Application Security (AppSec)
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Application Security skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Application Security over the 6 months to 9 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
9 May 2024
Same period 2023 Same period 2022
Rank 501 465 553
Rank change year-on-year -36 +88 -58
Permanent jobs citing Application Security 447 641 923
As % of all permanent jobs advertised in the UK 0.45% 0.63% 0.59%
As % of the Processes & Methodologies category 0.53% 0.66% 0.61%
Number of salaries quoted 301 382 530
10th Percentile £47,750 £37,500 £37,500
25th Percentile £56,250 £55,313 £50,313
Median annual salary (50th Percentile) £75,000 £77,500 £72,500
Median % change year-on-year -3.23% +6.90% +11.54%
75th Percentile £87,500 £93,750 £87,500
90th Percentile £105,000 £111,250 £110,000
UK excluding London median annual salary £65,000 £60,000 £55,000
% change year-on-year +8.33% +9.09% -8.33%

All Process and Methodology Skills
UK

Application Security is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 84,809 96,894 150,102
As % of all permanent jobs advertised in the UK 85.57% 95.61% 95.67%
Number of salaries quoted 59,843 56,945 82,179
10th Percentile £29,000 £34,000 £33,500
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,180 £60,000
Median % change year-on-year -10.10% +1.97% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,550
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +9.38%

Application Security
Job Vacancy Trend

Job postings citing Application Security as a proportion of all IT jobs advertised.

Job vacancy trend for Application Security in the UK

Application Security
Salary Trend

3-month moving average salary quoted in jobs citing Application Security.

Salary trend for Application Security in the UK

Application Security
Salary Histogram

Salary distribution for jobs citing Application Security over the 6 months to 9 May 2024.

Salary histogram for Application Security in the UK

Application Security
Top 16 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Application Security within the UK over the 6 months to 9 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -6 401 £75,000 -6.25% 95
London +42 230 £75,000 -14.29% 51
Work from Home +13 200 £72,500 -3.33% 62
UK excluding London -74 183 £65,000 +8.33% 38
North of England +36 66 £67,500 +12.50% 10
South East -28 57 £72,500 +31.82% 13
North West -4 38 £61,206 -5.84% 5
Midlands -18 23 £57,500 -4.17% 5
West Midlands +7 22 £57,500 -13.53% 5
South West -11 20 £75,000 -33.33% 5
Yorkshire +84 19 £79,842 +22.83% 4
Scotland -58 16 £50,000 +9.29% 1
North East +2 9 £62,500 +31.58% 1
Wales +5 2 £65,000 +74.98% 1
East of England -15 1 £60,000 -25.00% 5
East Midlands -19 1 £65,000 +18.18%

Application Security
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 12 (2.68%) SharePoint
2 10 (2.24%) Microsoft Exchange
3 2 (0.45%) Confluence
3 2 (0.45%) IIS
4 1 (0.22%) Apache
4 1 (0.22%) Blackberry Enterprise Server
4 1 (0.22%) Drupal
4 1 (0.22%) nginx
Applications
1 9 (2.01%) Microsoft Office
2 6 (1.34%) Microsoft Excel
Business Applications
1 2 (0.45%) SAP GRC
1 2 (0.45%) SAP S/4HANA
Cloud Services
1 159 (35.57%) Azure
2 112 (25.06%) AWS
3 55 (12.30%) Microsoft 365
4 24 (5.37%) Cloud Computing
5 23 (5.15%) GCP
5 23 (5.15%) SaaS
6 21 (4.70%) Entra ID
7 18 (4.03%) PaaS
8 17 (3.80%) IaaS
9 16 (3.58%) Azure AKS
10 14 (3.13%) Power Platform
11 13 (2.91%) Azure DevOps
12 10 (2.24%) Serverless
13 8 (1.79%) Azure Sentinel
14 6 (1.34%) Azure Service Bus
14 6 (1.34%) Azure Service Fabric
15 4 (0.89%) Azure App Service
15 4 (0.89%) PowerApps
16 3 (0.67%) AWS CodePipeline
16 3 (0.67%) Azure Functions
Communications & Networking
1 103 (23.04%) Firewall
2 77 (17.23%) WAN
3 66 (14.77%) Network Security
4 50 (11.19%) VPN
5 43 (9.62%) Internet
6 42 (9.40%) LAN
7 33 (7.38%) SD-WAN
8 16 (3.58%) Wireless
9 14 (3.13%) Intrusion Detection
10 8 (1.79%) TCP/IP
10 8 (1.79%) Wireshark
11 5 (1.12%) HTTP
12 4 (0.89%) BGP
12 4 (0.89%) Ethernet VPN
12 4 (0.89%) F5 BIG-IP GTM
12 4 (0.89%) F5 BIG-IP LTM
12 4 (0.89%) MPLS
12 4 (0.89%) OSPF
12 4 (0.89%) tcpdump
12 4 (0.89%) Unified Communications
Database & Business Intelligence
1 16 (3.58%) SQL Server
2 10 (2.24%) Relational Database
3 9 (2.01%) Azure SQL Database
4 8 (1.79%) CockroachDB
5 7 (1.57%) NoSQL
5 7 (1.57%) SQL Server Integration Services
5 7 (1.57%) SQL Server Reporting Services
6 4 (0.89%) RDBMS
7 3 (0.67%) Amazon RDS
7 3 (0.67%) Data Lake
7 3 (0.67%) Looker
8 2 (0.45%) Elasticsearch
8 2 (0.45%) MySQL
9 1 (0.22%) Big Data
9 1 (0.22%) Geospatial Data
9 1 (0.22%) PostgreSQL
9 1 (0.22%) Power BI
Development Applications
1 40 (8.95%) Burp Suite
2 35 (7.83%) Metasploit
3 12 (2.68%) Jenkins
4 9 (2.01%) Git
4 9 (2.01%) Sonatype Nexus
5 8 (1.79%) Jaeger
6 6 (1.34%) Selenium
7 5 (1.12%) SoapUI
8 4 (0.89%) Cypress.io
9 3 (0.67%) Moq
9 3 (0.67%) Postman
9 3 (0.67%) SpecFlow
9 3 (0.67%) Visual Studio
10 2 (0.45%) Bitbucket
10 2 (0.45%) JIRA
10 2 (0.45%) WebDriver
11 1 (0.22%) Gradle
11 1 (0.22%) Grunt
11 1 (0.22%) gulp
11 1 (0.22%) Robot Framework
General
1 140 (31.32%) Social Skills
2 102 (22.82%) Finance
3 61 (13.65%) Analytical Skills
4 51 (11.41%) Retail
5 35 (7.83%) Inclusion and Diversity
6 34 (7.61%) Law
7 20 (4.47%) Banking
8 19 (4.25%) Telecoms
9 18 (4.03%) Marketing
10 15 (3.36%) Public Sector
11 14 (3.13%) Legal
12 12 (2.68%) Financial Institution
12 12 (2.68%) Health Technology
13 10 (2.24%) Documentation Skills
13 10 (2.24%) Tech for Good
14 8 (1.79%) Presentation Skills
15 6 (1.34%) Manufacturing
16 5 (1.12%) Influencing Skills
17 2 (0.45%) Investment Banking
17 2 (0.45%) Local Government
Job Titles
1 153 (34.23%) Architect
2 119 (26.62%) Senior
3 89 (19.91%) Security Architect
4 50 (11.19%) Lead
5 46 (10.29%) Penetration Tester
6 45 (10.07%) Analyst
6 45 (10.07%) Tester
7 44 (9.84%) Security Analyst
8 42 (9.40%) Lead Architect
9 39 (8.72%) Security Engineer
10 31 (6.94%) Lead Security Architect
11 25 (5.59%) Consultant
12 24 (5.37%) Senior Analyst
13 23 (5.15%) Senior Security Analyst
14 22 (4.92%) Infrastructure Architect
15 21 (4.70%) Developer
16 20 (4.47%) Senior Architect
17 19 (4.25%) CISSP Analyst
18 16 (3.58%) Cybersecurity Analyst
18 16 (3.58%) IT Analyst
Libraries, Frameworks & Software Standards
1 24 (5.37%) OAuth
2 18 (4.03%) Web Services
3 16 (3.58%) REST
4 14 (3.13%) .NET
4 14 (3.13%) SAML
5 13 (2.91%) HTML
6 12 (2.68%) Middleware
6 12 (2.68%) React
6 12 (2.68%) RESTful
7 11 (2.46%) SailPoint
8 10 (2.24%) CSS
9 9 (2.01%) .NET Framework
9 9 (2.01%) Entity Framework
9 9 (2.01%) Kafka
9 9 (2.01%) Vue
10 8 (1.79%) OAuth2
10 8 (1.79%) OpenTelemetry
10 8 (1.79%) Spring Boot
11 7 (1.57%) HTML5
11 7 (1.57%) web3js
Miscellaneous
1 80 (17.90%) Management Information System
2 50 (11.19%) Distributed Denial-of-Service
3 25 (5.59%) Security Posture
4 22 (4.92%) PKI
5 20 (4.47%) Public Cloud
6 19 (4.25%) Self-Motivation
7 16 (3.58%) Cyber Threat
8 14 (3.13%) Data Centre
8 14 (3.13%) Distributed Systems
8 14 (3.13%) Greenfield Project
9 13 (2.91%) Cloud Native
10 12 (2.68%) Mobile App
10 12 (2.68%) Replication
11 10 (2.24%) Product Ownership
11 10 (2.24%) Robotics
12 8 (1.79%) Hybrid Cloud
13 7 (1.57%) Blockchain
13 7 (1.57%) Web3
14 4 (0.89%) IoT
15 3 (0.67%) Data Structures
Operating Systems
1 84 (18.79%) Linux
2 68 (15.21%) Windows
3 35 (7.83%) Ubuntu
3 35 (7.83%) VMS
4 33 (7.38%) Kali Linux
5 19 (4.25%) Windows Server
6 8 (1.79%) Android
6 8 (1.79%) Apple iOS
7 2 (0.45%) Unix
7 2 (0.45%) Windows 10
8 1 (0.22%) Red Hat Enterprise Linux
8 1 (0.22%) Windows Server 2019
Processes & Methodologies
1 179 (40.04%) Cybersecurity
2 144 (32.21%) Information Security
3 107 (23.94%) OWASP
4 100 (22.37%) DevSecOps
5 97 (21.70%) Penetration Testing
6 93 (20.81%) Problem-Solving
7 89 (19.91%) Computer Science
8 85 (19.02%) Security Architecture
9 84 (18.79%) Cloud Security
10 82 (18.34%) CI/CD
11 67 (14.99%) Agile
12 65 (14.54%) Security Testing
13 63 (14.09%) DevOps
14 60 (13.42%) SIEM
15 58 (12.98%) Vulnerability Management
16 57 (12.75%) Secure Coding
17 54 (12.08%) Identity Access Management
17 54 (12.08%) Security Operations
18 47 (10.51%) Threat Modelling
19 46 (10.29%) Identity Management
Programming Languages
1 51 (11.41%) SQL
2 37 (8.28%) Python
3 28 (6.26%) JavaScript
3 28 (6.26%) PowerShell
4 27 (6.04%) Java
5 16 (3.58%) C#
6 10 (2.24%) Kusto Query Language
7 9 (2.01%) TypeScript
8 8 (1.79%) Go
8 8 (1.79%) R
9 7 (1.57%) C
9 7 (1.57%) T-SQL
10 5 (1.12%) Scala
11 4 (0.89%) Bash
12 3 (0.67%) C++
12 3 (0.67%) PHP
12 3 (0.67%) Ruby
13 2 (0.45%) Kotlin
13 2 (0.45%) Lua
13 2 (0.45%) Objective-C
Qualifications
1 133 (29.75%) CISSP
2 119 (26.62%) Degree
3 81 (18.12%) CISM
4 60 (13.42%) Cisco Certification
5 59 (13.20%) Computer Science Degree
6 57 (12.75%) Security Cleared
7 56 (12.53%) (ISC)2 CCSP
8 55 (12.30%) CCSP
9 49 (10.96%) Azure Certification
10 45 (10.07%) AWS Certification
11 41 (9.17%) DV Cleared
12 33 (7.38%) CCSK
13 19 (4.25%) OSCP
14 18 (4.03%) AWS Certified Cloud Practitioner
14 18 (4.03%) CREST Certified
15 17 (3.80%) GIAC
15 17 (3.80%) SANS
15 17 (3.80%) SC Cleared
16 14 (3.13%) CompTIA Security+
16 14 (3.13%) PCI QSA
Quality Assurance & Compliance
1 100 (22.37%) NIST
2 41 (9.17%) ISO/IEC 27001
3 24 (5.37%) GRC
3 24 (5.37%) PCI DSS
4 19 (4.25%) SOC 2
5 18 (4.03%) GDPR
6 13 (2.91%) Cyber Essentials
7 12 (2.68%) COBIT
8 9 (2.01%) NCSC
8 9 (2.01%) NIST 800
9 6 (1.34%) Accessibility
9 6 (1.34%) Actionable Recommendations
9 6 (1.34%) Web Application Security Consortium
10 5 (1.12%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
10 5 (1.12%) QA
10 5 (1.12%) SLA
11 4 (0.89%) Cyber Essentials PLUS
11 4 (0.89%) WCAG
12 3 (0.67%) HIPAA
12 3 (0.67%) ISO 31000
System Software
1 62 (13.87%) Active Directory
2 60 (13.42%) Docker
3 13 (2.91%) VMware Infrastructure
4 9 (2.01%) Hyper-V
5 4 (0.89%) Microsoft Virtual Server
5 4 (0.89%) Virtual Servers
6 3 (0.67%) VMware ESXi
7 2 (0.45%) Virtual Machines
8 1 (0.22%) vSphere
Systems Management
1 85 (19.02%) Kubernetes
2 57 (12.75%) Terraform
3 47 (10.51%) Ansible
4 46 (10.29%) Single Sign-On
5 12 (2.68%) Computer Emergency Response Teams
6 8 (1.79%) Kiali
6 8 (1.79%) Microsoft Intune
6 8 (1.79%) Nessus
7 7 (1.57%) Nmap
8 5 (1.12%) Suricata
9 4 (0.89%) CSIRT
10 3 (0.67%) HP Fortify
10 3 (0.67%) QRadar
10 3 (0.67%) vCenter Server
11 1 (0.22%) CASB
11 1 (0.22%) WMI
11 1 (0.22%) WSUS
Vendors
1 97 (21.70%) Microsoft
2 18 (4.03%) Splunk
3 14 (3.13%) VMware
4 13 (2.91%) CyberArk
5 11 (2.46%) BeyondTrust
5 11 (2.46%) ServiceNow
6 10 (2.24%) Qualys
7 8 (1.79%) AppDynamics
7 8 (1.79%) Juniper
8 7 (1.57%) Cisco
9 5 (1.12%) F5
9 5 (1.12%) Palo Alto
10 4 (0.89%) OpenAI
11 3 (0.67%) Google
11 3 (0.67%) IBM
11 3 (0.67%) Oracle
11 3 (0.67%) SAP
11 3 (0.67%) Veracode
12 2 (0.45%) Aruba
12 2 (0.45%) Darktrace