Penetration Testing
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Penetration Testing skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Penetration Testing over the 6 months to 14 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
14 May 2024
Same period 2023 Same period 2022
Rank 459 468 562
Rank change year-on-year +9 +94 -134
Permanent jobs citing Penetration Testing 509 624 926
As % of all permanent jobs advertised in the UK 0.51% 0.62% 0.58%
As % of the Processes & Methodologies category 0.60% 0.65% 0.61%
Number of salaries quoted 402 419 636
10th Percentile £38,987 £43,477 £37,286
25th Percentile £47,500 £50,070 £51,188
Median annual salary (50th Percentile) £65,000 £67,500 £60,569
Median % change year-on-year -3.70% +11.44% +0.95%
75th Percentile £82,500 £90,000 £77,813
90th Percentile £95,000 £103,750 £90,000
UK excluding London median annual salary £55,000 £55,000 £60,000
% change year-on-year - -8.33% +9.09%

All Process and Methodology Skills
UK

Penetration Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 84,701 95,929 153,018
As % of all permanent jobs advertised in the UK 85.52% 95.60% 95.73%
Number of salaries quoted 59,701 56,502 82,944
10th Percentile £29,000 £34,000 £33,740
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,180 £60,000
Median % change year-on-year -10.10% +1.97% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +9.38%

Penetration Testing
Job Vacancy Trend

Job postings citing Penetration Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Penetration Testing in the UK

Penetration Testing
Salary Trend

3-month moving average salary quoted in jobs citing Penetration Testing.

Salary trend for Penetration Testing in the UK

Penetration Testing
Salary Histogram

Salary distribution for jobs citing Penetration Testing over the 6 months to 14 May 2024.

Salary histogram for Penetration Testing in the UK

Penetration Testing
Top 16 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 14 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England +28 461 £65,000 -3.70% 126
UK excluding London -60 234 £55,000 - 82
London +69 225 £72,500 -11.51% 49
Work from Home -23 210 £60,000 -11.11% 77
South East -3 65 £43,750 -37.50% 18
Midlands +1 53 £55,000 -8.33% 12
North of England +12 49 £57,500 +9.52% 20
South West -13 48 £62,500 +22.55% 18
North West +11 37 £60,000 +12.15% 12
West Midlands -13 31 £55,000 -8.33% 10
East Midlands -1 22 £65,000 - 2
Yorkshire +63 12 £44,250 -13.85% 6
East of England -9 8 £41,250 -25.00%
Scotland -73 7 £60,000 +7.75% 9
Wales +9 3 £90,000 +55.17% 3
Channel Islands - 1 £100,000 -

Penetration Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 4 (0.79%) Microsoft Exchange
2 3 (0.59%) SharePoint
3 1 (0.20%) Apache
3 1 (0.20%) Confluence
3 1 (0.20%) IIS
3 1 (0.20%) WebSphere
Applications
1 3 (0.59%) Microsoft Office
Business Applications
1 1 (0.20%) Remedy ITSM
Cloud Services
1 110 (21.61%) Azure
2 79 (15.52%) AWS
3 50 (9.82%) Microsoft 365
4 27 (5.30%) GCP
5 22 (4.32%) Cloud Computing
6 11 (2.16%) Google Workspace
7 10 (1.96%) Entra ID
8 9 (1.77%) SaaS
9 8 (1.57%) Amazon ECS
9 8 (1.57%) Cloudflare
9 8 (1.57%) PaaS
10 7 (1.38%) Dynamics 365
10 7 (1.38%) IaaS
11 6 (1.18%) Azure Sentinel
12 5 (0.98%) Azure DevOps
13 4 (0.79%) Azure Service Bus
13 4 (0.79%) Mimecast
14 3 (0.59%) Azure Synapse Analytics
14 3 (0.59%) Power Platform
14 3 (0.59%) PowerApps
Communications & Networking
1 125 (24.56%) Firewall
2 74 (14.54%) Network Security
3 40 (7.86%) Wireless
4 32 (6.29%) DNS
5 30 (5.89%) Intrusion Detection
6 18 (3.54%) Wi-Fi
7 16 (3.14%) TCP/IP
8 14 (2.75%) VPN
9 11 (2.16%) Broadband
9 11 (2.16%) NAS
10 10 (1.96%) Internet
10 10 (1.96%) Wireshark
11 9 (1.77%) SSL
12 7 (1.38%) LAN
13 6 (1.18%) BGP
13 6 (1.18%) WAN
14 5 (0.98%) HTTP
14 5 (0.98%) NGFW
14 5 (0.98%) OSPF
14 5 (0.98%) VLAN
Database & Business Intelligence
1 10 (1.96%) SQL Server
2 6 (1.18%) MongoDB
2 6 (1.18%) NoSQL
3 4 (0.79%) InfluxDB
4 3 (0.59%) Data Lake
5 2 (0.39%) Azure SQL Database
6 1 (0.20%) Redis
Development Applications
1 40 (7.86%) Metasploit
2 39 (7.66%) Burp Suite
3 9 (1.77%) Jenkins
4 8 (1.57%) Git
5 6 (1.18%) JIRA
6 5 (0.98%) Postman
7 4 (0.79%) JMeter
7 4 (0.79%) SoapUI
8 3 (0.59%) Cucumber
8 3 (0.59%) SpecFlow
9 2 (0.39%) Bitbucket
9 2 (0.39%) Selenium
10 1 (0.20%) GitLab
10 1 (0.20%) Snyk
General
1 160 (31.43%) Social Skills
2 92 (18.07%) Analytical Skills
3 73 (14.34%) Finance
4 47 (9.23%) Legal
5 33 (6.48%) Law
6 30 (5.89%) Retail
7 29 (5.70%) Presentation Skills
8 26 (5.11%) Telecoms
9 25 (4.91%) Games
10 23 (4.52%) Banking
11 21 (4.13%) Aerospace
12 20 (3.93%) Inclusion and Diversity
13 19 (3.73%) Marketing
14 18 (3.54%) Public Sector
15 14 (2.75%) Influencing Skills
15 14 (2.75%) Military
16 8 (1.57%) Manufacturing
17 7 (1.38%) Automotive
17 7 (1.38%) Aviation
17 7 (1.38%) Pharmaceutical
Job Titles
1 131 (25.74%) Penetration Tester
1 131 (25.74%) Tester
2 71 (13.95%) Analyst
3 67 (13.16%) Lead
3 67 (13.16%) Senior
4 53 (10.41%) Security Analyst
5 37 (7.27%) Consultant
5 37 (7.27%) Security Engineer
6 32 (6.29%) Security Manager
6 32 (6.29%) Team Leader
7 24 (4.72%) Architect
7 24 (4.72%) Security Consultant
8 23 (4.52%) Cybersecurity Analyst
8 23 (4.52%) Senior Penetration Tester
8 23 (4.52%) Senior Tester
9 21 (4.13%) Test Team Leader
10 20 (3.93%) Security Tester
11 19 (3.73%) Security Architect
11 19 (3.73%) Security Penetration Tester
12 18 (3.54%) Cybersecurity Manager
Libraries, Frameworks & Software Standards
1 14 (2.75%) OAuth
2 12 (2.36%) OAuth2
3 8 (1.57%) Laravel
4 6 (1.18%) Web Services
5 4 (0.79%) EDI
5 4 (0.79%) OpenID
5 4 (0.79%) SOAP
5 4 (0.79%) XML
6 3 (0.59%) RESTful
6 3 (0.59%) WPF
7 2 (0.39%) Kafka
7 2 (0.39%) SAML
8 1 (0.20%) .NET
8 1 (0.20%) HTML
8 1 (0.20%) JSON
8 1 (0.20%) React
8 1 (0.20%) SignalR
8 1 (0.20%) Spring
8 1 (0.20%) Spring Boot
8 1 (0.20%) YAML
Miscellaneous
1 55 (10.81%) Cyber Threat
2 45 (8.84%) Security Posture
3 44 (8.64%) Management Information System
4 36 (7.07%) Cyberattack
5 28 (5.50%) Mobile App
6 26 (5.11%) Onboarding
7 23 (4.52%) Self-Motivation
8 20 (3.93%) Operational Technology
9 15 (2.95%) Data Centre
10 14 (2.75%) Cyber Defence
10 14 (2.75%) IoT
11 13 (2.55%) Hybrid Cloud
12 11 (2.16%) Video Conferencing
13 10 (1.96%) Distributed Denial-of-Service
14 8 (1.57%) Cyber Security Posture
15 7 (1.38%) Analytical Mindset
15 7 (1.38%) Data Protection Act
16 6 (1.18%) Embedded Systems
17 5 (0.98%) Algorithms
17 5 (0.98%) Data Structures
Operating Systems
1 72 (14.15%) Windows
2 60 (11.79%) Linux
3 42 (8.25%) Kali Linux
4 25 (4.91%) Apple iOS
5 24 (4.72%) Android
6 22 (4.32%) Windows Server
7 16 (3.14%) Unix
8 12 (2.36%) Mac OS
9 3 (0.59%) Mac OS X
10 2 (0.39%) AIX
10 2 (0.39%) Red Hat Enterprise Linux
10 2 (0.39%) Windows 10
11 1 (0.20%) VMS
11 1 (0.20%) Windows Server 2012
11 1 (0.20%) Windows Server 2016
11 1 (0.20%) Windows XP
Processes & Methodologies
1 371 (72.89%) Cybersecurity
2 152 (29.86%) Information Security
3 118 (23.18%) Computer Science
4 115 (22.59%) Problem-Solving
5 104 (20.43%) Incident Response
6 94 (18.47%) Application Security
7 91 (17.88%) Vulnerability Scanning
8 87 (17.09%) Red Team
9 83 (16.31%) Security Testing
10 70 (13.75%) SIEM
11 67 (13.16%) Vulnerability Management
12 62 (12.18%) Mentoring
13 59 (11.59%) Vulnerability Assessment
14 55 (10.81%) OWASP
15 52 (10.22%) Security Operations
16 46 (9.04%) Patch Management
16 46 (9.04%) Risk Management
17 43 (8.45%) Data Protection
18 42 (8.25%) Malware Analysis
18 42 (8.25%) Reverse Engineering
Programming Languages
1 50 (9.82%) Python
2 32 (6.29%) Bash
3 14 (2.75%) Java
4 13 (2.55%) PowerShell
5 12 (2.36%) SQL
6 8 (1.57%) PHP
6 8 (1.57%) Rust
7 7 (1.38%) C#
7 7 (1.38%) Go
7 7 (1.38%) JavaScript
8 2 (0.39%) Ruby
9 1 (0.20%) Bicep
9 1 (0.20%) C++
9 1 (0.20%) TypeScript
Qualifications
1 124 (24.36%) Degree
2 105 (20.63%) CISSP
3 86 (16.90%) CREST Certified
4 69 (13.56%) OSCP
5 67 (13.16%) Computer Science Degree
6 61 (11.98%) CISM
7 46 (9.04%) Security Cleared
8 38 (7.47%) SC Cleared
9 36 (7.07%) CEH
9 36 (7.07%) CompTIA Security+
10 32 (6.29%) GIAC
11 31 (6.09%) CHECK Team Member
12 29 (5.70%) CISA
13 24 (4.72%) CHECK Team Leader
14 23 (4.52%) CompTIA CySA+
15 22 (4.32%) Cisco Certification
16 18 (3.54%) GPEN
17 16 (3.14%) Network+ Certification
18 14 (2.75%) Cyber Scheme
19 12 (2.36%) (ISC)2 CCSP
Quality Assurance & Compliance
1 101 (19.84%) ISO/IEC 27001
2 61 (11.98%) NIST
3 56 (11.00%) Cyber Essentials
4 30 (5.89%) GRC
5 27 (5.30%) Cyber Essentials PLUS
6 26 (5.11%) GDPR
6 26 (5.11%) PCI DSS
7 24 (4.72%) QA
8 23 (4.52%) SOC 2
9 9 (1.77%) NCSC
10 8 (1.57%) NIST 800
11 7 (1.38%) Actionable Recommendations
11 7 (1.38%) DO-254
12 6 (1.18%) COBIT
12 6 (1.18%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
13 5 (0.98%) HIPAA
14 4 (0.79%) Accessibility
14 4 (0.79%) HMG Security Policy Framework
15 3 (0.59%) JSP 440
15 3 (0.59%) JTAG
System Software
1 45 (8.84%) Active Directory
2 25 (4.91%) VMware Infrastructure
3 10 (1.96%) Virtual Machines
4 7 (1.38%) Docker
5 2 (0.39%) Hyper-V
5 2 (0.39%) Virtual Servers
Systems Management
1 21 (4.13%) Nessus
2 18 (3.54%) Kubernetes
3 13 (2.55%) WSUS
4 12 (2.36%) Ansible
5 11 (2.16%) Computer Emergency Response Teams
5 11 (2.16%) Single Sign-On
6 9 (1.77%) Nmap
6 9 (1.77%) QRadar
7 8 (1.57%) Microsoft Intune
8 7 (1.38%) SCCM
9 6 (1.18%) CASB
10 5 (0.98%) Grafana
10 5 (0.98%) Progress Chef
10 5 (0.98%) Suricata
10 5 (0.98%) Terraform
11 4 (0.79%) DatAdvantage
11 4 (0.79%) HP Fortify
12 3 (0.59%) FortiGate
13 2 (0.39%) CSIRT
14 1 (0.20%) Prometheus
Vendors
1 93 (18.27%) Microsoft
2 25 (4.91%) VMware
3 23 (4.52%) Cisco
3 23 (4.52%) Qualys
4 20 (3.93%) Google
5 15 (2.95%) Splunk
6 11 (2.16%) Apple
7 8 (1.57%) Palo Alto
8 7 (1.38%) Rapid7
9 6 (1.18%) HubSpot
9 6 (1.18%) IBM
9 6 (1.18%) Kenna
9 6 (1.18%) Oracle
10 5 (0.98%) Alibaba
10 5 (0.98%) Juniper
10 5 (0.98%) Red Hat
10 5 (0.98%) Veeam
11 4 (0.79%) HP
11 4 (0.79%) ServiceNow
11 4 (0.79%) Varonis