Application Security (AppSec)
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Application Security skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Application Security over the 6 months to 12 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
12 May 2024
Same period 2023 Same period 2022
Rank 509 456 555
Rank change year-on-year -53 +99 -68
Permanent jobs citing Application Security 447 645 923
As % of all permanent jobs advertised in the UK 0.45% 0.64% 0.59%
As % of the Processes & Methodologies category 0.53% 0.67% 0.61%
Number of salaries quoted 302 386 526
10th Percentile £47,750 £37,500 £37,500
25th Percentile £56,809 £55,313 £51,250
Median annual salary (50th Percentile) £75,000 £77,500 £72,500
Median % change year-on-year -3.23% +6.90% +11.54%
75th Percentile £88,750 £94,688 £87,500
90th Percentile £105,000 £111,250 £109,375
UK excluding London median annual salary £65,000 £58,750 £55,000
% change year-on-year +10.64% +6.82% -8.33%

All Process and Methodology Skills
UK

Application Security is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 84,952 96,876 150,957
As % of all permanent jobs advertised in the UK 85.57% 95.60% 95.70%
Number of salaries quoted 59,894 57,115 82,331
10th Percentile £29,002 £34,000 £33,515
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,000 £60,000
Median % change year-on-year -9.84% +1.67% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +9.38%

Application Security
Job Vacancy Trend

Job postings citing Application Security as a proportion of all IT jobs advertised.

Job vacancy trend for Application Security in the UK

Application Security
Salary Trend

3-month moving average salary quoted in jobs citing Application Security.

Salary trend for Application Security in the UK

Application Security
Salary Histogram

Salary distribution for jobs citing Application Security over the 6 months to 12 May 2024.

Salary histogram for Application Security in the UK

Application Security
Top 16 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Application Security within the UK over the 6 months to 12 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -20 401 £75,000 -6.25% 95
London +54 231 £75,000 -14.29% 45
Work from Home +29 201 £72,500 -3.33% 62
UK excluding London -81 182 £65,000 +10.64% 45
North of England +32 66 £67,500 +12.50% 13
South East -17 57 £72,500 +31.82% 15
North West -14 38 £61,206 -5.84% 6
Midlands -12 23 £57,500 -4.17% 6
West Midlands +19 22 £57,500 -13.53% 6
Yorkshire +74 19 £79,842 +22.83% 6
South West -14 19 £75,000 -33.33% 5
Scotland -46 16 £50,000 +9.29% 1
North East +1 9 £62,500 +31.58% 1
Wales +16 2 £65,000 +74.98% 1
East Midlands -13 1 £65,000 +18.18%
East of England -21 1 £60,000 -25.00% 5

Application Security
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 12 (2.68%) SharePoint
2 10 (2.24%) Microsoft Exchange
3 2 (0.45%) Confluence
3 2 (0.45%) IIS
4 1 (0.22%) Apache
4 1 (0.22%) Blackberry Enterprise Server
4 1 (0.22%) Drupal
4 1 (0.22%) nginx
Applications
1 10 (2.24%) Microsoft Office
2 6 (1.34%) Microsoft Excel
Business Applications
1 2 (0.45%) SAP GRC
1 2 (0.45%) SAP S/4HANA
Cloud Services
1 160 (35.79%) Azure
2 111 (24.83%) AWS
3 56 (12.53%) Microsoft 365
4 24 (5.37%) Cloud Computing
4 24 (5.37%) GCP
5 23 (5.15%) SaaS
6 21 (4.70%) Entra ID
7 18 (4.03%) PaaS
8 17 (3.80%) IaaS
9 16 (3.58%) Azure AKS
10 14 (3.13%) Power Platform
11 13 (2.91%) Azure DevOps
12 10 (2.24%) Serverless
13 8 (1.79%) Azure Sentinel
14 6 (1.34%) Azure Service Bus
14 6 (1.34%) Azure Service Fabric
15 4 (0.89%) Azure App Service
15 4 (0.89%) PowerApps
16 3 (0.67%) AWS CodePipeline
16 3 (0.67%) Azure Functions
Communications & Networking
1 102 (22.82%) Firewall
2 77 (17.23%) WAN
3 66 (14.77%) Network Security
4 50 (11.19%) VPN
5 43 (9.62%) Internet
6 42 (9.40%) LAN
7 33 (7.38%) SD-WAN
8 16 (3.58%) Wireless
9 12 (2.68%) Intrusion Detection
10 8 (1.79%) TCP/IP
10 8 (1.79%) Wireshark
11 5 (1.12%) HTTP
12 4 (0.89%) BGP
12 4 (0.89%) Ethernet VPN
12 4 (0.89%) F5 BIG-IP GTM
12 4 (0.89%) F5 BIG-IP LTM
12 4 (0.89%) MPLS
12 4 (0.89%) OSPF
12 4 (0.89%) tcpdump
12 4 (0.89%) Unified Communications
Database & Business Intelligence
1 16 (3.58%) SQL Server
2 10 (2.24%) Relational Database
3 9 (2.01%) Azure SQL Database
4 8 (1.79%) CockroachDB
5 7 (1.57%) NoSQL
5 7 (1.57%) SQL Server Integration Services
5 7 (1.57%) SQL Server Reporting Services
6 4 (0.89%) RDBMS
7 3 (0.67%) Amazon RDS
7 3 (0.67%) Data Lake
7 3 (0.67%) Looker
8 2 (0.45%) Elasticsearch
8 2 (0.45%) MySQL
9 1 (0.22%) Big Data
9 1 (0.22%) Geospatial Data
9 1 (0.22%) PostgreSQL
9 1 (0.22%) Power BI
Development Applications
1 41 (9.17%) Burp Suite
2 36 (8.05%) Metasploit
3 13 (2.91%) Jenkins
4 9 (2.01%) Git
4 9 (2.01%) Sonatype Nexus
5 8 (1.79%) Jaeger
6 6 (1.34%) Selenium
7 5 (1.12%) SoapUI
8 4 (0.89%) Cypress.io
9 3 (0.67%) Moq
9 3 (0.67%) Postman
9 3 (0.67%) SpecFlow
9 3 (0.67%) Visual Studio
10 2 (0.45%) Bitbucket
10 2 (0.45%) JIRA
10 2 (0.45%) WebDriver
11 1 (0.22%) Gradle
11 1 (0.22%) Grunt
11 1 (0.22%) gulp
11 1 (0.22%) Robot Framework
General
1 140 (31.32%) Social Skills
2 103 (23.04%) Finance
3 61 (13.65%) Analytical Skills
4 51 (11.41%) Retail
5 35 (7.83%) Inclusion and Diversity
6 34 (7.61%) Law
7 20 (4.47%) Banking
8 19 (4.25%) Telecoms
9 18 (4.03%) Marketing
10 15 (3.36%) Legal
10 15 (3.36%) Public Sector
11 12 (2.68%) Financial Institution
11 12 (2.68%) Health Technology
12 10 (2.24%) Documentation Skills
12 10 (2.24%) Tech for Good
13 8 (1.79%) Presentation Skills
14 6 (1.34%) Manufacturing
15 5 (1.12%) Influencing Skills
16 2 (0.45%) Investment Banking
16 2 (0.45%) Local Government
Job Titles
1 152 (34.00%) Architect
2 121 (27.07%) Senior
3 89 (19.91%) Security Architect
4 50 (11.19%) Lead
5 46 (10.29%) Penetration Tester
6 45 (10.07%) Tester
7 44 (9.84%) Analyst
8 43 (9.62%) Security Analyst
9 42 (9.40%) Lead Architect
10 39 (8.72%) Security Engineer
11 31 (6.94%) Lead Security Architect
12 25 (5.59%) Consultant
12 25 (5.59%) Senior Analyst
13 24 (5.37%) Senior Security Analyst
14 21 (4.70%) Developer
14 21 (4.70%) Infrastructure Architect
15 20 (4.47%) Senior Architect
16 19 (4.25%) CISSP Analyst
17 16 (3.58%) IT Analyst
17 16 (3.58%) Senior IT Security Analyst
Libraries, Frameworks & Software Standards
1 24 (5.37%) OAuth
2 19 (4.25%) Web Services
3 17 (3.80%) REST
4 14 (3.13%) .NET
4 14 (3.13%) SAML
5 13 (2.91%) HTML
6 12 (2.68%) Middleware
6 12 (2.68%) React
6 12 (2.68%) RESTful
7 11 (2.46%) SailPoint
8 10 (2.24%) CSS
9 9 (2.01%) .NET Framework
9 9 (2.01%) Entity Framework
9 9 (2.01%) Kafka
9 9 (2.01%) Vue
10 8 (1.79%) OAuth2
10 8 (1.79%) OpenTelemetry
10 8 (1.79%) Spring Boot
11 7 (1.57%) HTML5
11 7 (1.57%) web3js
Miscellaneous
1 81 (18.12%) Management Information System
2 48 (10.74%) Distributed Denial-of-Service
3 25 (5.59%) Security Posture
4 23 (5.15%) PKI
5 20 (4.47%) Public Cloud
6 19 (4.25%) Self-Motivation
7 14 (3.13%) Cyber Threat
7 14 (3.13%) Data Centre
7 14 (3.13%) Distributed Systems
7 14 (3.13%) Greenfield Project
8 13 (2.91%) Cloud Native
9 12 (2.68%) Mobile App
9 12 (2.68%) Replication
10 10 (2.24%) Product Ownership
10 10 (2.24%) Robotics
11 8 (1.79%) Hybrid Cloud
12 7 (1.57%) Blockchain
12 7 (1.57%) Web3
13 4 (0.89%) IoT
14 3 (0.67%) Data Structures
Operating Systems
1 84 (18.79%) Linux
2 69 (15.44%) Windows
3 35 (7.83%) Ubuntu
3 35 (7.83%) VMS
4 33 (7.38%) Kali Linux
5 19 (4.25%) Windows Server
6 8 (1.79%) Android
6 8 (1.79%) Apple iOS
7 2 (0.45%) Unix
7 2 (0.45%) Windows 10
8 1 (0.22%) Red Hat Enterprise Linux
8 1 (0.22%) Windows Server 2019
Processes & Methodologies
1 178 (39.82%) Cybersecurity
2 144 (32.21%) Information Security
3 108 (24.16%) OWASP
4 101 (22.60%) DevSecOps
5 96 (21.48%) Penetration Testing
6 93 (20.81%) Problem-Solving
7 87 (19.46%) Computer Science
8 85 (19.02%) Security Architecture
9 84 (18.79%) Cloud Security
10 82 (18.34%) CI/CD
11 67 (14.99%) Agile
12 65 (14.54%) Security Testing
13 63 (14.09%) DevOps
14 60 (13.42%) Vulnerability Management
15 58 (12.98%) SIEM
16 57 (12.75%) Secure Coding
17 54 (12.08%) Identity Access Management
18 52 (11.63%) Security Operations
19 48 (10.74%) Threat Modelling
20 46 (10.29%) Identity Management
Programming Languages
1 51 (11.41%) SQL
2 38 (8.50%) Python
3 28 (6.26%) JavaScript
3 28 (6.26%) PowerShell
4 27 (6.04%) Java
5 16 (3.58%) C#
6 10 (2.24%) Kusto Query Language
7 9 (2.01%) TypeScript
8 8 (1.79%) Go
8 8 (1.79%) R
9 7 (1.57%) C
9 7 (1.57%) T-SQL
10 5 (1.12%) Scala
11 4 (0.89%) Bash
12 3 (0.67%) C++
12 3 (0.67%) PHP
12 3 (0.67%) Ruby
13 2 (0.45%) Kotlin
13 2 (0.45%) Lua
13 2 (0.45%) Objective-C
Qualifications
1 132 (29.53%) CISSP
2 119 (26.62%) Degree
3 82 (18.34%) CISM
4 59 (13.20%) Computer Science Degree
5 58 (12.98%) Cisco Certification
6 57 (12.75%) Security Cleared
7 54 (12.08%) (ISC)2 CCSP
8 53 (11.86%) CCSP
9 49 (10.96%) Azure Certification
10 45 (10.07%) AWS Certification
11 41 (9.17%) DV Cleared
12 33 (7.38%) CCSK
13 19 (4.25%) OSCP
14 18 (4.03%) CREST Certified
14 18 (4.03%) GIAC
15 17 (3.80%) SANS
15 17 (3.80%) SC Cleared
16 16 (3.58%) AWS Certified Cloud Practitioner
17 14 (3.13%) PCI QSA
18 13 (2.91%) Microsoft Certification
Quality Assurance & Compliance
1 98 (21.92%) NIST
2 41 (9.17%) ISO/IEC 27001
3 24 (5.37%) GRC
3 24 (5.37%) PCI DSS
4 18 (4.03%) GDPR
5 17 (3.80%) SOC 2
6 13 (2.91%) COBIT
6 13 (2.91%) Cyber Essentials
7 9 (2.01%) NCSC
7 9 (2.01%) NIST 800
8 6 (1.34%) Accessibility
8 6 (1.34%) Actionable Recommendations
8 6 (1.34%) Web Application Security Consortium
9 5 (1.12%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
9 5 (1.12%) QA
9 5 (1.12%) SLA
10 4 (0.89%) Cyber Essentials PLUS
10 4 (0.89%) WCAG
11 3 (0.67%) HIPAA
11 3 (0.67%) ISO 31000
System Software
1 62 (13.87%) Active Directory
2 60 (13.42%) Docker
3 13 (2.91%) VMware Infrastructure
4 9 (2.01%) Hyper-V
5 4 (0.89%) Microsoft Virtual Server
5 4 (0.89%) Virtual Servers
6 3 (0.67%) VMware ESXi
7 2 (0.45%) Virtual Machines
8 1 (0.22%) vSphere
Systems Management
1 85 (19.02%) Kubernetes
2 57 (12.75%) Terraform
3 48 (10.74%) Ansible
4 46 (10.29%) Single Sign-On
5 12 (2.68%) Computer Emergency Response Teams
6 8 (1.79%) Kiali
6 8 (1.79%) Microsoft Intune
6 8 (1.79%) Nessus
6 8 (1.79%) Nmap
7 5 (1.12%) Suricata
8 4 (0.89%) CSIRT
9 3 (0.67%) HP Fortify
9 3 (0.67%) QRadar
9 3 (0.67%) vCenter Server
10 1 (0.22%) CASB
10 1 (0.22%) WMI
10 1 (0.22%) WSUS
Vendors
1 98 (21.92%) Microsoft
2 18 (4.03%) Splunk
3 14 (3.13%) VMware
4 13 (2.91%) CyberArk
5 11 (2.46%) BeyondTrust
5 11 (2.46%) ServiceNow
6 10 (2.24%) Qualys
7 8 (1.79%) AppDynamics
7 8 (1.79%) Juniper
8 7 (1.57%) Cisco
9 5 (1.12%) F5
9 5 (1.12%) Palo Alto
10 4 (0.89%) Google
10 4 (0.89%) OpenAI
11 3 (0.67%) IBM
11 3 (0.67%) Oracle
11 3 (0.67%) SAP
11 3 (0.67%) Veracode
12 2 (0.45%) Alibaba
12 2 (0.45%) Darktrace