 1 (1.08%) NIST 800
5 1 (1.08%) QA
System Software
1 15 (16.13%) Docker
2 5 (5.38%) Hyper-V
2 5 (5.38%) Virtual Machines
3 3 (3.23%) Active Directory
Systems Management
1 24 (25.81%) Terraform
2 23 (24.73%) Kubernetes
3 15 (16.13%) Ansible
4 3 (3.23%) SCCM
5 2 (2.15%) Argo
6 1 (1.08%) Nessus
6 1 (1.08%) Single Sign-On
6 1 (1.08%) Trend Micro Deep Security
Vendors
1 5 (5.38%) Microsoft
2 4 (4.30%) VMware
3 3 (3.23%) Qualys
3 3 (3.23%) Splunk
4 2 (2.15%) Checkmarx
4 2 (2.15%) F5
4 2 (2.15%) Veracode
5 1 (1.08%) ArcSight
5 1 (1.08%) Atlassian
5 1 (1.08%) CyberArk
5 1 (1.08%) Okta
5 1 (1.08%) Red Hat
5 1 (1.08%) SAP
5 1 (1.08%) Trend Micro