Threat Modelling
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Threat Modelling skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Threat Modelling over the 6 months to 27 April 2024 with a comparison to the same period in the previous 2 years.

6 months to
27 Apr 2024
Same period 2023 Same period 2022
Rank 762 502 743
Rank change year-on-year -260 +241 +3
Permanent jobs citing Threat Modelling 134 580 532
As % of all permanent jobs advertised in the UK 0.14% 0.55% 0.35%
As % of the Processes & Methodologies category 0.16% 0.58% 0.36%
Number of salaries quoted 97 321 270
10th Percentile £46,825 £43,750 £51,250
25th Percentile £56,875 £56,250 £60,000
Median annual salary (50th Percentile) £75,000 £75,000 £75,000
75th Percentile £83,750 £97,500 £90,000
90th Percentile £104,250 £111,250 £100,125
UK excluding London median annual salary £50,000 £68,257 £60,000
% change year-on-year -26.75% +13.76% -7.69%

All Process and Methodology Skills
UK

Threat Modelling is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 84,305 100,095 147,310
As % of all permanent jobs advertised in the UK 85.99% 95.64% 95.57%
Number of salaries quoted 59,591 58,745 83,129
10th Percentile £29,000 £34,000 £33,500
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £62,000 £60,000
Median % change year-on-year -11.29% +3.33% +9.09%
75th Percentile £72,500 £82,500 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +9.38%

Threat Modelling
Job Vacancy Trend

Job postings citing Threat Modelling as a proportion of all IT jobs advertised.

Job vacancy trend for Threat Modelling in the UK

Threat Modelling
Salary Trend

3-month moving average salary quoted in jobs citing Threat Modelling.

Salary trend for Threat Modelling in the UK

Threat Modelling
Salary Histogram

Salary distribution for jobs citing Threat Modelling over the 6 months to 27 April 2024.

Salary histogram for Threat Modelling in the UK

Threat Modelling
Top 13 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Threat Modelling within the UK over the 6 months to 27 April 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -224 95 £70,000 -12.50% 63
UK excluding London -157 65 £50,000 -26.75% 33
Work from Home -83 39 £82,500 +20.41% 29
London -97 36 £97,500 +14.71% 29
North of England -10 26 £50,000 -27.02% 7
North West -18 19 £45,000 -29.13% 3
South West -1 14 £72,500 +21.80% 7
South East -36 11 £59,000 -34.44% 8
Yorkshire +62 7 £50,000 -28.00% 4
West Midlands +16 7 £70,000 -4.11% 5
Midlands -5 7 £70,000 -4.11% 5
Scotland -93 6 - - 3
East of England +12 1 - - 3

Threat Modelling
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Applications
1 10 (7.46%) Microsoft Office
2 9 (6.72%) Microsoft Excel
Cloud Services
1 78 (58.21%) Azure
2 72 (53.73%) AWS
3 30 (22.39%) GCP
4 16 (11.94%) Microsoft 365
5 12 (8.96%) Power Platform
6 10 (7.46%) Serverless
7 8 (5.97%) PaaS
8 6 (4.48%) Azure Service Fabric
8 6 (4.48%) Cloud Computing
8 6 (4.48%) Entra ID
8 6 (4.48%) IaaS
8 6 (4.48%) SaaS
9 5 (3.73%) AWS CloudFormation
10 4 (2.99%) Amazon CloudWatch
10 4 (2.99%) Amazon EC2
10 4 (2.99%) Amazon GuardDuty
10 4 (2.99%) Amazon S3
10 4 (2.99%) AWS CloudTrail
10 4 (2.99%) AWS Lambda
10 4 (2.99%) Virtual Private Cloud
Communications & Networking
1 21 (15.67%) Firewall
2 18 (13.43%) LAN
3 14 (10.45%) DNS
4 9 (6.72%) Intrusion Detection
5 7 (5.22%) Network Security
6 6 (4.48%) HTTP
7 4 (2.99%) SMTP
7 4 (2.99%) SSL
8 3 (2.24%) Internet
8 3 (2.24%) VPN
8 3 (2.24%) Wireless
9 2 (1.49%) 802.11
9 2 (1.49%) Bluetooth
9 2 (1.49%) IPv4
9 2 (1.49%) ZigBee
10 1 (0.75%) SD-WAN
10 1 (0.75%) TCP/IP
10 1 (0.75%) WAN
Database & Business Intelligence
1 9 (6.72%) Power BI
2 6 (4.48%) Azure SQL Database
3 4 (2.99%) Amazon RDS
4 3 (2.24%) Data Lake
5 2 (1.49%) Big Data
Development Applications
1 17 (12.69%) Jenkins
2 5 (3.73%) Burp Suite
2 5 (3.73%) Metasploit
3 2 (1.49%) Bitbucket
3 2 (1.49%) sqlmap
4 1 (0.75%) CircleCI
4 1 (0.75%) GitLab
4 1 (0.75%) Snyk
General
1 44 (32.84%) Social Skills
2 31 (23.13%) Finance
3 18 (13.43%) Presentation Skills
3 18 (13.43%) Public Sector
4 13 (9.70%) Inclusion and Diversity
4 13 (9.70%) Law
4 13 (9.70%) Retail
5 12 (8.96%) Banking
6 9 (6.72%) Marketing
7 7 (5.22%) Analytical Skills
8 5 (3.73%) Manufacturing
9 4 (2.99%) Investment Banking
10 3 (2.24%) Legal
11 2 (1.49%) Cyber-Physical System
11 2 (1.49%) Financial Institution
11 2 (1.49%) Influencing Skills
11 2 (1.49%) Organisational Skills
12 1 (0.75%) Automotive
12 1 (0.75%) Pharmaceutical
12 1 (0.75%) Telecoms
Job Titles
1 47 (35.07%) Architect
2 40 (29.85%) Security Architect
3 39 (29.10%) Senior
4 24 (17.91%) Cybersecurity Architect
5 21 (15.67%) Security Engineer
6 16 (11.94%) Lead
7 15 (11.19%) Senior Architect
8 13 (9.70%) Consultant
8 13 (9.70%) Security Consultant
8 13 (9.70%) Security Technical Architect
8 13 (9.70%) Technical Architect
9 9 (6.72%) Senior Security Architect
10 8 (5.97%) Cybersecurity Engineer
10 8 (5.97%) Information Architect
10 8 (5.97%) Information Security Architect
11 7 (5.22%) AWS Engineer
11 7 (5.22%) Senior Consultant
11 7 (5.22%) Senior Security Consultant
11 7 (5.22%) Senior Security Engineer
12 6 (4.48%) Lead Architect
Libraries, Frameworks & Software Standards
1 12 (8.96%) OAuth
2 9 (6.72%) Web Services
3 6 (4.48%) REST
3 6 (4.48%) SAML
3 6 (4.48%) SOAP
4 4 (2.99%) JWT
5 3 (2.24%) HTML
6 2 (1.49%) 802.1X
6 2 (1.49%) HTML5
6 2 (1.49%) Middleware
6 2 (1.49%) OAuth2
6 2 (1.49%) OpenID
6 2 (1.49%) WebSockets
7 1 (0.75%) AWS CDK
Miscellaneous
1 37 (27.61%) Cyberattack
2 27 (20.15%) Management Information System
3 26 (19.40%) Cyber Threat
4 21 (15.67%) Data Centre
5 18 (13.43%) PKI
6 17 (12.69%) Onboarding
7 15 (11.19%) Security Posture
8 13 (9.70%) iPhone
9 8 (5.97%) Public Cloud
10 7 (5.22%) IoT
11 6 (4.48%) Distributed Systems
11 6 (4.48%) Hybrid Cloud
12 4 (2.99%) Mobile App
13 3 (2.24%) Cloud Native
13 3 (2.24%) SCADA
13 3 (2.24%) Self-Motivation
14 2 (1.49%) PropTech
14 2 (1.49%) Renewable Energy
14 2 (1.49%) Robotics
14 2 (1.49%) Security Operations Centre
Operating Systems
1 17 (12.69%) Windows
2 7 (5.22%) Android
2 7 (5.22%) Apple iOS
3 6 (4.48%) Kali Linux
4 1 (0.75%) Linux
4 1 (0.75%) Red Hat Enterprise Linux
4 1 (0.75%) Windows Server
Processes & Methodologies
1 93 (69.40%) Cybersecurity
2 58 (43.28%) Information Security
3 43 (32.09%) Application Security
4 35 (26.12%) Incident Response
4 35 (26.12%) Vulnerability Management
5 34 (25.37%) Security Architecture
6 31 (23.13%) Penetration Testing
7 28 (20.90%) Threat Management
8 24 (17.91%) Identity Access Management
8 24 (17.91%) Threat Intelligence
9 23 (17.16%) Cyber Threat Intelligence
10 22 (16.42%) OWASP
10 22 (16.42%) Problem-Solving
10 22 (16.42%) Roadmaps
10 22 (16.42%) SDLC
10 22 (16.42%) Secure Coding
10 22 (16.42%) Stakeholder Management
11 21 (15.67%) Cyber Assurance
11 21 (15.67%) MITRE ATT&CK
12 20 (14.93%) Cloud Security
Programming Languages
1 28 (20.90%) Python
2 11 (8.21%) Go
2 11 (8.21%) Java
3 6 (4.48%) C#
3 6 (4.48%) JavaScript
3 6 (4.48%) SQL
4 4 (2.99%) Lua
4 4 (2.99%) Ruby
4 4 (2.99%) Rust
5 3 (2.24%) PowerShell
6 2 (1.49%) Dart
6 2 (1.49%) Kotlin
6 2 (1.49%) Objective-C
6 2 (1.49%) PHP
6 2 (1.49%) Swift
7 1 (0.75%) C++
Qualifications
1 72 (53.73%) CISSP
2 55 (41.04%) CISM
3 36 (26.87%) GIAC
4 34 (25.37%) AWS Certification
5 27 (20.15%) OSCP
6 25 (18.66%) Security Cleared
7 24 (17.91%) SC Cleared
8 23 (17.16%) CREST Certified
8 23 (17.16%) Degree
9 21 (15.67%) Azure Certification
10 18 (13.43%) CRISC
11 14 (10.45%) ISSMP
12 13 (9.70%) BPSS Clearance
13 10 (7.46%) CISA
14 9 (6.72%) Computer Science Degree
15 8 (5.97%) CEH
15 8 (5.97%) Master's Degree
16 7 (5.22%) (ISC)2 CCSP
16 7 (5.22%) Cisco Certification
16 7 (5.22%) SANS
Quality Assurance & Compliance
1 33 (24.63%) NIST
2 23 (17.16%) ISO/IEC 27001
3 20 (14.93%) COBIT
4 10 (7.46%) PCI DSS
5 7 (5.22%) Cyber Essentials
5 7 (5.22%) QA
5 7 (5.22%) SOC 2
6 6 (4.48%) Web Application Security Consortium
7 5 (3.73%) Cyber Essentials PLUS
7 5 (3.73%) IASME
8 4 (2.99%) GDPR
8 4 (2.99%) NCSC
8 4 (2.99%) NIST 800
9 3 (2.24%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
10 2 (1.49%) HIPAA
10 2 (1.49%) ISO 31000
11 1 (0.75%) GRC
11 1 (0.75%) IEC 61508
System Software
1 21 (15.67%) Active Directory
2 4 (2.99%) Docker
2 4 (2.99%) Virtual Machines
Systems Management
1 18 (13.43%) Kubernetes
2 14 (10.45%) Ansible
3 9 (6.72%) Nessus
4 7 (5.22%) Computer Emergency Response Teams
5 4 (2.99%) Single Sign-On
6 3 (2.24%) HP Fortify
6 3 (2.24%) Nmap
6 3 (2.24%) Suricata
7 2 (1.49%) QRadar
7 2 (1.49%) Terraform
8 1 (0.75%) Anchore
8 1 (0.75%) Computer Incident Response Team
Vendors
1 22 (16.42%) Microsoft
2 14 (10.45%) Alibaba
3 11 (8.21%) Google
4 8 (5.97%) Splunk
5 4 (2.99%) Palo Alto
6 3 (2.24%) Cisco
6 3 (2.24%) Juniper
6 3 (2.24%) Qualys
6 3 (2.24%) Veracode
7 2 (1.49%) Fortinet
7 2 (1.49%) IBM
8 1 (0.75%) Forcepoint
8 1 (0.75%) Intel
8 1 (0.75%) Netskope
8 1 (0.75%) Okta
8 1 (0.75%) Red Hat