Penetration Testing Contracts

Penetration Testing
UK

The following table provides summary statistics for contract job vacancies with a requirement for Penetration Testing skills. Included is a benchmarking guide to the contractor rates offered in vacancies that have cited Penetration Testing over the 6 months to 29 April 2024 with a comparison to the same period in the previous 2 years.

6 months to
29 Apr 2024
Same period 2023 Same period 2022
Rank 360 466 557
Rank change year-on-year +106 +91 -63
Contract jobs citing Penetration Testing 250 251 307
As % of all contract jobs advertised in the UK 0.57% 0.42% 0.35%
As % of the Processes & Methodologies category 0.66% 0.47% 0.38%
Number of daily rates quoted 155 156 198
10th Percentile £425 £450 £371
25th Percentile £506 £500 £500
Median daily rate (50th Percentile) £588 £600 £575
Median % change year-on-year -2.08% +4.35% +5.26%
75th Percentile £675 £700 £650
90th Percentile £750 £799 £707
UK excluding London median daily rate £537 £560 £579
% change year-on-year -4.20% -3.24% +19.33%
Number of hourly rates quoted 1 1 0
10th Percentile - - -
25th Percentile £81.75 - -
Median hourly rate £83.50 £80.00 -
Median % change year-on-year +4.38% - -
75th Percentile £85.25 - -
90th Percentile - - -
UK excluding London median hourly rate £83.50 - -

All Process and Methodology Skills
UK

Penetration Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all contract job vacancies with a requirement for process or methodology skills.

Contract vacancies with a requirement for process or methodology skills 37,621 53,662 80,392
As % of all contract IT jobs advertised in the UK 86.30% 89.91% 90.59%
Number of daily rates quoted 24,254 37,244 56,449
10th Percentile £300 £325 £340
25th Percentile £413 £438 £425
Median daily rate (50th Percentile) £525 £550 £525
Median % change year-on-year -4.55% +4.76% +7.69%
75th Percentile £638 £650 £638
90th Percentile £750 £750 £738
UK excluding London median daily rate £500 £500 £475
% change year-on-year - +5.26% +9.20%
Number of hourly rates quoted 2,437 1,746 1,925
10th Percentile £12.75 £11.00 £12.50
25th Percentile £16.00 £16.25 £15.25
Median hourly rate £35.50 £37.30 £25.00
Median % change year-on-year -4.83% +49.20% -
75th Percentile £59.95 £65.00 £49.25
90th Percentile £72.50 £75.00 £64.32
UK excluding London median hourly rate £36.50 £36.00 £20.00
% change year-on-year +1.39% +80.00% -7.24%

Penetration Testing
Job Vacancy Trend

Job postings citing Penetration Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Penetration Testing in the UK

Penetration Testing
Contractor Daily Rate Trend

3-month moving average daily rate quoted in jobs citing Penetration Testing.

Daily rate trend for Penetration Testing in the UK

Penetration Testing
Daily Rate Histogram

Daily rate distribution for jobs citing Penetration Testing over the 6 months to 29 April 2024.

Daily rate histogram for Penetration Testing in the UK

Penetration Testing
Contractor Hourly Rate Trend

3-month moving average hourly rates quoted in jobs citing Penetration Testing.

Hourly rate trend for Penetration Testing in the UK

Penetration Testing
Top 16 Contract Locations

The table below looks at the demand and provides a guide to the median contractor rates quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 29 April 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Contract
IT Job Ads
Median
Daily Rate
Past 6 Months
Median Daily Rate
% Change
on Same Period
Last Year
Live
Jobs
England +85 211 £590 +2.61% 123
UK excluding London +97 117 £537 -4.20% 68
Work from Home +137 114 £600 - 64
London +64 102 £590 -1.67% 50
South East +35 39 £530 -7.42% 22
North of England +32 25 £650 +23.81% 10
South West +23 22 £525 -10.64% 17
North West +32 19 £666 +26.86% 5
Scotland +49 17 £515 - 1
Midlands +20 11 £550 -16.98% 9
East of England +12 8 £700 +16.67% 3
West Midlands +21 7 £650 -1.89% 3
Yorkshire +16 4 £650 +23.81% 4
East Midlands - 4 £400 - 6
North East - 2 £625 - 1
Wales - 1 £363 - 3

Penetration Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 5 (2.00%) Confluence
2 4 (1.60%) IIS
2 4 (1.60%) JBoss
2 4 (1.60%) SharePoint
Applications
1 7 (2.80%) Microsoft Excel
2 5 (2.00%) Microsoft PowerPoint
2 5 (2.00%) Spreadsheet
3 1 (0.40%) Microsoft Office
Business Applications
1 3 (1.20%) Dynamics GP
Cloud Services
1 39 (15.60%) Azure
1 39 (15.60%) SaaS
2 33 (13.20%) PaaS
3 31 (12.40%) IaaS
4 27 (10.80%) AWS
5 12 (4.80%) GCP
6 7 (2.80%) Azure DevOps
7 6 (2.40%) Azure Sentinel
8 5 (2.00%) CloudFront
8 5 (2.00%) Entra ID
8 5 (2.00%) Virtual Private Cloud
9 4 (1.60%) Power Platform
10 3 (1.20%) GitHub
10 3 (1.20%) GitHub Actions
10 3 (1.20%) Microsoft 365
11 2 (0.80%) AWS CloudFormation
12 1 (0.40%) Amazon GuardDuty
12 1 (0.40%) Cloud Functions
12 1 (0.40%) Cloudflare
12 1 (0.40%) Dynamics 365
Communications & Networking
1 55 (22.00%) Firewall
2 38 (15.20%) Network Security
3 32 (12.80%) 5G
4 31 (12.40%) Broadband
5 17 (6.80%) Wireless
6 12 (4.80%) Intrusion Detection
6 12 (4.80%) WAN
7 11 (4.40%) SD-WAN
8 7 (2.80%) DNS
8 7 (2.80%) TCP/IP
8 7 (2.80%) VPN
9 5 (2.00%) Cisco ISE
9 5 (2.00%) tcpdump
9 5 (2.00%) Wireshark
10 3 (1.20%) NGFW
10 3 (1.20%) SSL
11 2 (0.80%) DHCP
11 2 (0.80%) Internet
12 1 (0.40%) FTP
12 1 (0.40%) HTTP
Database & Business Intelligence
1 4 (1.60%) Apache Hive
1 4 (1.60%) DB2
1 4 (1.60%) Hadoop
1 4 (1.60%) Tableau
2 1 (0.40%) Oracle Database
2 1 (0.40%) Oracle Exadata
Development Applications
1 17 (6.80%) Jenkins
2 12 (4.80%) Burp Suite
3 11 (4.40%) GitLab
4 6 (2.40%) JIRA
5 4 (1.60%) IDA Disassembler
5 4 (1.60%) TeamCity
5 4 (1.60%) Vagrant
6 3 (1.20%) Metasploit
7 1 (0.40%) CircleCI
General
1 53 (21.20%) Finance
2 44 (17.60%) Social Skills
3 34 (13.60%) Public Sector
4 32 (12.80%) Analytical Skills
4 32 (12.80%) Law
5 31 (12.40%) Organisational Skills
6 30 (12.00%) Banking
7 9 (3.60%) Retail
8 6 (2.40%) Manufacturing
9 5 (2.00%) Legal
10 4 (1.60%) Presentation Skills
11 3 (1.20%) Automotive
12 2 (0.80%) Electronics
12 2 (0.80%) Multimedia
13 1 (0.40%) Marketing
13 1 (0.40%) Spanish Language
Job Titles
1 49 (19.60%) Penetration Tester
1 49 (19.60%) Tester
2 37 (14.80%) Security Specialist
3 36 (14.40%) Architect
4 32 (12.80%) Security Architect
5 31 (12.40%) Security Penetration Tester
5 31 (12.40%) Security Tester
5 31 (12.40%) Testing Specialist
6 28 (11.20%) Consultant
7 26 (10.40%) Analyst
7 26 (10.40%) Security Engineer
8 24 (9.60%) Security Consultant
9 20 (8.00%) Senior
10 16 (6.40%) Security Analyst
11 15 (6.00%) Infrastructure Engineer
12 14 (5.60%) Network Engineer
13 12 (4.80%) Cybersecurity Analyst
14 11 (4.40%) Network Infrastructure Engineer
15 8 (3.20%) SC Cleared Network Engineer
15 8 (3.20%) Security Manager
Libraries, Frameworks & Software Standards
1 31 (12.40%) Web Services
2 5 (2.00%) OAuth
2 5 (2.00%) OAuth2
2 5 (2.00%) SAML
3 4 (1.60%) OLE
4 1 (0.40%) EDI
4 1 (0.40%) RESTful
Miscellaneous
1 50 (20.00%) Mobile App
2 24 (9.60%) Cyber Threat
3 22 (8.80%) Security Posture
4 16 (6.40%) Data Centre
5 15 (6.00%) Private Cloud
6 14 (5.60%) Management Information System
6 14 (5.60%) PKI
7 11 (4.40%) Security Operations Centre
8 9 (3.60%) Operational Technology
9 8 (3.20%) Cloud Native
10 6 (2.40%) Cyber Defence
11 5 (2.00%) Cyber Kill Chain
11 5 (2.00%) IoT
12 4 (1.60%) Hybrid Cloud
12 4 (1.60%) YARA
13 3 (1.20%) Cyberattack
13 3 (1.20%) Renewable Energy
14 2 (0.80%) Algorithms
14 2 (0.80%) Cloud Security Posture
14 2 (0.80%) Public Cloud
Operating Systems
1 48 (19.20%) Windows
2 41 (16.40%) Linux
3 10 (4.00%) Kali Linux
4 6 (2.40%) Unix
5 5 (2.00%) Windows Server
6 4 (1.60%) AIX
6 4 (1.60%) Solaris
7 1 (0.40%) Mac OS X
Processes & Methodologies
1 140 (56.00%) Cybersecurity
2 69 (27.60%) Application Security
3 67 (26.80%) Information Security
4 53 (21.20%) MITRE ATT&CK
5 52 (20.80%) Security Testing
6 49 (19.60%) OWASP
7 47 (18.80%) Cloud Security
7 47 (18.80%) Stakeholder Management
8 41 (16.40%) SIEM
9 36 (14.40%) Security Operations
9 36 (14.40%) Vulnerability Scanning
10 35 (14.00%) DevOps
11 34 (13.60%) DevSecOps
11 34 (13.60%) Incident Response
11 34 (13.60%) Threat Modelling
12 32 (12.80%) Problem-Solving
12 32 (12.80%) Vulnerability Assessment
12 32 (12.80%) Vulnerability Management
13 31 (12.40%) Red Team
14 30 (12.00%) CI/CD
Programming Languages
1 27 (10.80%) Python
2 13 (5.20%) Kusto Query Language
3 10 (4.00%) C++
4 8 (3.20%) C#
5 7 (2.80%) Go
5 7 (2.80%) JavaScript
5 7 (2.80%) PowerShell
6 4 (1.60%) Perl
6 4 (1.60%) Search Processing Language
6 4 (1.60%) SQL
7 3 (1.20%) C
7 3 (1.20%) Java
7 3 (1.20%) Shell Script
8 2 (0.80%) Ruby
9 1 (0.40%) Bash
Qualifications
1 85 (34.00%) Security Cleared
2 57 (22.80%) OSCP
3 52 (20.80%) CREST Certified
4 51 (20.40%) SC Cleared
5 46 (18.40%) GIAC
6 42 (16.80%) GPEN
7 32 (12.80%) SANS
8 29 (11.60%) Degree
9 15 (6.00%) CISSP
9 15 (6.00%) Computer Science Degree
10 14 (5.60%) CEH
11 12 (4.80%) CISM
12 7 (2.80%) CHECK Team Leader
12 7 (2.80%) CompTIA Security+
13 5 (2.00%) AWS Certification
13 5 (2.00%) DV Cleared
13 5 (2.00%) MCSE
13 5 (2.00%) Microsoft Certification
14 4 (1.60%) Cisco Certification
14 4 (1.60%) ITIL Certification
Quality Assurance & Compliance
1 50 (20.00%) ISO/IEC 27001
2 49 (19.60%) NIST
3 46 (18.40%) GDPR
3 46 (18.40%) PCI DSS
4 36 (14.40%) NCSC
5 12 (4.80%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
6 9 (3.60%) HMG Security Policy Framework
7 7 (2.80%) QA
8 5 (2.00%) COBIT
8 5 (2.00%) HIPAA
8 5 (2.00%) PMO
9 4 (1.60%) Disclosure Scotland
9 4 (1.60%) SLA
10 2 (0.80%) Automotive SPICE
10 2 (0.80%) AUTOSAR
10 2 (0.80%) Cyber Essentials
10 2 (0.80%) ISO 22301
10 2 (0.80%) Sarbanes-Oxley
11 1 (0.40%) Actionable Recommendations
11 1 (0.40%) Cyber Essentials PLUS
System Software
1 16 (6.40%) Active Directory
1 16 (6.40%) VMware Infrastructure
2 14 (5.60%) vSphere
3 5 (2.00%) Docker
3 5 (2.00%) Snort
4 3 (1.20%) Hyper-V
5 1 (0.40%) Terminal Services
Systems Management
1 20 (8.00%) Terraform
2 13 (5.20%) vCenter Server
3 6 (2.40%) Nessus
4 4 (1.60%) Kibana
4 4 (1.60%) Tivoli
5 3 (1.20%) SCCM
6 2 (0.80%) Ansible
6 2 (0.80%) CASB
6 2 (0.80%) HP Fortify
6 2 (0.80%) Kubernetes
7 1 (0.40%) Computer Emergency Response Teams
7 1 (0.40%) CSIRT
7 1 (0.40%) Microsoft Intune
7 1 (0.40%) Nmap
7 1 (0.40%) Single Sign-On
Vendors
1 33 (13.20%) Microsoft
2 31 (12.40%) Virgin Media
3 17 (6.80%) VMware
4 15 (6.00%) Google
5 9 (3.60%) Cisco
5 9 (3.60%) Splunk
6 6 (2.40%) Qualys
7 5 (2.00%) F5
7 5 (2.00%) Oracle
7 5 (2.00%) SAP
8 4 (1.60%) AppDynamics
8 4 (1.60%) CheckPoint
8 4 (1.60%) IBM
9 3 (1.20%) Tufin
9 3 (1.20%) Zscaler
10 2 (0.80%) Palo Alto
10 2 (0.80%) Remedy
11 1 (0.40%) Barracuda Networks
11 1 (0.40%) Imperva
11 1 (0.40%) Salesforce