Penetration Testing Job Trends

Penetration Testing
UK

The table below provides summary statistics and salary benchmarking for jobs requiring Penetration Testing skills. It covers permanent job vacancies from the 6 months leading up to 7 January 2026, with comparisons to the same periods in the previous two years.

6 months to
7 Jan 2026
Same period 2025 Same period 2024
Rank 456 387 371
Rank change year-on-year -69 -16 +154
Permanent jobs citing Penetration Testing 188 354 400
As % of all permanent jobs in the UK 0.31% 0.65% 0.74%
As % of the Processes & Methodologies category 0.39% 0.72% 0.82%
Number of salaries quoted 154 200 325
10th Percentile £48,165 £45,000 £43,750
25th Percentile £55,000 £55,938 £52,500
Median annual salary (50th Percentile) £70,000 £65,000 £65,000
Median % change year-on-year +7.69% - -6.07%
75th Percentile £89,375 £88,750 £82,500
90th Percentile £90,000 £100,000 £88,750
UK excluding London median annual salary £62,500 £60,000 £60,000
% change year-on-year +4.17% - -7.69%

All Process & Methodology Skills
UK

Penetration Testing falls under the Processes and Methodologies category. For comparison with the information above, the following table provides summary statistics for all permanent job vacancies requiring process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 48,581 48,989 48,580
As % of all permanent jobs advertised in the UK 81.32% 90.25% 90.41%
Number of salaries quoted 28,539 24,001 36,978
10th Percentile £28,500 £35,000 £31,250
25th Percentile £37,500 £45,000 £42,500
Median annual salary (50th Percentile) £55,000 £60,000 £60,000
Median % change year-on-year -8.33% - -4.00%
75th Percentile £75,000 £80,000 £78,750
90th Percentile £95,000 £100,000 £97,500
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% -4.55%

Penetration Testing
Job Vacancy Trend

Historical trend showing the proportion of permanent IT job postings citing Penetration Testing relative to all permanent IT jobs advertised.

Penetration Testing job vacancy trend in the UK

Penetration Testing
Salary Trend

Salary distribution trend for jobs in the UK citing Penetration Testing.

Salary distribution trend for jobs in the UK citing Penetration Testing

Penetration Testing
Salary Histogram

Salary distribution for jobs citing Penetration Testing over the 6 months to 7 January 2026.

Salary histogram for Penetration Testing in the UK

Penetration Testing
Top 14 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 7 January 2026. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -31 169 £70,000 +7.69% 92
UK excluding London -35 98 £62,500 +4.17% 65
London -19 73 £76,000 +4.83% 34
Work from Home -10 70 £60,000 -7.69% 49
South West +29 33 £80,000 +25.00% 15
Midlands +13 27 £52,500 -8.70% 15
South East -20 19 £62,500 +4.17% 17
West Midlands +9 14 £59,000 -9.23% 11
East Midlands +10 13 £51,058 -11.20% 4
North of England -12 11 £55,000 - 13
Scotland -32 8 £90,000 +21.21% 1
Yorkshire -10 7 £60,000 +14.29% 4
North West -3 4 £55,000 -12.00% 8
East of England +18 1 £85,000 +198.25% 4

Penetration Testing
Co-Occurring Skills & Capabilities by Category

The following tables expand on the one above by listing co-occurrences grouped by category. They cover the same employment type, locality and period, with up to 20 co-occurrences shown in each category:

Application Platforms
1 6 (3.19%) Microsoft Exchange
2 3 (1.60%) SharePoint
3 1 (0.53%) Confluence
Applications
1 7 (3.72%) Microsoft Excel
1 7 (3.72%) Microsoft Office
2 2 (1.06%) Weka
3 1 (0.53%) GNU Octave
Cloud Services
1 58 (30.85%) Azure
2 32 (17.02%) AWS
3 16 (8.51%) GitHub
4 15 (7.98%) Azure Sentinel
5 14 (7.45%) Slack
6 12 (6.38%) Entra ID
6 12 (6.38%) GitHub Actions
6 12 (6.38%) Microsoft 365
7 11 (5.85%) Microsoft Purview
8 10 (5.32%) Power Platform
9 8 (4.26%) GCP
10 3 (1.60%) IBM Cloud
10 3 (1.60%) Mimecast
11 2 (1.06%) Rubrik
11 2 (1.06%) SaaS
11 2 (1.06%) SecurityScorecard
12 1 (0.53%) Cloud Computing
12 1 (0.53%) Datadog
12 1 (0.53%) OpenShift
12 1 (0.53%) Tessian
Communications & Networking
1 35 (18.62%) Firewall
2 26 (13.83%) Network Security
3 22 (11.70%) TCP/IP
4 13 (6.91%) VPN
5 9 (4.79%) Wireshark
6 7 (3.72%) Intrusion Detection
6 7 (3.72%) Wi-Fi
6 7 (3.72%) Wireless
7 5 (2.66%) HTTP
7 5 (2.66%) VLAN
8 4 (2.13%) DNS
8 4 (2.13%) Ethernet
9 3 (1.60%) Cisco ISE
9 3 (1.60%) Internet
9 3 (1.60%) Modbus
10 2 (1.06%) BGP
10 2 (1.06%) Cisco Nexus
10 2 (1.06%) ICMP
10 2 (1.06%) OSPF
10 2 (1.06%) SSH
Database & Business Intelligence
1 10 (5.32%) Power BI
2 7 (3.72%) Tableau
3 2 (1.06%) SQL Server
4 1 (0.53%) Elasticsearch
Development Applications
1 22 (11.70%) Burp Suite
1 22 (11.70%) Metasploit
2 16 (8.51%) JIRA
3 12 (6.38%) Jenkins
4 2 (1.06%) IDA Disassembler
5 1 (0.53%) Git
5 1 (0.53%) GitLab
General
1 72 (38.30%) Social Skills
2 40 (21.28%) Finance
3 20 (10.64%) Analytical Skills
4 17 (9.04%) Influencing Skills
5 16 (8.51%) Inclusion and Diversity
6 15 (7.98%) Presentation Skills
7 11 (5.85%) Public Sector
7 11 (5.85%) Retail
8 9 (4.79%) Banking
9 6 (3.19%) Law
10 4 (2.13%) Documentation Skills
10 4 (2.13%) Electronics
10 4 (2.13%) Legal
10 4 (2.13%) Marketing
11 3 (1.60%) Manufacturing
11 3 (1.60%) Military
12 2 (1.06%) Aerospace
12 2 (1.06%) Pharmaceutical
12 2 (1.06%) Public Speaking
12 2 (1.06%) Telecoms
Job Titles
1 47 (25.00%) Security Engineer
2 30 (15.96%) Analyst
3 26 (13.83%) Security Analyst
4 24 (12.77%) Senior
5 20 (10.64%) Tester
6 19 (10.11%) Consultant
6 19 (10.11%) Penetration Tester
6 19 (10.11%) Security Consultant
7 17 (9.04%) Cybersecurity Engineer
8 15 (7.98%) Applications Engineer
8 15 (7.98%) IT Manager
8 15 (7.98%) Senior Security Engineer
9 12 (6.38%) Cybersecurity Consultant
10 10 (5.32%) Security Manager
10 10 (5.32%) Security Specialist
11 9 (4.79%) Lead
12 8 (4.26%) Auditor
12 8 (4.26%) Information Analyst
12 8 (4.26%) Information Security Analyst
12 8 (4.26%) IT Auditor
Libraries, Frameworks & Software Standards
1 5 (2.66%) JSON
2 1 (0.53%) Elastic Stack
2 1 (0.53%) PyTorch
2 1 (0.53%) TensorFlow
2 1 (0.53%) YAML
Miscellaneous
1 33 (17.55%) Security Posture
2 24 (12.77%) Management Information System
3 14 (7.45%) Cyber Threat
4 12 (6.38%) Cyber Defence
5 11 (5.85%) Security Operations Centre
6 9 (4.79%) Mobile App
7 8 (4.26%) Operational Technology
7 8 (4.26%) Self-Motivation
8 7 (3.72%) Analytical Mindset
8 7 (3.72%) Insider Threat
8 7 (3.72%) PKI
9 6 (3.19%) Cyber Kill Chain
10 5 (2.66%) Cloud Native
10 5 (2.66%) Enterprise Software
10 5 (2.66%) SCADA
11 4 (2.13%) Linux Command Line
12 3 (1.60%) Cyber Security Posture
12 3 (1.60%) Data Protection Act
12 3 (1.60%) Onboarding
12 3 (1.60%) Renewable Energy
Operating Systems
1 25 (13.30%) Linux
2 24 (12.77%) Windows
3 7 (3.72%) Unix
4 6 (3.19%) Windows Server
5 4 (2.13%) Android
5 4 (2.13%) Apple iOS
6 3 (1.60%) Kali Linux
7 1 (0.53%) Debian
7 1 (0.53%) Ubuntu
7 1 (0.53%) Windows 10
7 1 (0.53%) Windows Server 2016
7 1 (0.53%) Windows Server 2019
Processes & Methodologies
1 94 (50.00%) Cybersecurity
2 64 (34.04%) Incident Response
3 48 (25.53%) SIEM
4 44 (23.40%) Vulnerability Management
5 43 (22.87%) Red Team
6 40 (21.28%) Information Security
7 37 (19.68%) Problem-Solving
8 36 (19.15%) Application Security
9 32 (17.02%) Security Operations
9 32 (17.02%) Vulnerability Scanning
10 31 (16.49%) Vulnerability Assessment
11 28 (14.89%) Security Testing
11 28 (14.89%) Threat Modelling
12 27 (14.36%) DevOps
13 26 (13.83%) Technology Transformation
14 25 (13.30%) Vulnerability Remediation
15 22 (11.70%) CI/CD
15 22 (11.70%) Cloud Security
15 22 (11.70%) ITIL
16 21 (11.17%) SDLC
Programming Languages
1 60 (31.91%) Python
2 38 (20.21%) Bash
3 37 (19.68%) PowerShell
4 16 (8.51%) Go
5 10 (5.32%) SQL
6 7 (3.72%) C
6 7 (3.72%) C++
6 7 (3.72%) R
7 6 (3.19%) C#
7 6 (3.19%) Perl
8 5 (2.66%) JavaScript
9 3 (1.60%) Java
10 2 (1.06%) Ruby
11 1 (0.53%) Kusto Query Language
11 1 (0.53%) Scala
Qualifications
1 59 (31.38%) CISSP
2 43 (22.87%) Degree
3 41 (21.81%) CREST Certified
4 40 (21.28%) Security Cleared
5 34 (18.09%) SC Cleared
6 30 (15.96%) Cisco Certification
6 30 (15.96%) OSCP
7 22 (11.70%) SANS
8 21 (11.17%) CCNA
9 19 (10.11%) CompTIA Security+
10 18 (9.57%) GIAC
11 17 (9.04%) CHECK Team Member
12 14 (7.45%) CEH
13 13 (6.91%) DV Cleared
14 12 (6.38%) CISA
14 12 (6.38%) GCIA
14 12 (6.38%) GCIH
15 11 (5.85%) CCNP
16 10 (5.32%) MCP
16 10 (5.32%) Microsoft Certification
Quality Assurance & Compliance
1 72 (38.30%) ISO/IEC 27001
2 52 (27.66%) NIST
3 27 (14.36%) Cyber Essentials
4 26 (13.83%) Accessibility
5 14 (7.45%) GDPR
6 7 (3.72%) Actionable Recommendations
7 6 (3.19%) GRC
7 6 (3.19%) NCSC
8 5 (2.66%) NIST 800
9 4 (2.13%) QA
10 3 (1.60%) ITGC
10 3 (1.60%) PCI DSS
10 3 (1.60%) RMADS
11 2 (1.06%) Cyber Essentials PLUS
11 2 (1.06%) GxP
11 2 (1.06%) ISO/IEC 27005
12 1 (0.53%) COBIT
12 1 (0.53%) ISO/IEC 42001
12 1 (0.53%) Sarbanes-Oxley
12 1 (0.53%) SOC 2
System Software
1 14 (7.45%) Virtual Machines
2 9 (4.79%) Active Directory
3 6 (3.19%) VMware Infrastructure
4 4 (2.13%) VMware ESXi
5 3 (1.60%) Hyper-V
6 2 (1.06%) Docker
6 2 (1.06%) EMC RecoverPoint
6 2 (1.06%) Firmware
6 2 (1.06%) pfSense
6 2 (1.06%) Squid
6 2 (1.06%) vSphere
Systems Management
1 19 (10.11%) Nmap
2 17 (9.04%) Nessus
3 8 (4.26%) QRadar
4 5 (2.66%) Kubernetes
4 5 (2.66%) Single Sign-On
5 4 (2.13%) Microsoft Intune
6 3 (1.60%) ArcSight ESM
6 3 (1.60%) Proxmox
7 2 (1.06%) Cisco CUCM
7 2 (1.06%) CSIRT
7 2 (1.06%) Terraform
7 2 (1.06%) VxRail
8 1 (0.53%) Ansible
8 1 (0.53%) CASB
8 1 (0.53%) Kibana
8 1 (0.53%) Progress Chef
8 1 (0.53%) SCCM
Vendors
1 55 (29.26%) Microsoft
2 16 (8.51%) Cisco
3 15 (7.98%) Tenable
4 14 (7.45%) ServiceNow
5 11 (5.85%) Splunk
6 8 (4.26%) VMware
7 7 (3.72%) Oracle
8 5 (2.66%) Fortinet
8 5 (2.66%) Palo Alto
8 5 (2.66%) Qualys
9 4 (2.13%) CheckPoint
9 4 (2.13%) Zscaler
10 3 (1.60%) ArcSight
10 3 (1.60%) CyberArk
10 3 (1.60%) IBM
10 3 (1.60%) LogLogic
10 3 (1.60%) LogRhythm
10 3 (1.60%) McAfee
11 2 (1.06%) Okta
11 2 (1.06%) Trend Micro