Period
to 23 January 2018

The median annual salary for a Penetration Tester was £70,000 in advertised job vacancies in England during the 6 months to 23 January 2018.

The first table below provides salary benchmarking and summary statistics including a comparison to same period in the previous 2 years.

Penetration Tester
UK > England
6 months to
23 Jan 2018
Same period 2017 Same period 2016
Rank 932 901 1056
Rank change year-on-year -31 +155 +17
Permanent jobs requiring a Penetration Tester 215 245 204
As % of all permanent IT jobs advertised in England 0.13% 0.15% 0.10%
As % of the Job Titles category 0.14% 0.15% 0.11%
Number of salaries quoted 176 184 169
England median annual salary £70,000 £56,250 £60,000
Median salary % change year-on-year +24.44% -6.25% +9.09%
10th Percentile £41,250 £37,575 £26,250
90th Percentile £98,750 £90,000 £95,000
UK median annual salary £70,000 £57,500 £60,000
% change year-on-year +21.74% -4.17% +9.09%

The following table is for comparison with the above and includes summary statistics for all permanent IT job vacancies advertised in England. Most job vacancies include a discernible job title that can be normalized. As such, the figures in the second row provide an indication of the number of permanent jobs in our overall sample.

All Permanent IT Job Vacancies
England
Permanent vacancies in England with a recognized job title 157,043 160,190 188,299
% of permanent IT jobs with a recognized job title 96.08% 96.48% 96.65%
Number of salaries quoted 128,961 134,332 158,959
England median annual salary £50,000 £47,500 £47,500
Median salary % change year-on-year +5.26% - +5.56%
10th Percentile £27,500 £27,500 £26,750
90th Percentile £80,000 £77,500 £76,250
UK median annual salary £50,000 £47,500 £46,000
% change year-on-year +5.26% +3.26% +2.22%

Penetration Tester
Job Vacancy Trend in England

Job postings that featured Penetration Tester in the job title as a percentage of all IT jobs advertised in England.

Job vacancy trend for Penetration Tester in England

Penetration Tester
Salary Trend in England

This chart provides the 3-month moving average for salaries quoted in permanent IT jobs citing Penetration Tester in England.

Salary trend for Penetration Tester in England

Penetration Tester
Salary Histogram in England

The salary distribution of IT jobs citing Penetration Tester in England over the 6 months to 23 January 2018.

Salary histogram for Penetration Tester in England

Penetration Tester
Job Locations in England

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Penetration Tester within the England region over the 6 months to 23 January 2018. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Job
Vacancies
London -1 111 £80,000 +23.08% 22
North of England -12 36 £65,000 +18.18% 5
South East +2 35 £53,750 -6.52% 7
North West +10 23 £71,250 +42.50% 3
Midlands -4 16 £70,000 +36.59% 2
West Midlands -11 16 £70,000 +33.33% 1
Yorkshire -16 13 £51,250 -6.82% 2
East of England +13 6 £52,500 +61.54% 2
South West -4 6 £60,000 +20.00% 3
Penetration Tester
UK

Penetration Tester Skill Set
Top 30 Co-occurring IT Skills in England

For the 6 months to 23 January 2018, Penetration Tester job roles required the following IT skills in order of popularity. The figures indicate the absolute number co-occurrences and as a proportion of all permanent job ads across the England region featuring Penetration Tester in the job title.

1 196 (91.16%) Penetration Testing
2 105 (48.84%) CREST Certified
3 84 (39.07%) Information Security
4 72 (33.49%) OSCP
5 54 (25.12%) Ethical Hacking
5 54 (25.12%) Java
6 53 (24.65%) Cybersecurity
6 53 (24.65%) Android
7 52 (24.19%) Finance
8 50 (23.26%) Wireless
8 50 (23.26%) OWASP
9 48 (22.33%) Apple iOS
10 45 (20.93%) Windows
11 42 (19.53%) Unix
12 41 (19.07%) CHECK Team Leader
13 40 (18.60%) Security Testing
14 39 (18.14%) Python
15 38 (17.67%) SANS
16 35 (16.28%) Linux
17 33 (15.35%) CEH
18 32 (14.88%) Degree
19 31 (14.42%) Vulnerability Assessment
19 31 (14.42%) Firewall
20 30 (13.95%) C
21 28 (13.02%) C++
21 28 (13.02%) CISSP
21 28 (13.02%) Social Engineering
21 28 (13.02%) Security Cleared
22 26 (12.09%) Network Security
23 25 (11.63%) Security Architecture

Penetration Tester Skill Set
Co-occurring IT Skills in England by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same job type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 9 (4.19%) OpenStack
2 3 (1.40%) IIS
Business Applications
1 3 (1.40%) Payment Gateway
Cloud Services
1 9 (4.19%) Amazon AWS
1 9 (4.19%) Microsoft Azure
2 1 (0.47%) SaaS
Communications & Networking
1 50 (23.26%) Wireless
2 31 (14.42%) Firewall
3 26 (12.09%) Network Security
4 19 (8.84%) TCP/IP
5 10 (4.65%) HTTP
6 9 (4.19%) 802.11
6 9 (4.19%) SNMP
6 9 (4.19%) VPN
7 8 (3.72%) Internet
8 6 (2.79%) PPP
9 5 (2.33%) DNS
9 5 (2.33%) LAN
9 5 (2.33%) WAN
9 5 (2.33%) Wireshark
10 4 (1.86%) tcpdump
11 3 (1.40%) Cisco ASA
12 2 (0.93%) VoIP
12 2 (0.93%) Wireless Security
13 1 (0.47%) DHCP
13 1 (0.47%) SMS
Database & Business Intelligence
1 6 (2.79%) SQL Server
2 3 (1.40%) GIS
Development Applications
1 22 (10.23%) Burp Suite
2 18 (8.37%) Metasploit
3 11 (5.12%) AppScan
4 4 (1.86%) Paros
5 2 (0.93%) JIRA
5 2 (0.93%) MSTest
5 2 (0.93%) Team Foundation Server
5 2 (0.93%) WebScarab
6 1 (0.47%) sqlmap
General
1 52 (24.19%) Finance
2 14 (6.51%) Retail
3 10 (4.65%) Telecoms
4 6 (2.79%) Banking
5 4 (1.86%) Financial Institution
6 3 (1.40%) Games
6 3 (1.40%) Legal
6 3 (1.40%) Marketing
7 2 (0.93%) Advertising
7 2 (0.93%) Automotive
7 2 (0.93%) Electronics
7 2 (0.93%) Investment Banking
7 2 (0.93%) Manufacturing
8 1 (0.47%) Aerospace
8 1 (0.47%) Law
8 1 (0.47%) Publishing
Libraries, Frameworks & Software Standards
1 19 (8.84%) .NET
2 11 (5.12%) HTML
3 9 (4.19%) 802.1X
4 7 (3.26%) Web Services
5 6 (2.79%) REST
5 6 (2.79%) XML
6 4 (1.86%) ASP.NET
6 4 (1.86%) Node.js
7 3 (1.40%) ASP.NET Web API
7 3 (1.40%) HTML5
7 3 (1.40%) J2EE
7 3 (1.40%) JNI
7 3 (1.40%) JSON
7 3 (1.40%) RESTful
8 1 (0.47%) CakePHP
8 1 (0.47%) CGI
Miscellaneous
1 18 (8.37%) Virtual Team
2 17 (7.91%) Mobile App
3 13 (6.05%) Computer Science
3 13 (6.05%) Management Information System
4 8 (3.72%) SCADA
5 6 (2.79%) Analytical Skills
6 5 (2.33%) CESG
7 4 (1.86%) Embedded Systems
8 2 (0.93%) Cyber Kill Chain
8 2 (0.93%) Cyberattack
8 2 (0.93%) Data Protection Act
8 2 (0.93%) Fintech
8 2 (0.93%) iPad
9 1 (0.47%) Analytical Mindset
9 1 (0.47%) Blog
9 1 (0.47%) Cyberthreat
9 1 (0.47%) Data Centre
Operating Systems
1 53 (24.65%) Android
2 48 (22.33%) Apple iOS
3 45 (20.93%) Windows
4 42 (19.53%) Unix
5 35 (16.28%) Linux
6 9 (4.19%) Kali Linux
7 2 (0.93%) KNOPPIX
7 2 (0.93%) Mac OS X
7 2 (0.93%) Windows Mobile
Processes & Methodologies
1 196 (91.16%) Penetration Testing
2 84 (39.07%) Information Security
3 54 (25.12%) Ethical Hacking
4 53 (24.65%) Cybersecurity
5 50 (23.26%) OWASP
6 40 (18.60%) Security Testing
7 31 (14.42%) Vulnerability Assessment
8 28 (13.02%) Social Engineering
9 25 (11.63%) Security Architecture
10 24 (11.16%) Collaborative Working
10 24 (11.16%) Time Management
11 21 (9.77%) Threat Modelling
12 20 (9.30%) Stakeholder Management
13 19 (8.84%) Open Source
14 16 (7.44%) Task Automation
15 14 (6.51%) Mentoring
16 13 (6.05%) Reverse Engineering
17 11 (5.12%) Patch Management
18 10 (4.65%) Threat Intelligence
19 8 (3.72%) Cyber Threat Intelligence
Programming Languages
1 54 (25.12%) Java
2 39 (18.14%) Python
3 30 (13.95%) C
4 28 (13.02%) C++
5 23 (10.70%) C#
6 20 (9.30%) PHP
6 20 (9.30%) Ruby
6 20 (9.30%) SQL
7 15 (6.98%) Shell Script
8 12 (5.58%) Bash Shell
8 12 (5.58%) PowerShell
9 9 (4.19%) Lua
9 9 (4.19%) Perl
10 6 (2.79%) VB.NET
11 3 (1.40%) Objective-C
12 2 (0.93%) JavaScript
Qualifications
1 105 (48.84%) CREST Certified
2 72 (33.49%) OSCP
3 41 (19.07%) CHECK Team Leader
4 38 (17.67%) SANS
5 33 (15.35%) CEH
6 32 (14.88%) Degree
7 28 (13.02%) CISSP
7 28 (13.02%) Security Cleared
8 24 (11.16%) CHECK Team Member
9 19 (8.84%) Tigerscheme
10 16 (7.44%) Cyber Scheme
11 14 (6.51%) GPEN
12 11 (5.12%) CISM
13 9 (4.19%) Master's Degree
13 9 (4.19%) OSCE
14 8 (3.72%) CISA
15 7 (3.26%) GIAC
15 7 (3.26%) GXPN
16 6 (2.79%) CSSLP
17 5 (2.33%) SC Cleared
Quality Assurance & Compliance
1 4 (1.86%) PCI DSS
1 4 (1.86%) QA
2 3 (1.40%) GDPR
2 3 (1.40%) ISO/IEC 27001
3 2 (0.93%) Cyber Essentials
3 2 (0.93%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
4 1 (0.47%) Cyber Essentials PLUS
4 1 (0.47%) IASME
System Software
1 6 (2.79%) Active Directory
Systems Management
1 22 (10.23%) Nessus
2 16 (7.44%) Nmap
3 8 (3.72%) WebInspect
4 4 (1.86%) Core Impact
5 2 (0.93%) HP Fortify
5 2 (0.93%) HP Quality Center
5 2 (0.93%) Nexpose
Vendors
1 6 (2.79%) Microsoft
2 5 (2.33%) Citrix
3 4 (1.86%) Splunk
4 3 (1.40%) CheckPoint
4 3 (1.40%) Cisco
5 2 (0.93%) SAP