Penetration Testing
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Penetration Testing skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Penetration Testing over the 6 months to 28 November 2023 with a comparison to the same period in the previous 2 years.

6 months to
28 Nov 2023
Same period 2022 Same period 2021
Rank 406 538 500
Rank change year-on-year +132 -38 -134
Permanent jobs citing Penetration Testing 363 693 757
As % of all permanent jobs advertised in the UK 0.67% 0.55% 0.59%
As % of the Processes & Methodologies category 0.71% 0.58% 0.62%
Number of salaries quoted 319 515 542
10th Percentile £42,500 £40,973 £38,750
25th Percentile £52,113 £53,750 £47,500
Median annual salary (50th Percentile) £62,500 £70,000 £60,000
Median % change year-on-year -10.71% +16.67% +3.45%
75th Percentile £77,500 £85,000 £77,500
90th Percentile £90,000 £100,000 £90,000
UK excluding London median annual salary £58,500 £65,000 £55,000
% change year-on-year -10.00% +18.18% +15.61%

All Process and Methodology Skills
UK

Penetration Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 51,121 120,104 122,523
As % of all permanent jobs advertised in the UK 94.09% 95.72% 95.43%
Number of salaries quoted 36,956 73,203 81,032
10th Percentile £32,500 £34,313 £32,500
25th Percentile £43,750 £45,000 £42,500
Median annual salary (50th Percentile) £60,000 £60,000 £59,000
Median % change year-on-year - +1.69% +7.27%
75th Percentile £80,000 £81,250 £77,500
90th Percentile £98,750 £100,000 £95,000
UK excluding London median annual salary £52,500 £53,000 £50,000
% change year-on-year -0.94% +6.00% +4.17%

Penetration Testing
Job Vacancy Trend

Job postings citing Penetration Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Penetration Testing in the UK

Penetration Testing
Salary Trend

3-month moving average salary quoted in jobs citing Penetration Testing.

Salary trend for Penetration Testing in the UK

Penetration Testing
Salary Histogram

Salary distribution for jobs citing Penetration Testing over the 6 months to 28 November 2023.

Salary histogram for Penetration Testing in the UK

Penetration Testing
Top 17 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 28 November 2023. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England +129 314 £60,000 -14.29% 171
Work from Home +137 194 £64,902 -3.85% 112
UK excluding London +101 177 £58,500 -10.00% 95
London +143 154 £65,000 -13.33% 80
Midlands +111 44 £56,325 -13.35% 14
North of England +68 40 £55,000 -10.20% 25
West Midlands +95 34 £57,500 -11.54% 9
South West +68 31 £50,950 -27.21% 19
South East +99 29 £59,250 -10.57% 20
North West +83 27 £50,000 -21.57% 15
East of England +120 15 £65,500 +0.77% 9
Scotland +33 12 £70,000 +7.69% 3
Yorkshire +63 11 £55,000 -4.35% 10
East Midlands +53 10 £45,560 -39.89% 5
Northern Ireland +38 3 £80,000 +23.08% 3
Wales +4 3 £60,000 +41.18% 3
North East +38 2 £75,000 +38.25%

Penetration Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 8 (2.20%) SharePoint
2 1 (0.28%) Apache
2 1 (0.28%) Drupal
2 1 (0.28%) MS Exchange
2 1 (0.28%) nginx
2 1 (0.28%) WordPress
Applications
1 4 (1.10%) Microsoft Office
2 1 (0.28%) Microsoft Excel
2 1 (0.28%) Microsoft PowerPoint
Business Applications
1 2 (0.55%) Dynamics CRM
2 1 (0.28%) Magento
2 1 (0.28%) Payment Gateway
Cloud Services
1 82 (22.59%) Azure
2 53 (14.60%) AWS
3 43 (11.85%) Microsoft 365
4 19 (5.23%) Entra ID
5 16 (4.41%) SaaS
6 15 (4.13%) Cloud Computing
6 15 (4.13%) PaaS
7 12 (3.31%) GCP
8 11 (3.03%) IaaS
9 10 (2.75%) Azure Sentinel
10 9 (2.48%) Azure DevOps
11 7 (1.93%) WhatsApp
12 6 (1.65%) Microsoft Purview
12 6 (1.65%) Mimecast
13 5 (1.38%) Power Automate
14 4 (1.10%) AWS Control Tower
14 4 (1.10%) Azure ExpressRoute
14 4 (1.10%) GitHub
15 3 (0.83%) Amazon GuardDuty
15 3 (0.83%) AWS CloudTrail
Communications & Networking
1 122 (33.61%) Firewall
2 75 (20.66%) Network Security
3 44 (12.12%) Intrusion Detection
4 22 (6.06%) VPN
5 17 (4.68%) LAN
5 17 (4.68%) Wireshark
6 16 (4.41%) Wireless
7 15 (4.13%) TCP/IP
8 14 (3.86%) Wi-Fi
9 12 (3.31%) WAN
10 11 (3.03%) Internet
11 9 (2.48%) Cisco Nexus
12 8 (2.20%) DHCP
12 8 (2.20%) DNS
12 8 (2.20%) VLAN
12 8 (2.20%) VoIP
13 7 (1.93%) SAN
13 7 (1.93%) SSL
14 6 (1.65%) BGP
14 6 (1.65%) EIGRP
Database & Business Intelligence
1 7 (1.93%) SQL Server
2 6 (1.65%) Amazon RDS
3 4 (1.10%) MySQL
3 4 (1.10%) PostgreSQL
4 1 (0.28%) NoSQL
Development Applications
1 12 (3.31%) Burp Suite
2 8 (2.20%) Metasploit
3 7 (1.93%) Jenkins
4 4 (1.10%) sqlmap
5 3 (0.83%) CircleCI
6 2 (0.55%) GitLab
6 2 (0.55%) Selenium
6 2 (0.55%) SoapUI
7 1 (0.28%) Bitbucket
7 1 (0.28%) Cucumber
7 1 (0.28%) Git
7 1 (0.28%) IDA Disassembler
7 1 (0.28%) JMeter
7 1 (0.28%) Maven
7 1 (0.28%) Snyk
General
1 87 (23.97%) Social Skills
2 50 (13.77%) Finance
3 41 (11.29%) Law
4 36 (9.92%) Analytical Skills
5 30 (8.26%) Public Sector
6 21 (5.79%) Legal
7 19 (5.23%) Retail
8 10 (2.75%) Banking
9 9 (2.48%) Inclusion and Diversity
10 8 (2.20%) Organisational Skills
11 6 (1.65%) Automotive
11 6 (1.65%) Financial Institution
12 5 (1.38%) Advertising
12 5 (1.38%) Marketing
12 5 (1.38%) Presentation Skills
13 3 (0.83%) Influencing Skills
14 2 (0.55%) Aeronautics
14 2 (0.55%) Documentation Skills
14 2 (0.55%) Military
14 2 (0.55%) Police
Job Titles
1 76 (20.94%) Analyst
2 68 (18.73%) Senior
3 67 (18.46%) Security Analyst
4 50 (13.77%) Consultant
5 49 (13.50%) Tester
6 46 (12.67%) Penetration Tester
7 44 (12.12%) Security Engineer
8 42 (11.57%) Security Consultant
8 42 (11.57%) Security Manager
9 39 (10.74%) Cybersecurity Analyst
10 23 (6.34%) Cybersecurity Manager
10 23 (6.34%) Lead
11 22 (6.06%) Senior Consultant
11 22 (6.06%) Senior Security Consultant
12 21 (5.79%) Infrastructure Engineer
13 19 (5.23%) Cybersecurity Engineer
14 18 (4.96%) Penetration Test Consultant
15 16 (4.41%) Cybersecurity Consultant
15 16 (4.41%) Information Manager
15 16 (4.41%) Information Security Manager
Libraries, Frameworks & Software Standards
1 8 (2.20%) OAuth
2 5 (1.38%) .NET
2 5 (1.38%) React
3 4 (1.10%) Node.js
4 3 (0.83%) OpenID
4 3 (0.83%) Web Services
5 2 (0.55%) HTML
5 2 (0.55%) ModSecurity
5 2 (0.55%) RESTful
5 2 (0.55%) SAML
5 2 (0.55%) Spring
5 2 (0.55%) Spring Boot
6 1 (0.28%) CSS
6 1 (0.28%) Django
6 1 (0.28%) Kafka
6 1 (0.28%) LDAP
6 1 (0.28%) OAuth2
6 1 (0.28%) Svelte
Miscellaneous
1 48 (13.22%) Management Information System
2 29 (7.99%) Security Posture
3 28 (7.71%) Cyber Threat
4 25 (6.89%) Onboarding
5 21 (5.79%) Mobile App
6 17 (4.68%) Cybercrime
7 16 (4.41%) Cyberattack
7 16 (4.41%) Security Operations Centre
8 12 (3.31%) Distributed Denial-of-Service
9 9 (2.48%) Operational Technology
9 9 (2.48%) Self-Motivation
10 7 (1.93%) Blog
10 7 (1.93%) PKI
11 6 (1.65%) IoT
12 5 (1.38%) CESG
12 5 (1.38%) Data Centre
12 5 (1.38%) Embedded Systems
12 5 (1.38%) Mainframe
12 5 (1.38%) Public Cloud
12 5 (1.38%) SWIFT Messaging Network
Operating Systems
1 54 (14.88%) Windows
2 44 (12.12%) Linux
3 21 (5.79%) Windows Server
4 16 (4.41%) Android
4 16 (4.41%) Apple iOS
5 7 (1.93%) Unix
6 4 (1.10%) Mac OS
6 4 (1.10%) Mac OS X
7 2 (0.55%) Kali Linux
7 2 (0.55%) Ubuntu
7 2 (0.55%) Windows 10
8 1 (0.28%) Windows Server 2012
Processes & Methodologies
1 229 (63.09%) Cybersecurity
2 141 (38.84%) Information Security
3 89 (24.52%) Vulnerability Assessment
4 83 (22.87%) SIEM
5 71 (19.56%) Vulnerability Management
6 69 (19.01%) Security Operations
7 66 (18.18%) Incident Response
8 62 (17.08%) Problem-Solving
9 53 (14.60%) Application Security
10 52 (14.33%) Security Testing
11 44 (12.12%) Risk Management
12 40 (11.02%) Computer Science
13 38 (10.47%) Red Team
14 36 (9.92%) Security Monitoring
15 35 (9.64%) Vulnerability Scanning
16 33 (9.09%) Mentoring
17 28 (7.71%) Cloud Security
17 28 (7.71%) Data Security
17 28 (7.71%) ITIL
18 26 (7.16%) Roadmaps
Programming Languages
1 32 (8.82%) Python
2 21 (5.79%) PowerShell
3 18 (4.96%) Bash
4 13 (3.58%) C#
4 13 (3.58%) SQL
5 10 (2.75%) C
5 10 (2.75%) C++
6 6 (1.65%) TypeScript
7 4 (1.10%) JavaScript
7 4 (1.10%) Perl
7 4 (1.10%) T-SQL
8 3 (0.83%) Go
8 3 (0.83%) Java
8 3 (0.83%) Ruby
9 2 (0.55%) Kusto Query Language
10 1 (0.28%) Bicep
10 1 (0.28%) PHP
10 1 (0.28%) Shell Script
10 1 (0.28%) VB
Qualifications
1 105 (28.93%) CISSP
2 65 (17.91%) Security Cleared
3 57 (15.70%) Degree
4 51 (14.05%) CREST Certified
5 48 (13.22%) CISM
6 41 (11.29%) Cisco Certification
7 34 (9.37%) OSCP
8 26 (7.16%) SC Cleared
9 25 (6.89%) (ISC)2 CCSP
9 25 (6.89%) CEH
10 23 (6.34%) CCSP
11 21 (5.79%) CISA
11 21 (5.79%) CompTIA Security+
11 21 (5.79%) Computer Science Degree
12 18 (4.96%) CISMP
13 16 (4.41%) BPSS Clearance
13 16 (4.41%) CompTIA CySA+
14 15 (4.13%) CCNA
14 15 (4.13%) Cyber Scheme
15 14 (3.86%) CESG Certified Professional
Quality Assurance & Compliance
1 102 (28.10%) ISO/IEC 27001
2 73 (20.11%) NIST
3 39 (10.74%) Cyber Essentials
4 35 (9.64%) GDPR
5 31 (8.54%) PCI DSS
6 18 (4.96%) Cyber Essentials PLUS
7 17 (4.68%) SOC 2
8 15 (4.13%) NIST 800
9 13 (3.58%) NCSC
10 12 (3.31%) GRC
10 12 (3.31%) QA
11 10 (2.75%) ISO 9001
12 6 (1.65%) HMG Security Policy Framework
13 5 (1.38%) Accessibility
14 4 (1.10%) COBIT
14 4 (1.10%) SLA
15 3 (0.83%) Def Stans
15 3 (0.83%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
15 3 (0.83%) PSD2
16 2 (0.55%) Disclosure Scotland
System Software
1 31 (8.54%) Active Directory
2 18 (4.96%) VMware Infrastructure
3 15 (4.13%) Hyper-V
4 7 (1.93%) Docker
5 3 (0.83%) KVM
5 3 (0.83%) Virtual Machines
5 3 (0.83%) XenApp
5 3 (0.83%) XenDesktop
6 2 (0.55%) Firmware
6 2 (0.55%) Microsoft Virtual Server
6 2 (0.55%) Virtual Servers
6 2 (0.55%) VMware Server
7 1 (0.28%) Snort
7 1 (0.28%) VMware ESXi
7 1 (0.28%) vSphere
Systems Management
1 18 (4.96%) Microsoft Intune
2 11 (3.03%) Terraform
3 10 (2.75%) Ansible
3 10 (2.75%) Nessus
4 9 (2.48%) Nmap
5 8 (2.20%) Kubernetes
6 6 (1.65%) FortiGate
7 5 (1.38%) HP Fortify
7 5 (1.38%) Stealthwatch
8 3 (0.83%) Progress Chef
8 3 (0.83%) Puppet
9 2 (0.55%) CASB
9 2 (0.55%) DatAdvantage
9 2 (0.55%) QRadar
9 2 (0.55%) SmoothWall
9 2 (0.55%) WSUS
10 1 (0.28%) Core Impact
10 1 (0.28%) McAfee ePO
10 1 (0.28%) Network Intrusion Detection System
10 1 (0.28%) Packer
Vendors
1 52 (14.33%) Microsoft
2 45 (12.40%) Cisco
3 23 (6.34%) Palo Alto
4 20 (5.51%) VMware
5 15 (4.13%) Meraki
6 13 (3.58%) Qualys
7 12 (3.31%) Aruba
8 7 (1.93%) Fortinet
8 7 (1.93%) SolarWinds
9 6 (1.65%) Juniper
10 5 (1.38%) Citrix
10 5 (1.38%) HP
10 5 (1.38%) ServiceNow
10 5 (1.38%) Tanium
11 4 (1.10%) CheckPoint
11 4 (1.10%) Splunk
11 4 (1.10%) Ubiquiti
11 4 (1.10%) Veeam
12 3 (0.83%) McAfee
12 3 (0.83%) Sophos