Hybrid/Remote Penetration Testing Job Trends

Penetration Testing
UK > Work from Home

The table below provides summary statistics and salary benchmarking for remote or hybrid work requiring Penetration Testing skills. It covers permanent job vacancies from the 6 months leading up to 4 July 2026, with comparisons to the same periods in the previous two years.

6 months to
4 Jul 2026
Same period 2025 Same period 2024
Rank 317 368 389
Rank change year-on-year +51 +21 -31
Permanent jobs citing Penetration Testing 126 68 199
As % of all permanent jobs with remote/hybrid work options 0.60% 0.42% 0.60%
As % of the Processes & Methodologies category 0.73% 0.45% 0.68%
Number of salaries quoted 87 58 177
10th Percentile £45,000 £51,250 £37,500
25th Percentile £48,958 £61,250 £47,500
Median annual salary (50th Percentile) £72,500 £74,000 £60,000
Median % change year-on-year -2.03% +23.33% -7.69%
75th Percentile £90,000 £88,333 £76,250
90th Percentile £108,500 £105,000 £105,000
UK median annual salary £70,000 £67,500 £65,000
% change year-on-year +3.70% +3.85% +4.00%

All Process & Methodology Skills
Work from Home

Penetration Testing falls under the Processes and Methodologies category. For comparison with the information above, the following table provides summary statistics for all permanent job vacancies with remote or hybrid options requiring process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 17,173 15,146 29,476
As % of all permanent jobs with a WFH option 82.44% 93.69% 88.91%
Number of salaries quoted 12,544 8,967 22,622
10th Percentile £35,000 £29,913 £33,750
25th Percentile £45,000 £41,250 £42,500
Median annual salary (50th Percentile) £60,000 £60,000 £57,500
Median % change year-on-year - +4.35% -8.00%
75th Percentile £80,000 £80,000 £75,772
90th Percentile £100,000 £105,000 £95,000
UK median annual salary £60,000 £57,500 £55,000
% change year-on-year +4.35% +4.55% -9.09%

Penetration Testing
Job Vacancy Trend for Remote/Hybrid Jobs

Historical trend showing the proportion of permanent IT job postings citing Penetration Testing and offering remote or hybrid work options relative to all permanent IT jobs advertised.

Penetration Testing job vacancy trend for remote/hybrid jobs

Penetration Testing
Salary Trend for Remote/Hybrid Jobs

Salary distribution trend for jobs with remote/hybrid work options citing Penetration Testing.

Salary distribution trend for jobs with remote/hybrid work options citing Penetration Testing

Penetration Testing
Salary Histogram for Remote/Hybrid Jobs

Salary distribution for jobs with remote/hybrid work options citing Penetration Testing over the 6 months to 4 July 2026.

Penetration Testing salary histogram for jobs with remote/hybrid work options

Penetration Testing
Co-Occurring Skills & Capabilities in Remote/Hybrid Jobs by Category

The following tables expand on the one above by listing co-occurrences grouped by category. They cover the same employment type, locality and period, with up to 20 co-occurrences shown in each category:

Application Platforms
1 1 (0.79%) Apache
1 1 (0.79%) Confluence
1 1 (0.79%) Drupal
1 1 (0.79%) IIS
1 1 (0.79%) nginx
1 1 (0.79%) SharePoint
1 1 (0.79%) WordPress
Business Applications
1 1 (0.79%) Magento
Cloud Services
1 42 (33.33%) AWS
2 39 (30.95%) Azure
3 20 (15.87%) GCP
4 4 (3.17%) Amazon EKS
4 4 (3.17%) AWS CloudFormation
4 4 (3.17%) Azure DevOps
4 4 (3.17%) Microsoft 365
4 4 (3.17%) Mimecast
4 4 (3.17%) SaaS
5 3 (2.38%) Entra ID
6 2 (1.59%) Azure Key Vault
6 2 (1.59%) Figma
7 1 (0.79%) Amazon ECS
7 1 (0.79%) AWS Control Tower
7 1 (0.79%) Azure Monitor
7 1 (0.79%) Azure Sentinel
7 1 (0.79%) GitHub Actions
7 1 (0.79%) Power Automate
7 1 (0.79%) Power Platform
7 1 (0.79%) PowerApps
Communications & Networking
1 35 (27.78%) Firewall
2 13 (10.32%) Cisco Nexus
2 13 (10.32%) Network Security
3 9 (7.14%) Wi-Fi
4 7 (5.56%) VPN
5 4 (3.17%) Cisco ISE
5 4 (3.17%) DNS
5 4 (3.17%) Intrusion Detection
6 3 (2.38%) DMARC
6 3 (2.38%) VLAN
7 2 (1.59%) Broadband
7 2 (1.59%) Wireless
8 1 (0.79%) HTTP
8 1 (0.79%) Internet
8 1 (0.79%) TCP/IP
Database & Business Intelligence
1 1 (0.79%) Amazon RDS
1 1 (0.79%) InterSystems Cache
1 1 (0.79%) Redis
1 1 (0.79%) SQL Server
Development Applications
1 10 (7.94%) Burp Suite
2 9 (7.14%) Metasploit
3 4 (3.17%) JIRA
4 3 (2.38%) Git
5 2 (1.59%) Bitbucket
5 2 (1.59%) Gatling
5 2 (1.59%) NUnit
6 1 (0.79%) Cucumber
6 1 (0.79%) GitLab
6 1 (0.79%) IDA Disassembler
6 1 (0.79%) JMeter
6 1 (0.79%) JUnit
6 1 (0.79%) Postman
6 1 (0.79%) Selenium
6 1 (0.79%) Vagrant
General
1 58 (46.03%) Social Skills
2 16 (12.70%) Banking
3 15 (11.90%) Analytical Skills
3 15 (11.90%) Law
3 15 (11.90%) Public Sector
4 14 (11.11%) Retail
5 13 (10.32%) Finance
6 10 (7.94%) Inclusion and Diversity
7 4 (3.17%) Legal
7 4 (3.17%) Marketing
8 3 (2.38%) Back Office
8 3 (2.38%) Financial Institution
9 2 (1.59%) Social Housing
10 1 (0.79%) Influencing Skills
Job Titles
1 30 (23.81%) Penetration Tester
1 30 (23.81%) Tester
2 26 (20.63%) Senior
3 19 (15.08%) Analyst
4 16 (12.70%) Security Analyst
5 14 (11.11%) Consultant
5 14 (11.11%) Security Consultant
6 13 (10.32%) Cybersecurity Analyst
6 13 (10.32%) Senior Analyst
7 11 (8.73%) Security Manager
8 10 (7.94%) Security Specialist
8 10 (7.94%) Senior Cybersecurity Analyst
8 10 (7.94%) Senior Security Analyst
9 9 (7.14%) Architect
9 9 (7.14%) Network Analyst
9 9 (7.14%) Senior Network Analyst
10 8 (6.35%) Senior Penetration Tester
10 8 (6.35%) Senior Tester
11 7 (5.56%) Cybersecurity Manager
11 7 (5.56%) Services Director
Libraries, Frameworks & Software Standards
1 4 (3.17%) .NET
1 4 (3.17%) RESTful
2 3 (2.38%) .NET Framework
3 2 (1.59%) AngularJS
3 2 (1.59%) ASP.NET
3 2 (1.59%) ASP.NET Core
3 2 (1.59%) Entity Framework
3 2 (1.59%) OpenAPI
3 2 (1.59%) RxJS
3 2 (1.59%) Swagger
3 2 (1.59%) Vitest
4 1 (0.79%) ARM Templates
4 1 (0.79%) Memcached
4 1 (0.79%) OAuth
4 1 (0.79%) Playwright
Miscellaneous
1 35 (27.78%) Security Posture
2 20 (15.87%) Cyber Threat
3 16 (12.70%) Mobile App
4 8 (6.35%) Management Information System
5 7 (5.56%) Blog
5 7 (5.56%) Self-Motivation
6 6 (4.76%) Cloud Native
7 5 (3.97%) Insider Threat
8 4 (3.17%) Cyber Defence
8 4 (3.17%) Public Cloud
9 3 (2.38%) Cyber Kill Chain
9 3 (2.38%) Data Centre
9 3 (2.38%) Operational Technology
10 2 (1.59%) Distributed Systems
10 2 (1.59%) Enterprise Software
10 2 (1.59%) Housing Association
10 2 (1.59%) Security Operations Centre
10 2 (1.59%) Social Media
11 1 (0.79%) Cyberattack
11 1 (0.79%) Web Conferencing
Operating Systems
1 19 (15.08%) Linux
2 18 (14.29%) Windows
3 17 (13.49%) Android
3 17 (13.49%) Apple iOS
4 4 (3.17%) Kali Linux
4 4 (3.17%) Windows Server
5 1 (0.79%) Mac OS
Processes & Methodologies
1 82 (65.08%) Cybersecurity
2 43 (34.13%) Incident Response
3 40 (31.75%) Vulnerability Management
4 32 (25.40%) Information Security
5 31 (24.60%) Red Team
6 30 (23.81%) Cloud Security
7 23 (18.25%) Problem-Solving
7 23 (18.25%) Security Testing
7 23 (18.25%) SIEM
8 19 (15.08%) Threat Modelling
9 18 (14.29%) Disaster Recovery
9 18 (14.29%) Offensive Security
9 18 (14.29%) OWASP
9 18 (14.29%) Risk Management
9 18 (14.29%) Security Architecture
10 17 (13.49%) Threat Intelligence
11 16 (12.70%) Application Security
11 16 (12.70%) Cyber Threat Intelligence
11 16 (12.70%) Mentoring
12 15 (11.90%) CI/CD
Programming Languages
1 19 (15.08%) Python
2 13 (10.32%) Java
2 13 (10.32%) PowerShell
3 12 (9.52%) Go
4 5 (3.97%) C
4 5 (3.97%) C#
4 5 (3.97%) C++
5 4 (3.17%) Bash
5 4 (3.17%) Perl
5 4 (3.17%) Ruby
6 3 (2.38%) Objective-C
6 3 (2.38%) PHP
6 3 (2.38%) Rust
7 2 (1.59%) Bicep
7 2 (1.59%) JavaScript
7 2 (1.59%) SQL
7 2 (1.59%) TypeScript
Qualifications
1 34 (26.98%) CREST Certified
2 31 (24.60%) Security Cleared
3 26 (20.63%) SC Cleared
4 24 (19.05%) OSCP
5 18 (14.29%) CISSP
6 13 (10.32%) CISM
6 13 (10.32%) Degree
7 10 (7.94%) CHECK Team Member
8 9 (7.14%) CEH
8 9 (7.14%) GIAC
9 7 (5.56%) CHECK Team Leader
9 7 (5.56%) Cisco Certification
9 7 (5.56%) DV Cleared
10 6 (4.76%) CCNP
10 6 (4.76%) GPEN
11 5 (3.97%) CCNA
11 5 (3.97%) CCSAS
11 5 (3.97%) CompTIA Security+
11 5 (3.97%) GXPN
12 4 (3.17%) Cyber Scheme
Quality Assurance & Compliance
1 52 (41.27%) ISO/IEC 27001
2 27 (21.43%) NIST
3 25 (19.84%) GDPR
4 21 (16.67%) Cyber Essentials
5 19 (15.08%) PCI DSS
6 13 (10.32%) Actionable Recommendations
7 11 (8.73%) GRC
8 9 (7.14%) Cyber Essentials PLUS
9 7 (5.56%) NCSC
10 4 (3.17%) Def Stans
10 4 (3.17%) NIST 800
11 3 (2.38%) Data Quality
12 2 (1.59%) Accessibility
12 2 (1.59%) QA
13 1 (0.79%) ISO/IEC 42001
13 1 (0.79%) SOC 2
13 1 (0.79%) WCAG
System Software
1 10 (7.94%) Active Directory
2 2 (1.59%) Docker
Systems Management
1 12 (9.52%) Kubernetes
2 8 (6.35%) Nmap
3 5 (3.97%) Terraform
4 3 (2.38%) CSIRT
4 3 (2.38%) Nessus
5 1 (0.79%) Ansible
5 1 (0.79%) Consul
5 1 (0.79%) Microsoft Intune
5 1 (0.79%) OpenVAS
5 1 (0.79%) Packer
5 1 (0.79%) Progress Chef
5 1 (0.79%) Puppet
Vendors
1 26 (20.63%) Microsoft
2 14 (11.11%) Cisco
3 13 (10.32%) Qualys
4 12 (9.52%) Palo Alto
5 9 (7.14%) Aruba
6 7 (5.56%) Fortinet
6 7 (5.56%) Sophos
6 7 (5.56%) Splunk
7 4 (3.17%) CheckPoint
7 4 (3.17%) CrowdStrike
7 4 (3.17%) Okta
7 4 (3.17%) Zscaler
8 3 (2.38%) New Relic
8 3 (2.38%) SolarWinds
8 3 (2.38%) Veeam
8 3 (2.38%) Zerto
9 2 (1.59%) DevExpress
9 2 (1.59%) Google
10 1 (0.79%) Foundry
10 1 (0.79%) TOWER Software