Hybrid/Remote Penetration Testing Job Trends

Penetration Testing
UK > Work from Home

The table below provides summary statistics and salary benchmarking for remote or hybrid work requiring Penetration Testing skills. It covers permanent job vacancies from the 6 months leading up to 30 May 2026, with comparisons to the same periods in the previous two years.

6 months to
30 May 2026
Same period 2025 Same period 2024
Rank 310 358 364
Rank change year-on-year +48 +6 +13
Permanent jobs citing Penetration Testing 107 75 208
As % of all permanent jobs with remote/hybrid work options 0.56% 0.51% 0.63%
As % of the Processes & Methodologies category 0.67% 0.53% 0.70%
Number of salaries quoted 75 65 183
10th Percentile £43,500 £52,500 £37,500
25th Percentile £48,165 £62,500 £47,500
Median annual salary (50th Percentile) £67,500 £76,000 £60,000
Median % change year-on-year -11.18% +26.67% -11.11%
75th Percentile £97,500 £93,250 £75,625
90th Percentile £110,000 £105,000 £105,000
UK median annual salary £65,000 £67,500 £65,000
% change year-on-year -3.70% +3.85% -

All Process & Methodology Skills
Work from Home

Penetration Testing falls under the Processes and Methodologies category. For comparison with the information above, the following table provides summary statistics for all permanent job vacancies with remote or hybrid options requiring process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 15,885 14,034 29,900
As % of all permanent jobs with a WFH option 82.77% 94.81% 90.07%
Number of salaries quoted 11,369 8,239 23,472
10th Percentile £35,000 £30,450 £33,750
25th Percentile £45,000 £42,500 £42,500
Median annual salary (50th Percentile) £60,000 £60,000 £57,500
Median % change year-on-year - +4.35% -8.00%
75th Percentile £80,000 £80,000 £75,000
90th Percentile £100,000 £105,000 £95,000
UK median annual salary £60,000 £57,610 £55,000
% change year-on-year +4.15% +4.75% -9.69%

Penetration Testing
Job Vacancy Trend for Remote/Hybrid Jobs

Historical trend showing the proportion of permanent IT job postings citing Penetration Testing and offering remote or hybrid work options relative to all permanent IT jobs advertised.

Penetration Testing job vacancy trend for remote/hybrid jobs

Penetration Testing
Salary Trend for Remote/Hybrid Jobs

Salary distribution trend for jobs with remote/hybrid work options citing Penetration Testing.

Salary distribution trend for jobs with remote/hybrid work options citing Penetration Testing

Penetration Testing
Salary Histogram for Remote/Hybrid Jobs

Salary distribution for jobs with remote/hybrid work options citing Penetration Testing over the 6 months to 30 May 2026.

Penetration Testing salary histogram for jobs with remote/hybrid work options

Penetration Testing
Co-Occurring Skills & Capabilities in Remote/Hybrid Jobs by Category

The following tables expand on the one above by listing co-occurrences grouped by category. They cover the same employment type, locality and period, with up to 20 co-occurrences shown in each category:

Application Platforms
1 1 (0.93%) Apache
1 1 (0.93%) Confluence
1 1 (0.93%) Drupal
1 1 (0.93%) IIS
1 1 (0.93%) nginx
1 1 (0.93%) WordPress
Business Applications
1 1 (0.93%) Magento
Cloud Services
1 39 (36.45%) AWS
2 30 (28.04%) Azure
3 20 (18.69%) GCP
4 4 (3.74%) Amazon EKS
4 4 (3.74%) AWS CloudFormation
4 4 (3.74%) Azure DevOps
4 4 (3.74%) Mimecast
4 4 (3.74%) SaaS
5 2 (1.87%) Azure Key Vault
5 2 (1.87%) Entra ID
5 2 (1.87%) Figma
6 1 (0.93%) Amazon EC2
6 1 (0.93%) Amazon ElastiCache
6 1 (0.93%) Amazon S3
6 1 (0.93%) Azure Monitor
6 1 (0.93%) CloudFront
6 1 (0.93%) GitHub
6 1 (0.93%) GitHub Actions
6 1 (0.93%) Microsoft 365
6 1 (0.93%) Virtual Private Cloud
Communications & Networking
1 20 (18.69%) Firewall
2 12 (11.21%) Network Security
3 7 (6.54%) VPN
4 5 (4.67%) Cisco Nexus
5 4 (3.74%) Cisco ISE
5 4 (3.74%) Intrusion Detection
6 3 (2.80%) DMARC
6 3 (2.80%) DNS
6 3 (2.80%) VLAN
7 1 (0.93%) Broadband
7 1 (0.93%) TCP/IP
7 1 (0.93%) Wi-Fi
7 1 (0.93%) Wireless
7 1 (0.93%) Wireshark
Database & Business Intelligence
1 1 (0.93%) Amazon RDS
1 1 (0.93%) InterSystems Cache
1 1 (0.93%) Redis
1 1 (0.93%) SQL Server
Development Applications
1 9 (8.41%) Burp Suite
2 8 (7.48%) Metasploit
3 3 (2.80%) Git
4 2 (1.87%) Bitbucket
4 2 (1.87%) Gatling
4 2 (1.87%) JIRA
4 2 (1.87%) NUnit
5 1 (0.93%) Cucumber
5 1 (0.93%) GitLab
5 1 (0.93%) IDA Disassembler
5 1 (0.93%) JMeter
5 1 (0.93%) JUnit
5 1 (0.93%) Postman
5 1 (0.93%) Selenium
5 1 (0.93%) Vagrant
General
1 47 (43.93%) Social Skills
2 18 (16.82%) Banking
3 17 (15.89%) Law
4 16 (14.95%) Retail
5 14 (13.08%) Public Sector
6 13 (12.15%) Inclusion and Diversity
7 11 (10.28%) Finance
8 4 (3.74%) Analytical Skills
9 3 (2.80%) Back Office
9 3 (2.80%) Financial Institution
9 3 (2.80%) Marketing
10 2 (1.87%) Legal
10 2 (1.87%) Social Housing
11 1 (0.93%) Influencing Skills
11 1 (0.93%) Investment Banking
Job Titles
1 27 (25.23%) Penetration Tester
1 27 (25.23%) Tester
2 16 (14.95%) Consultant
2 16 (14.95%) Security Consultant
2 16 (14.95%) Senior
3 13 (12.15%) Security Specialist
4 10 (9.35%) Security Manager
4 10 (9.35%) Senior Penetration Tester
4 10 (9.35%) Senior Tester
5 9 (8.41%) Cybersecurity Consultant
6 7 (6.54%) Architect
6 7 (6.54%) Client Director
6 7 (6.54%) Services Director
7 6 (5.61%) Cybersecurity Manager
7 6 (5.61%) Head of Professional Services
7 6 (5.61%) Security Penetration Tester
7 6 (5.61%) Security Tester
8 5 (4.67%) Lead
8 5 (4.67%) Solutions Architect
8 5 (4.67%) Threat Intelligence Specialist
Libraries, Frameworks & Software Standards
1 4 (3.74%) .NET
2 3 (2.80%) .NET Framework
2 3 (2.80%) RESTful
3 2 (1.87%) AngularJS
3 2 (1.87%) ASP.NET
3 2 (1.87%) ASP.NET Core
3 2 (1.87%) Entity Framework
3 2 (1.87%) OpenAPI
3 2 (1.87%) RxJS
3 2 (1.87%) Swagger
3 2 (1.87%) Vitest
4 1 (0.93%) ARM Templates
4 1 (0.93%) Memcached
4 1 (0.93%) OAuth
4 1 (0.93%) Playwright
Miscellaneous
1 25 (23.36%) Security Posture
2 16 (14.95%) Mobile App
3 14 (13.08%) Cyber Threat
4 7 (6.54%) Blog
5 6 (5.61%) Self-Motivation
6 5 (4.67%) Cloud Native
6 5 (4.67%) Insider Threat
6 5 (4.67%) Public Cloud
7 4 (3.74%) Cyber Defence
7 4 (3.74%) Data Centre
7 4 (3.74%) Management Information System
7 4 (3.74%) Operational Technology
8 2 (1.87%) Enterprise Software
8 2 (1.87%) Housing Association
9 1 (0.93%) Cyber Kill Chain
9 1 (0.93%) Cyberattack
9 1 (0.93%) Distributed Systems
9 1 (0.93%) Driving Licence
9 1 (0.93%) Social Media
9 1 (0.93%) Web Conferencing
Operating Systems
1 20 (18.69%) Android
1 20 (18.69%) Apple iOS
2 16 (14.95%) Linux
3 15 (14.02%) Windows
4 2 (1.87%) Windows Server
5 1 (0.93%) Kali Linux
5 1 (0.93%) Mac OS
Processes & Methodologies
1 64 (59.81%) Cybersecurity
2 33 (30.84%) Red Team
3 31 (28.97%) Incident Response
4 28 (26.17%) Information Security
5 26 (24.30%) Cloud Security
6 24 (22.43%) Security Testing
7 19 (17.76%) Application Security
7 19 (17.76%) Vulnerability Management
8 18 (16.82%) Offensive Security
9 17 (15.89%) OWASP
10 16 (14.95%) Actionable Insight
10 16 (14.95%) Threat Modelling
11 15 (14.02%) Mentoring
11 15 (14.02%) SIEM
11 15 (14.02%) Test Automation
12 14 (13.08%) CI/CD
12 14 (13.08%) Disaster Recovery
12 14 (13.08%) Risk Management
12 14 (13.08%) Security Architecture
13 13 (12.15%) SDLC
Programming Languages
1 15 (14.02%) Java
2 14 (13.08%) Go
2 14 (13.08%) Python
3 9 (8.41%) PowerShell
4 6 (5.61%) C
4 6 (5.61%) C++
5 5 (4.67%) Bash
5 5 (4.67%) C#
6 4 (3.74%) Perl
6 4 (3.74%) Ruby
7 3 (2.80%) Objective-C
7 3 (2.80%) Rust
8 2 (1.87%) Bicep
8 2 (1.87%) PHP
8 2 (1.87%) SQL
8 2 (1.87%) TypeScript
9 1 (0.93%) JavaScript
Qualifications
1 35 (32.71%) CREST Certified
2 26 (24.30%) OSCP
3 21 (19.63%) Security Cleared
4 17 (15.89%) SC Cleared
5 14 (13.08%) CISSP
6 13 (12.15%) Degree
7 10 (9.35%) CEH
7 10 (9.35%) Cisco Certification
7 10 (9.35%) GPEN
8 8 (7.48%) CCNA
8 8 (7.48%) CHECK Team Member
9 7 (6.54%) GIAC
10 6 (5.61%) CCNP
10 6 (5.61%) CISM
10 6 (5.61%) DV Cleared
11 5 (4.67%) GXPN
11 5 (4.67%) Microsoft Certification
12 4 (3.74%) CISMP
12 4 (3.74%) MCSE
12 4 (3.74%) Microsoft Certified Professional
Quality Assurance & Compliance
1 38 (35.51%) ISO/IEC 27001
2 20 (18.69%) GDPR
3 19 (17.76%) Cyber Essentials
4 17 (15.89%) NIST
5 16 (14.95%) Actionable Recommendations
6 15 (14.02%) PCI DSS
7 10 (9.35%) Cyber Essentials PLUS
7 10 (9.35%) GRC
8 5 (4.67%) NCSC
9 3 (2.80%) Data Quality
10 2 (1.87%) Accessibility
10 2 (1.87%) Def Stans
10 2 (1.87%) NIST 800
10 2 (1.87%) QA
11 1 (0.93%) SOC 2
11 1 (0.93%) WCAG
System Software
1 11 (10.28%) Active Directory
2 2 (1.87%) Docker
Systems Management
1 12 (11.21%) Kubernetes
2 7 (6.54%) Nmap
3 5 (4.67%) Terraform
4 3 (2.80%) CSIRT
4 3 (2.80%) Nessus
5 1 (0.93%) Ansible
5 1 (0.93%) Consul
5 1 (0.93%) Microsoft Intune
5 1 (0.93%) Packer
5 1 (0.93%) Progress Chef
5 1 (0.93%) Puppet
Vendors
1 22 (20.56%) Microsoft
2 9 (8.41%) Cisco
3 7 (6.54%) Fortinet
3 7 (6.54%) Sophos
4 5 (4.67%) Splunk
5 4 (3.74%) CheckPoint
5 4 (3.74%) CrowdStrike
5 4 (3.74%) Okta
5 4 (3.74%) Palo Alto
5 4 (3.74%) Zscaler
6 3 (2.80%) Qualys
6 3 (2.80%) Veeam
7 2 (1.87%) DevExpress
7 2 (1.87%) Google
8 1 (0.93%) Aruba
8 1 (0.93%) New Relic
8 1 (0.93%) SolarWinds
8 1 (0.93%) TOWER Software
8 1 (0.93%) Zerto