Penetration Testing Job Trends

Penetration Testing
UK

The table below provides summary statistics and salary benchmarking for jobs requiring Penetration Testing skills. It covers permanent job vacancies from the 6 months leading up to 1 January 2026, with comparisons to the same periods in the previous two years.

6 months to
1 Jan 2026
Same period 2025 Same period 2024
Rank 465 385 366
Rank change year-on-year -80 -19 +167
Permanent jobs citing Penetration Testing 187 363 391
As % of all permanent jobs in the UK 0.32% 0.66% 0.76%
As % of the Processes & Methodologies category 0.39% 0.73% 0.83%
Number of salaries quoted 154 205 316
10th Percentile £48,165 £45,000 £43,415
25th Percentile £55,000 £56,250 £52,500
Median annual salary (50th Percentile) £70,000 £65,000 £65,000
Median % change year-on-year +7.69% - -5.93%
75th Percentile £89,375 £88,750 £82,500
90th Percentile £90,000 £100,000 £89,375
UK excluding London median annual salary £62,500 £61,250 £60,000
% change year-on-year +2.04% +2.08% -7.69%

All Process & Methodology Skills
UK

Penetration Testing falls under the Processes and Methodologies category. For comparison with the information above, the following table provides summary statistics for all permanent job vacancies requiring process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 48,455 49,716 46,950
As % of all permanent jobs advertised in the UK 81.91% 90.02% 91.47%
Number of salaries quoted 28,359 24,660 35,854
10th Percentile £28,500 £35,000 £31,552
25th Percentile £36,500 £45,000 £42,500
Median annual salary (50th Percentile) £55,000 £60,000 £60,000
Median % change year-on-year -8.33% - -4.00%
75th Percentile £75,000 £80,000 £80,000
90th Percentile £95,000 £100,000 £97,500
UK excluding London median annual salary £49,000 £55,000 £52,500
% change year-on-year -10.91% +4.76% -4.50%

Penetration Testing
Job Vacancy Trend

Historical trend showing the proportion of permanent IT job postings citing Penetration Testing relative to all permanent IT jobs advertised.

Penetration Testing job vacancy trend in the UK

Penetration Testing
Salary Trend

Salary distribution trend for jobs in the UK citing Penetration Testing.

Salary distribution trend for jobs in the UK citing Penetration Testing

Penetration Testing
Salary Histogram

Salary distribution for jobs citing Penetration Testing over the 6 months to 1 January 2026.

Salary histogram for Penetration Testing in the UK

Penetration Testing
Top 14 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 1 January 2026. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -45 168 £70,000 +7.69% 125
UK excluding London -36 96 £62,500 +2.04% 78
London -47 74 £75,000 - 49
Work from Home +4 69 £60,000 -7.69% 67
South West +25 33 £80,000 +25.00% 15
Midlands +12 25 £52,750 -8.26% 14
South East -18 20 £60,500 +0.83% 21
West Midlands +3 14 £59,000 -9.23% 9
East Midlands -1 11 £51,058 -11.20% 5
North of England -3 10 £55,000 -3.30% 23
Scotland -21 8 £90,000 +21.21% 2
Yorkshire -5 6 £54,250 +3.33% 7
North West -1 4 £55,000 -12.00% 15
East of England +20 1 £85,000 +198.25% 3

Penetration Testing
Co-Occurring Skills & Capabilities by Category

The following tables expand on the one above by listing co-occurrences grouped by category. They cover the same employment type, locality and period, with up to 20 co-occurrences shown in each category:

Application Platforms
1 6 (3.21%) Microsoft Exchange
2 3 (1.60%) SharePoint
3 1 (0.53%) Confluence
Applications
1 7 (3.74%) Microsoft Excel
1 7 (3.74%) Microsoft Office
2 2 (1.07%) Weka
3 1 (0.53%) GNU Octave
Cloud Services
1 58 (31.02%) Azure
2 33 (17.65%) AWS
3 16 (8.56%) Azure Sentinel
3 16 (8.56%) GitHub
4 14 (7.49%) Slack
5 12 (6.42%) Entra ID
5 12 (6.42%) GitHub Actions
5 12 (6.42%) Microsoft 365
6 11 (5.88%) Microsoft Purview
7 10 (5.35%) Power Platform
8 9 (4.81%) GCP
9 3 (1.60%) IBM Cloud
9 3 (1.60%) Mimecast
9 3 (1.60%) SaaS
10 2 (1.07%) Rubrik
10 2 (1.07%) SecurityScorecard
11 1 (0.53%) Azure Key Vault
11 1 (0.53%) Dynamics 365
11 1 (0.53%) Power Automate
11 1 (0.53%) Tessian
Communications & Networking
1 35 (18.72%) Firewall
2 26 (13.90%) Network Security
3 22 (11.76%) TCP/IP
4 13 (6.95%) VPN
5 9 (4.81%) Wireshark
6 7 (3.74%) Intrusion Detection
6 7 (3.74%) Wi-Fi
6 7 (3.74%) Wireless
7 5 (2.67%) HTTP
7 5 (2.67%) VLAN
8 4 (2.14%) DNS
8 4 (2.14%) Ethernet
9 3 (1.60%) Cisco ISE
9 3 (1.60%) Modbus
10 2 (1.07%) BGP
10 2 (1.07%) Cisco Nexus
10 2 (1.07%) ICMP
10 2 (1.07%) Internet
10 2 (1.07%) OSPF
10 2 (1.07%) SSH
Database & Business Intelligence
1 10 (5.35%) Power BI
2 7 (3.74%) Tableau
3 2 (1.07%) SQL Server
4 1 (0.53%) Elasticsearch
Development Applications
1 23 (12.30%) Burp Suite
2 22 (11.76%) Metasploit
3 16 (8.56%) JIRA
4 12 (6.42%) Jenkins
5 2 (1.07%) IDA Disassembler
6 1 (0.53%) Git
6 1 (0.53%) GitLab
General
1 72 (38.50%) Social Skills
2 40 (21.39%) Finance
3 20 (10.70%) Analytical Skills
4 17 (9.09%) Influencing Skills
5 16 (8.56%) Inclusion and Diversity
6 15 (8.02%) Presentation Skills
7 11 (5.88%) Public Sector
8 10 (5.35%) Retail
9 9 (4.81%) Banking
10 6 (3.21%) Law
11 4 (2.14%) Documentation Skills
11 4 (2.14%) Electronics
11 4 (2.14%) Legal
11 4 (2.14%) Marketing
12 3 (1.60%) Manufacturing
12 3 (1.60%) Military
13 2 (1.07%) Aerospace
13 2 (1.07%) Pharmaceutical
13 2 (1.07%) Public Speaking
13 2 (1.07%) Telecoms
Job Titles
1 47 (25.13%) Security Engineer
2 31 (16.58%) Analyst
3 27 (14.44%) Security Analyst
4 25 (13.37%) Senior
5 21 (11.23%) Tester
6 20 (10.70%) Penetration Tester
7 18 (9.63%) Consultant
7 18 (9.63%) Security Consultant
8 17 (9.09%) Cybersecurity Engineer
9 15 (8.02%) Applications Engineer
9 15 (8.02%) IT Manager
9 15 (8.02%) Senior Security Engineer
10 11 (5.88%) Cybersecurity Consultant
11 10 (5.35%) Security Manager
12 9 (4.81%) Lead
12 9 (4.81%) Security Specialist
13 8 (4.28%) Auditor
13 8 (4.28%) Cybersecurity Analyst
13 8 (4.28%) Information Analyst
13 8 (4.28%) Information Security Analyst
Libraries, Frameworks & Software Standards
1 5 (2.67%) JSON
2 1 (0.53%) Elastic Stack
2 1 (0.53%) PyTorch
2 1 (0.53%) TensorFlow
2 1 (0.53%) YAML
Miscellaneous
1 30 (16.04%) Security Posture
2 24 (12.83%) Management Information System
3 15 (8.02%) Cyber Threat
4 12 (6.42%) Cyber Defence
4 12 (6.42%) Security Operations Centre
5 9 (4.81%) Mobile App
6 8 (4.28%) Operational Technology
6 8 (4.28%) Self-Motivation
7 7 (3.74%) Analytical Mindset
7 7 (3.74%) PKI
8 6 (3.21%) Cyber Kill Chain
8 6 (3.21%) Insider Threat
9 5 (2.67%) Cloud Native
9 5 (2.67%) Enterprise Software
9 5 (2.67%) SCADA
10 4 (2.14%) Linux Command Line
11 3 (1.60%) Cyber Security Posture
11 3 (1.60%) Data Protection Act
11 3 (1.60%) Onboarding
11 3 (1.60%) Renewable Energy
Operating Systems
1 27 (14.44%) Linux
2 24 (12.83%) Windows
3 7 (3.74%) Unix
4 6 (3.21%) Windows Server
5 4 (2.14%) Android
5 4 (2.14%) Apple iOS
5 4 (2.14%) Kali Linux
6 1 (0.53%) Debian
6 1 (0.53%) Ubuntu
6 1 (0.53%) Windows 10
6 1 (0.53%) Windows Server 2016
6 1 (0.53%) Windows Server 2019
Processes & Methodologies
1 94 (50.27%) Cybersecurity
2 65 (34.76%) Incident Response
3 49 (26.20%) SIEM
4 44 (23.53%) Vulnerability Management
5 42 (22.46%) Red Team
6 39 (20.86%) Information Security
7 36 (19.25%) Problem-Solving
8 35 (18.72%) Application Security
9 33 (17.65%) Security Operations
10 32 (17.11%) Vulnerability Assessment
10 32 (17.11%) Vulnerability Scanning
11 29 (15.51%) Threat Modelling
12 27 (14.44%) DevOps
12 27 (14.44%) Security Testing
13 26 (13.90%) Technology Transformation
13 26 (13.90%) Vulnerability Remediation
14 22 (11.76%) Cloud Security
14 22 (11.76%) ITIL
15 21 (11.23%) CI/CD
15 21 (11.23%) SDLC
Programming Languages
1 61 (32.62%) Python
2 39 (20.86%) Bash
3 38 (20.32%) PowerShell
4 16 (8.56%) Go
5 10 (5.35%) SQL
6 7 (3.74%) C
6 7 (3.74%) C++
6 7 (3.74%) R
7 6 (3.21%) C#
7 6 (3.21%) Perl
8 5 (2.67%) JavaScript
9 3 (1.60%) Java
10 2 (1.07%) Ruby
11 1 (0.53%) Kusto Query Language
11 1 (0.53%) Scala
Qualifications
1 57 (30.48%) CISSP
2 42 (22.46%) Degree
3 40 (21.39%) CREST Certified
4 39 (20.86%) Security Cleared
5 33 (17.65%) SC Cleared
6 30 (16.04%) OSCP
7 29 (15.51%) Cisco Certification
8 22 (11.76%) SANS
9 20 (10.70%) CCNA
10 18 (9.63%) CompTIA Security+
11 17 (9.09%) CHECK Team Member
11 17 (9.09%) GIAC
12 13 (6.95%) CEH
12 13 (6.95%) DV Cleared
13 12 (6.42%) CISA
13 12 (6.42%) GCIA
13 12 (6.42%) GCIH
14 11 (5.88%) CCNP
15 9 (4.81%) CISM
15 9 (4.81%) MCP
Quality Assurance & Compliance
1 72 (38.50%) ISO/IEC 27001
2 52 (27.81%) NIST
3 28 (14.97%) Cyber Essentials
4 26 (13.90%) Accessibility
5 15 (8.02%) GDPR
6 6 (3.21%) Actionable Recommendations
6 6 (3.21%) GRC
6 6 (3.21%) NCSC
7 5 (2.67%) NIST 800
8 4 (2.14%) QA
9 3 (1.60%) Cyber Essentials PLUS
9 3 (1.60%) ITGC
9 3 (1.60%) PCI DSS
9 3 (1.60%) RMADS
10 2 (1.07%) GxP
10 2 (1.07%) ISO/IEC 27005
11 1 (0.53%) COBIT
11 1 (0.53%) ISO/IEC 42001
11 1 (0.53%) Sarbanes-Oxley
11 1 (0.53%) SOC 2
System Software
1 14 (7.49%) Virtual Machines
2 9 (4.81%) Active Directory
3 6 (3.21%) VMware Infrastructure
4 4 (2.14%) VMware ESXi
5 3 (1.60%) Hyper-V
6 2 (1.07%) Docker
6 2 (1.07%) EMC RecoverPoint
6 2 (1.07%) Firmware
6 2 (1.07%) pfSense
6 2 (1.07%) Squid
6 2 (1.07%) vSphere
Systems Management
1 19 (10.16%) Nmap
2 17 (9.09%) Nessus
3 8 (4.28%) QRadar
4 5 (2.67%) Kubernetes
4 5 (2.67%) Single Sign-On
5 4 (2.14%) Microsoft Intune
6 3 (1.60%) ArcSight ESM
6 3 (1.60%) Proxmox
7 2 (1.07%) Cisco CUCM
7 2 (1.07%) CSIRT
7 2 (1.07%) Terraform
7 2 (1.07%) VxRail
8 1 (0.53%) Ansible
8 1 (0.53%) CASB
8 1 (0.53%) Kibana
8 1 (0.53%) Progress Chef
8 1 (0.53%) SCCM
8 1 (0.53%) ZENworks
Vendors
1 54 (28.88%) Microsoft
2 16 (8.56%) Tenable
3 15 (8.02%) Cisco
4 14 (7.49%) ServiceNow
5 11 (5.88%) Splunk
6 8 (4.28%) VMware
7 7 (3.74%) Oracle
8 5 (2.67%) Fortinet
8 5 (2.67%) Palo Alto
9 4 (2.14%) CheckPoint
9 4 (2.14%) Qualys
9 4 (2.14%) Zscaler
10 3 (1.60%) ArcSight
10 3 (1.60%) CyberArk
10 3 (1.60%) IBM
10 3 (1.60%) LogLogic
10 3 (1.60%) LogRhythm
10 3 (1.60%) McAfee
11 2 (1.07%) Okta
11 2 (1.07%) Trend Micro