Threat Modelling
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Threat Modelling skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Threat Modelling over the 6 months to 11 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
11 May 2024
Same period 2023 Same period 2022
Rank 749 540 751
Rank change year-on-year -209 +211 -18
Permanent jobs citing Threat Modelling 145 521 531
As % of all permanent jobs advertised in the UK 0.15% 0.52% 0.34%
As % of the Processes & Methodologies category 0.17% 0.54% 0.35%
Number of salaries quoted 105 271 272
10th Percentile £46,875 £46,454 £51,250
25th Percentile £57,500 £61,750 £60,000
Median annual salary (50th Percentile) £75,000 £81,928 £77,500
Median % change year-on-year -8.46% +5.71% +3.33%
75th Percentile £90,000 £98,000 £92,500
90th Percentile £102,750 £113,750 £101,250
UK excluding London median annual salary £58,750 £70,000 £65,000
% change year-on-year -16.07% +7.69% -

All Process and Methodology Skills
UK

Threat Modelling is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 84,921 96,445 150,777
As % of all permanent jobs advertised in the UK 85.57% 95.59% 95.69%
Number of salaries quoted 59,902 56,808 82,456
10th Percentile £29,010 £34,000 £33,645
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,000 £60,000
Median % change year-on-year -9.84% +1.67% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +10.53%

Threat Modelling
Job Vacancy Trend

Job postings citing Threat Modelling as a proportion of all IT jobs advertised.

Job vacancy trend for Threat Modelling in the UK

Threat Modelling
Salary Trend

3-month moving average salary quoted in jobs citing Threat Modelling.

Salary trend for Threat Modelling in the UK

Threat Modelling
Salary Histogram

Salary distribution for jobs citing Threat Modelling over the 6 months to 11 May 2024.

Salary histogram for Threat Modelling in the UK

Threat Modelling
Top 13 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Threat Modelling within the UK over the 6 months to 11 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -223 107 £70,000 -14.56% 51
UK excluding London -131 72 £58,750 -16.07% 25
London -90 41 £97,500 +14.71% 25
Work from Home -51 39 £82,500 +10.00% 24
North of England -8 27 £50,000 -28.29% 4
North West -16 20 £50,000 -28.57% 2
South West -24 14 £72,500 +11.97% 6
South East -56 13 £59,000 -30.59% 2
West Midlands +7 11 £72,500 -0.68% 9
Midlands -13 11 £72,500 -0.68% 9
Yorkshire +56 7 £50,000 -28.00% 2
Scotland -79 6 - - 2
East of England +19 1 - - 2

Threat Modelling
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Applications
1 12 (8.28%) Microsoft Office
2 9 (6.21%) Microsoft Excel
Cloud Services
1 81 (55.86%) Azure
2 79 (54.48%) AWS
3 32 (22.07%) GCP
4 18 (12.41%) Microsoft 365
5 13 (8.97%) Serverless
6 12 (8.28%) Power Platform
7 9 (6.21%) AWS CloudFormation
7 9 (6.21%) Cloud Computing
8 8 (5.52%) Amazon CloudWatch
8 8 (5.52%) Amazon EC2
8 8 (5.52%) Amazon GuardDuty
8 8 (5.52%) Amazon S3
8 8 (5.52%) AWS CloudTrail
8 8 (5.52%) AWS Lambda
8 8 (5.52%) PaaS
8 8 (5.52%) Virtual Private Cloud
9 6 (4.14%) Azure Service Fabric
9 6 (4.14%) Entra ID
9 6 (4.14%) IaaS
9 6 (4.14%) SaaS
Communications & Networking
1 26 (17.93%) Firewall
2 19 (13.10%) LAN
3 16 (11.03%) DNS
4 11 (7.59%) Intrusion Detection
5 9 (6.21%) Network Security
6 6 (4.14%) HTTP
7 5 (3.45%) Internet
7 5 (3.45%) SSL
7 5 (3.45%) VPN
8 4 (2.76%) SMTP
8 4 (2.76%) Wireless
9 3 (2.07%) WAN
10 2 (1.38%) 802.11
10 2 (1.38%) Bluetooth
10 2 (1.38%) IPv4
10 2 (1.38%) ZigBee
11 1 (0.69%) SD-WAN
11 1 (0.69%) TCP/IP
11 1 (0.69%) Wireshark
Database & Business Intelligence
1 9 (6.21%) Power BI
2 8 (5.52%) Amazon RDS
3 6 (4.14%) Azure SQL Database
4 3 (2.07%) Data Lake
5 2 (1.38%) Big Data
Development Applications
1 19 (13.10%) Jenkins
2 7 (4.83%) Burp Suite
2 7 (4.83%) Metasploit
3 3 (2.07%) sqlmap
4 2 (1.38%) Bitbucket
5 1 (0.69%) CircleCI
5 1 (0.69%) GitLab
5 1 (0.69%) Snyk
General
1 45 (31.03%) Social Skills
2 35 (24.14%) Finance
3 17 (11.72%) Presentation Skills
3 17 (11.72%) Public Sector
4 14 (9.66%) Banking
4 14 (9.66%) Inclusion and Diversity
4 14 (9.66%) Law
4 14 (9.66%) Retail
5 10 (6.90%) Marketing
6 7 (4.83%) Analytical Skills
7 5 (3.45%) Investment Banking
7 5 (3.45%) Legal
7 5 (3.45%) Manufacturing
8 2 (1.38%) Cyber-Physical System
8 2 (1.38%) Financial Institution
8 2 (1.38%) Influencing Skills
8 2 (1.38%) Organisational Skills
9 1 (0.69%) Automotive
9 1 (0.69%) Pharmaceutical
9 1 (0.69%) Telecoms
Job Titles
1 48 (33.10%) Architect
2 41 (28.28%) Security Architect
3 40 (27.59%) Senior
4 24 (16.55%) Security Engineer
5 23 (15.86%) Cybersecurity Architect
6 17 (11.72%) Lead
7 15 (10.34%) Senior Architect
8 13 (8.97%) Consultant
8 13 (8.97%) Security Consultant
9 12 (8.28%) Security Technical Architect
9 12 (8.28%) Technical Architect
10 10 (6.90%) AWS Engineer
11 9 (6.21%) Senior Security Architect
12 8 (5.52%) Cybersecurity Engineer
12 8 (5.52%) Information Architect
12 8 (5.52%) Information Security Architect
13 7 (4.83%) Analyst
13 7 (4.83%) DevSecOps Engineer
13 7 (4.83%) Senior Consultant
13 7 (4.83%) Senior Security Engineer
Libraries, Frameworks & Software Standards
1 13 (8.97%) Web Services
2 12 (8.28%) OAuth
3 6 (4.14%) REST
3 6 (4.14%) SAML
3 6 (4.14%) SOAP
4 4 (2.76%) JWT
5 3 (2.07%) HTML
6 2 (1.38%) 802.1X
6 2 (1.38%) HTML5
6 2 (1.38%) Middleware
6 2 (1.38%) OAuth2
6 2 (1.38%) OpenID
6 2 (1.38%) WebSockets
7 1 (0.69%) AWS CDK
Miscellaneous
1 36 (24.83%) Cyberattack
2 31 (21.38%) Management Information System
3 26 (17.93%) Cyber Threat
4 22 (15.17%) Data Centre
5 20 (13.79%) PKI
6 17 (11.72%) Security Posture
7 16 (11.03%) Onboarding
8 12 (8.28%) iPhone
9 9 (6.21%) Public Cloud
10 8 (5.52%) Hybrid Cloud
10 8 (5.52%) IoT
11 6 (4.14%) Distributed Systems
12 5 (3.45%) Mobile App
12 5 (3.45%) PropTech
13 4 (2.76%) Self-Motivation
14 3 (2.07%) Cloud Native
14 3 (2.07%) SCADA
15 2 (1.38%) CAN bus
15 2 (1.38%) Life Science
15 2 (1.38%) Robotics
Operating Systems
1 21 (14.48%) Windows
2 9 (6.21%) Kali Linux
3 7 (4.83%) Android
3 7 (4.83%) Apple iOS
4 2 (1.38%) Linux
4 2 (1.38%) Unix
4 2 (1.38%) Windows Server
5 1 (0.69%) Red Hat Enterprise Linux
5 1 (0.69%) Windows XP
Processes & Methodologies
1 100 (68.97%) Cybersecurity
2 60 (41.38%) Information Security
3 48 (33.10%) Application Security
4 43 (29.66%) Incident Response
5 39 (26.90%) Vulnerability Management
6 37 (25.52%) Penetration Testing
7 35 (24.14%) Security Architecture
8 28 (19.31%) Threat Management
9 26 (17.93%) Identity Access Management
9 26 (17.93%) Threat Intelligence
10 25 (17.24%) Cyber Threat Intelligence
10 25 (17.24%) OWASP
10 25 (17.24%) Secure Coding
11 24 (16.55%) Stakeholder Management
12 23 (15.86%) Cloud Security
12 23 (15.86%) Cryptography
13 22 (15.17%) Cyber Assurance
13 22 (15.17%) Problem-Solving
13 22 (15.17%) Roadmaps
13 22 (15.17%) SDLC
Programming Languages
1 36 (24.83%) Python
2 11 (7.59%) Go
2 11 (7.59%) Java
3 6 (4.14%) C#
3 6 (4.14%) JavaScript
3 6 (4.14%) SQL
4 5 (3.45%) PowerShell
5 4 (2.76%) Lua
5 4 (2.76%) Ruby
5 4 (2.76%) Rust
6 2 (1.38%) Dart
6 2 (1.38%) Kotlin
6 2 (1.38%) Objective-C
6 2 (1.38%) PHP
6 2 (1.38%) Swift
7 1 (0.69%) C++
Qualifications
1 75 (51.72%) CISSP
2 56 (38.62%) CISM
3 39 (26.90%) AWS Certification
4 38 (26.21%) GIAC
5 27 (18.62%) OSCP
6 25 (17.24%) Degree
7 24 (16.55%) CREST Certified
7 24 (16.55%) Security Cleared
8 23 (15.86%) SC Cleared
9 22 (15.17%) Azure Certification
10 20 (13.79%) CRISC
11 16 (11.03%) ISSMP
12 12 (8.28%) BPSS Clearance
13 10 (6.90%) CISA
14 9 (6.21%) Computer Science Degree
15 8 (5.52%) CEH
15 8 (5.52%) Master's Degree
16 7 (4.83%) (ISC)2 CCSP
16 7 (4.83%) Cisco Certification
16 7 (4.83%) SANS
Quality Assurance & Compliance
1 41 (28.28%) NIST
2 29 (20.00%) ISO/IEC 27001
3 23 (15.86%) COBIT
4 12 (8.28%) PCI DSS
5 7 (4.83%) Cyber Essentials
5 7 (4.83%) QA
5 7 (4.83%) SOC 2
6 6 (4.14%) Web Application Security Consortium
7 5 (3.45%) Cyber Essentials PLUS
7 5 (3.45%) IASME
7 5 (3.45%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
8 4 (2.76%) GDPR
8 4 (2.76%) NCSC
8 4 (2.76%) NIST 800
9 2 (1.38%) HIPAA
9 2 (1.38%) ISO 31000
10 1 (0.69%) GRC
10 1 (0.69%) IEC 61508
System Software
1 20 (13.79%) Active Directory
2 4 (2.76%) Virtual Machines
3 3 (2.07%) Docker
Systems Management
1 18 (12.41%) Kubernetes
2 16 (11.03%) Ansible
3 10 (6.90%) Nessus
4 7 (4.83%) Computer Emergency Response Teams
5 5 (3.45%) Suricata
6 4 (2.76%) Nmap
6 4 (2.76%) Single Sign-On
7 3 (2.07%) HP Fortify
8 2 (1.38%) QRadar
8 2 (1.38%) Terraform
9 1 (0.69%) Anchore
9 1 (0.69%) Computer Incident Response Team
Vendors
1 26 (17.93%) Microsoft
2 16 (11.03%) Alibaba
3 13 (8.97%) Google
4 10 (6.90%) Splunk
5 6 (4.14%) Cisco
5 6 (4.14%) Palo Alto
6 5 (3.45%) Juniper
7 4 (2.76%) Qualys
8 3 (2.07%) Veracode
9 2 (1.38%) Fortinet
9 2 (1.38%) IBM
10 1 (0.69%) Forcepoint
10 1 (0.69%) Intel
10 1 (0.69%) Netskope
10 1 (0.69%) Okta
10 1 (0.69%) Red Hat
10 1 (0.69%) VMware