Application Security Contracts

Application Security (AppSec)
UK

The following table provides summary statistics for contract job vacancies with a requirement for Application Security skills. Included is a benchmarking guide to the contractor rates offered in vacancies that have cited Application Security over the 6 months to 18 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
18 May 2024
Same period 2023 Same period 2022
Rank 333 265 350
Rank change year-on-year -68 +85 +33
Contract jobs citing Application Security 242 563 668
As % of all contract jobs advertised in the UK 0.57% 0.99% 0.76%
As % of the Processes & Methodologies category 0.66% 1.10% 0.84%
Number of daily rates quoted 170 419 475
10th Percentile £474 £488 £425
25th Percentile £540 £540 £514
Median daily rate (50th Percentile) £614 £625 £600
Median % change year-on-year -1.84% +4.17% +7.62%
75th Percentile £719 £750 £688
90th Percentile £784 £838 £800
UK excluding London median daily rate £623 £622 £575
% change year-on-year +0.08% +8.17% +9.52%
Number of hourly rates quoted 0 2 3
10th Percentile - £40.63 £42.00
25th Percentile - £49.06 £45.00
Median hourly rate - £66.25 £50.00
Median % change year-on-year - +32.50% +62.60%
75th Percentile - £86.56 £63.50
90th Percentile - £96.88 £71.60
UK excluding London median hourly rate - - £77.00
% change year-on-year - - +258.14%

All Process and Methodology Skills
UK

Application Security is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all contract job vacancies with a requirement for process or methodology skills.

Contract vacancies with a requirement for process or methodology skills 36,673 51,121 79,325
As % of all contract IT jobs advertised in the UK 86.13% 89.77% 90.61%
Number of daily rates quoted 23,631 35,432 55,673
10th Percentile £300 £325 £344
25th Percentile £413 £438 £430
Median daily rate (50th Percentile) £525 £550 £530
Median % change year-on-year -4.55% +3.77% +7.07%
75th Percentile £638 £650 £638
90th Percentile £750 £750 £738
UK excluding London median daily rate £500 £500 £480
% change year-on-year - +4.17% +9.09%
Number of hourly rates quoted 2,440 1,683 1,892
10th Percentile £12.75 £10.63 £12.50
25th Percentile £15.99 £16.01 £15.50
Median hourly rate £36.05 £36.00 £25.68
Median % change year-on-year +0.13% +40.19% +7.00%
75th Percentile £60.00 £65.00 £49.54
90th Percentile £72.50 £75.00 £65.00
UK excluding London median hourly rate £37.50 £35.00 £20.00
% change year-on-year +7.14% +75.00% -4.99%

Application Security
Job Vacancy Trend

Job postings citing Application Security as a proportion of all IT jobs advertised.

Job vacancy trend for Application Security in the UK

Application Security
Contractor Daily Rate Trend

3-month moving average daily rate quoted in jobs citing Application Security.

Daily rate trend for Application Security in the UK

Application Security
Daily Rate Histogram

Daily rate distribution for jobs citing Application Security over the 6 months to 18 May 2024.

Daily rate histogram for Application Security in the UK

Application Security
Contractor Hourly Rate Trend

3-month moving average hourly rates quoted in jobs citing Application Security.

Hourly rate trend for Application Security in the UK

Application Security
Top 16 Contract Locations

The table below looks at the demand and provides a guide to the median contractor rates quoted in IT jobs citing Application Security within the UK over the 6 months to 18 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Contract
IT Job Ads
Median
Daily Rate
Past 6 Months
Median Daily Rate
% Change
on Same Period
Last Year
Live
Jobs
England -63 203 £622 -4.31% 102
London -60 127 £600 -14.29% 43
Work from Home -14 86 £600 -7.69% 71
UK excluding London -7 77 £623 +0.08% 59
North of England +21 30 £625 +3.14% 20
South East +23 26 £513 -26.79% 20
Yorkshire +19 15 £622 +8.17% 6
North West +12 13 £663 +9.41% 11
Midlands -17 8 £650 +9.24% 8
South West +10 7 £400 -38.46% 7
West Midlands -8 7 £650 +9.24% 7
Scotland +40 6 £623 +38.33% 1
Wales +17 2 £666 +40.26% 1
North East +6 2 £625 -26.23% 3
East Midlands +8 1 £567 -6.44% 1
East of England -3 1 - - 5

Application Security
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 4 (1.65%) Confluence
2 3 (1.24%) Microsoft Exchange
3 2 (0.83%) SharePoint
4 1 (0.41%) IBM Notes
4 1 (0.41%) nginx
4 1 (0.41%) SAS
Applications
1 10 (4.13%) Microsoft Office
2 3 (1.24%) Microsoft Project
Business Applications
1 1 (0.41%) SAP S/4HANA
Cloud Services
1 77 (31.82%) AWS
2 67 (27.69%) Azure
3 42 (17.36%) GCP
4 20 (8.26%) SaaS
5 18 (7.44%) Serverless
6 15 (6.20%) AWS CloudFormation
7 14 (5.79%) PaaS
8 13 (5.37%) IaaS
9 12 (4.96%) GitHub
10 10 (4.13%) Virtual Private Cloud
11 8 (3.31%) Entra ID
12 7 (2.89%) Azure DevOps
12 7 (2.89%) OpenShift
13 6 (2.48%) Amazon EKS
14 5 (2.07%) Azure API Management
14 5 (2.07%) Azure Data Factory
14 5 (2.07%) Azure Functions
14 5 (2.07%) Azure Key Vault
14 5 (2.07%) Azure Logic Apps
14 5 (2.07%) Azure Monitor
Communications & Networking
1 41 (16.94%) Firewall
2 27 (11.16%) Network Security
3 13 (5.37%) DNS
4 11 (4.55%) HTTPS
5 10 (4.13%) Wireless
6 9 (3.72%) VPN
7 6 (2.48%) BIG-IP
7 6 (2.48%) Intrusion Detection
8 5 (2.07%) DHCP
8 5 (2.07%) HTTP
8 5 (2.07%) SD-WAN
8 5 (2.07%) TCP/IP
8 5 (2.07%) WAN
9 4 (1.65%) Cisco ISE
9 4 (1.65%) Cisco Nexus
9 4 (1.65%) Internet
9 4 (1.65%) IPv4
10 3 (1.24%) F5 BIG-IP GTM
10 3 (1.24%) Reverse Proxy
10 3 (1.24%) SSL
Database & Business Intelligence
1 13 (5.37%) SQL Server
2 8 (3.31%) MySQL
3 5 (2.07%) Azure SQL Database
4 4 (1.65%) Metadata
4 4 (1.65%) RDBMS
4 4 (1.65%) Relational Database
5 3 (1.24%) Data Vault
5 3 (1.24%) Data Warehouse
5 3 (1.24%) Elasticsearch
5 3 (1.24%) NoSQL
5 3 (1.24%) SQL Server Integration Services
6 1 (0.41%) Data Lake
6 1 (0.41%) DB2
6 1 (0.41%) Oracle Reports
6 1 (0.41%) SAP HANA
Development Applications
1 15 (6.20%) Jenkins
2 13 (5.37%) Git
3 12 (4.96%) Sonatype Nexus
4 11 (4.55%) GitLab
5 10 (4.13%) JIRA
6 9 (3.72%) Burp Suite
7 8 (3.31%) Robot Framework
8 6 (2.48%) Gradle
8 6 (2.48%) Maven
8 6 (2.48%) Visual Studio
9 4 (1.65%) Browser DevTools
10 3 (1.24%) Atlassian Bamboo
10 3 (1.24%) CircleCI
10 3 (1.24%) SonarQube
10 3 (1.24%) Travis CI
11 2 (0.83%) Appium
11 2 (0.83%) AppScan
11 2 (0.83%) git-flow
11 2 (0.83%) Subversion
11 2 (0.83%) XCUITest
General
1 59 (24.38%) Finance
2 42 (17.36%) Social Skills
3 28 (11.57%) Banking
4 26 (10.74%) Analytical Skills
5 13 (5.37%) Public Sector
6 11 (4.55%) Documentation Skills
7 10 (4.13%) Retail
8 6 (2.48%) Financial Institution
8 6 (2.48%) Telecoms
9 5 (2.07%) Legal
10 4 (1.65%) Automotive
10 4 (1.65%) Front Office
10 4 (1.65%) Presentation Skills
11 3 (1.24%) Electronics
12 2 (0.83%) Publishing
13 1 (0.41%) Arabic Language
13 1 (0.41%) Back Office
13 1 (0.41%) Health Technology
13 1 (0.41%) Retail Banking
Job Titles
1 83 (34.30%) Architect
2 57 (23.55%) Security Architect
3 33 (13.64%) Consultant
4 32 (13.22%) Security Consultant
5 31 (12.81%) Security Engineer
6 24 (9.92%) Solutions Architect
7 21 (8.68%) Applications Engineer
8 20 (8.26%) Senior
9 16 (6.61%) Applications Architect
10 14 (5.79%) Analyst
11 13 (5.37%) Cloud Engineer
12 12 (4.96%) Senior Architect
13 11 (4.55%) Senior Security Architect
14 10 (4.13%) Penetration Tester
14 10 (4.13%) Security Manager
14 10 (4.13%) Tester
15 9 (3.72%) Cloud Architect
15 9 (3.72%) Cybersecurity Consultant
16 8 (3.31%) Cloud Security Architect
17 7 (2.89%) Market Data Analyst
Libraries, Frameworks & Software Standards
1 19 (7.85%) SailPoint
2 11 (4.55%) OAuth
3 8 (3.31%) SAML
4 7 (2.89%) .NET
4 7 (2.89%) JSON
5 6 (2.48%) CSS
5 6 (2.48%) Elastic Stack
5 6 (2.48%) OpenID
5 6 (2.48%) XML
6 5 (2.07%) ARM Templates
6 5 (2.07%) HTML
6 5 (2.07%) OAuth2
6 5 (2.07%) REST
7 4 (1.65%) FIX Protocol
7 4 (1.65%) HTML5
7 4 (1.65%) RESTful
7 4 (1.65%) YAML
8 3 (1.24%) Kafka
8 3 (1.24%) SOAP
8 3 (1.24%) Web Services
Miscellaneous
1 25 (10.33%) Mobile App
2 16 (6.61%) PKI
3 15 (6.20%) Cloud Native
4 14 (5.79%) Data Centre
4 14 (5.79%) IoT
4 14 (5.79%) Security Posture
5 8 (3.31%) Operational Technology
6 6 (2.48%) Cyber Threat
6 6 (2.48%) Management Information System
6 6 (2.48%) Product Ownership
7 5 (2.07%) Hedge funds
7 5 (2.07%) Security Operations Centre
8 4 (1.65%) Public Cloud
9 3 (1.24%) Cyberattack
9 3 (1.24%) Data Structures
10 2 (0.83%) Data Protection Act
10 2 (0.83%) Hybrid Cloud
11 1 (0.41%) Distributed Denial-of-Service
11 1 (0.41%) FMCG
11 1 (0.41%) W3C
Operating Systems
1 41 (16.94%) Windows
2 30 (12.40%) Linux
3 15 (6.20%) Windows Server
4 14 (5.79%) Unix
5 12 (4.96%) Windows Server 2019
6 4 (1.65%) CentOS
6 4 (1.65%) Windows Server 2016
7 2 (0.83%) Android
7 2 (0.83%) Apple iOS
8 1 (0.41%) Windows 10
Processes & Methodologies
1 77 (31.82%) CI/CD
2 76 (31.40%) Cloud Security
3 70 (28.93%) Cybersecurity
4 67 (27.69%) DevOps
5 56 (23.14%) DevSecOps
6 55 (22.73%) Information Security
7 54 (22.31%) Agile
8 50 (20.66%) Security Testing
9 45 (18.60%) Identity Access Management
10 44 (18.18%) Deployment Automation
10 44 (18.18%) Static Application Security Testing
11 42 (17.36%) SDLC
11 42 (17.36%) Threat Modelling
12 38 (15.70%) Penetration Testing
12 38 (15.70%) Security Architecture
12 38 (15.70%) Vulnerability Management
13 36 (14.88%) Dynamic Application Security Testing
13 36 (14.88%) OWASP
14 33 (13.64%) Infrastructure as Code
15 28 (11.57%) Containerisation
Programming Languages
1 44 (18.18%) Python
2 30 (12.40%) PowerShell
3 17 (7.02%) C++
4 15 (6.20%) Bash
5 13 (5.37%) JavaScript
5 13 (5.37%) Shell Script
6 11 (4.55%) SQL
7 10 (4.13%) Java
8 8 (3.31%) Ruby
9 6 (2.48%) C#
9 6 (2.48%) Groovy
9 6 (2.48%) PHP
10 4 (1.65%) C
10 4 (1.65%) Go
10 4 (1.65%) T-SQL
10 4 (1.65%) VBScript
11 3 (1.24%) ActionScript
11 3 (1.24%) Perl
12 2 (0.83%) Swift
13 1 (0.41%) PL/SQL
Qualifications
1 27 (11.16%) CISSP
2 25 (10.33%) Security Cleared
3 22 (9.09%) CISM
4 19 (7.85%) Degree
5 17 (7.02%) SC Cleared
6 15 (6.20%) AWS Certification
7 14 (5.79%) CISA
8 11 (4.55%) CEH
8 11 (4.55%) OSCP
9 10 (4.13%) GIAC
10 9 (3.72%) CREST Certified
11 8 (3.31%) GPEN
12 7 (2.89%) ISACA
12 7 (2.89%) Master's Degree
12 7 (2.89%) MBA
13 5 (2.07%) Computer Science Degree
13 5 (2.07%) DV Cleared
14 4 (1.65%) SANS
15 3 (1.24%) Cisco Certification
15 3 (1.24%) CRISC
Quality Assurance & Compliance
1 44 (18.18%) NIST
2 12 (4.96%) ISO/IEC 27001
2 12 (4.96%) QA
3 11 (4.55%) GDPR
4 10 (4.13%) COBIT
5 8 (3.31%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
6 7 (2.89%) RMADS
7 4 (1.65%) PCI DSS
8 3 (1.24%) Accessibility
9 2 (0.83%) Automotive SPICE
9 2 (0.83%) AUTOSAR
9 2 (0.83%) HIPAA
9 2 (0.83%) ISO 9001
10 1 (0.41%) GLBA
10 1 (0.41%) GRC
10 1 (0.41%) HMG Security Policy Framework
10 1 (0.41%) ISAE 3402
10 1 (0.41%) ISO 31000
10 1 (0.41%) NCSC
10 1 (0.41%) Sarbanes-Oxley
System Software
1 24 (9.92%) Active Directory
2 20 (8.26%) Docker
3 8 (3.31%) VMware Infrastructure
4 2 (0.83%) Virtual Desktop
5 1 (0.41%) Virtual Machines
Systems Management
1 40 (16.53%) Terraform
2 30 (12.40%) Ansible
3 19 (7.85%) Kubernetes
4 9 (3.72%) Puppet
5 6 (2.48%) Grafana
5 6 (2.48%) Prometheus
6 5 (2.07%) Progress Chef
7 4 (1.65%) Nessus
8 3 (1.24%) Docker Swarm
8 3 (1.24%) Graylog
8 3 (1.24%) HP Fortify
8 3 (1.24%) Kibana
8 3 (1.24%) logstash
8 3 (1.24%) Nagios
8 3 (1.24%) Single Sign-On
8 3 (1.24%) Thomson Reuters DACS
9 2 (0.83%) SCCM
9 2 (0.83%) WebInspect
10 1 (0.41%) McAfee ePO
10 1 (0.41%) WMI
Vendors
1 25 (10.33%) Microsoft
2 19 (7.85%) CyberArk
3 18 (7.44%) BeyondTrust
3 18 (7.44%) ServiceNow
4 12 (4.96%) Splunk
5 10 (4.13%) Cisco
5 10 (4.13%) F5
6 9 (3.72%) VMware
7 6 (2.48%) Checkmarx
7 6 (2.48%) SAP
7 6 (2.48%) Veracode
8 5 (2.07%) Red Hat
9 4 (1.65%) CheckPoint
9 4 (1.65%) Fortinet
9 4 (1.65%) Juniper
9 4 (1.65%) Palo Alto
10 3 (1.24%) Bloomberg
10 3 (1.24%) Qualys
10 3 (1.24%) Tufin
10 3 (1.24%) Unisys