OWASP Contracts

Open Web Application Security Project (OWASP)
UK

The following table provides summary statistics for contract job vacancies with a requirement for OWASP skills. Included is a benchmarking guide to the contractor rates offered in vacancies that have cited OWASP over the 6 months to 9 June 2024 with a comparison to the same period in the previous 2 years.

6 months to
9 Jun 2024
Same period 2023 Same period 2022
Rank 511 561 529
Rank change year-on-year +50 -32 -82
Contract jobs citing OWASP 91 134 353
As % of all contract jobs advertised in the UK 0.21% 0.24% 0.40%
As % of the Processes & Methodologies category 0.25% 0.27% 0.44%
Number of daily rates quoted 59 84 215
10th Percentile £460 £450 £450
25th Percentile £516 £500 £500
Median daily rate (50th Percentile) £600 £575 £575
Median % change year-on-year +4.35% - +13.86%
75th Percentile £689 £656 £638
90th Percentile £850 £738 £733
UK excluding London median daily rate £594 £575 £550
% change year-on-year +3.30% +4.55% +6.80%
Number of hourly rates quoted 1 2 2
10th Percentile - - £46.00
25th Percentile £46.25 - £55.00
Median hourly rate £47.50 £70.00 £70.00
Median % change year-on-year -32.14% - +33.33%
75th Percentile £48.75 - £85.00
90th Percentile - - £94.00
UK excluding London median hourly rate £47.50 £70.00 -
% change year-on-year -32.14% - -

All Process and Methodology Skills
UK

OWASP is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all contract job vacancies with a requirement for process or methodology skills.

Contract vacancies with a requirement for process or methodology skills 36,914 49,809 79,437
As % of all contract IT jobs advertised in the UK 85.21% 89.64% 90.63%
Number of daily rates quoted 23,592 34,469 55,846
10th Percentile £300 £325 £350
25th Percentile £413 £438 £435
Median daily rate (50th Percentile) £525 £550 £538
Median % change year-on-year -4.55% +2.33% +7.50%
75th Percentile £638 £650 £649
90th Percentile £750 £750 £743
UK excluding London median daily rate £500 £500 £490
% change year-on-year - +2.04% +8.89%
Number of hourly rates quoted 2,564 1,687 1,868
10th Percentile £12.75 £10.70 £12.50
25th Percentile £16.00 £15.75 £15.75
Median hourly rate £36.50 £35.80 £25.68
Median % change year-on-year +1.96% +39.41% +11.65%
75th Percentile £61.25 £65.00 £50.00
90th Percentile £72.50 £75.00 £65.00
UK excluding London median hourly rate £38.12 £35.00 £20.51
% change year-on-year +8.91% +70.69% -2.36%

OWASP
Job Vacancy Trend

Job postings citing OWASP as a proportion of all IT jobs advertised.

Job vacancy trend for OWASP in the UK

OWASP
Contractor Daily Rate Trend

3-month moving average daily rate quoted in jobs citing OWASP.

Daily rate trend for OWASP in the UK

OWASP
Daily Rate Histogram

Daily rate distribution for jobs citing OWASP over the 6 months to 9 June 2024.

Daily rate histogram for OWASP in the UK

OWASP
Contractor Hourly Rate Trend

3-month moving average hourly rates quoted in jobs citing OWASP.

Hourly rate trend for OWASP in the UK

OWASP
Top 11 Contract Locations

The table below looks at the demand and provides a guide to the median contractor rates quoted in IT jobs citing OWASP within the UK over the 6 months to 9 June 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Contract
IT Job Ads
Median
Daily Rate
Past 6 Months
Median Daily Rate
% Change
on Same Period
Last Year
Live
Jobs
England +61 77 £600 +4.35% 49
UK excluding London +16 42 £594 +3.30% 28
London +88 39 £650 +13.04% 22
Work from Home +72 31 £550 -4.35% 34
North of England +13 16 £558 -3.04% 9
South East +19 14 £550 +4.76% 10
Yorkshire +5 9 £550 - 1
Scotland +45 7 £623 +10.67%
North West +10 7 £575 -12.55% 8
South West +10 3 £600 - 3
Wales +20 2 £666 +2.50%

OWASP
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 4 (4.40%) Microsoft Exchange
2 2 (2.20%) Apache
2 2 (2.20%) Confluence
2 2 (2.20%) Jupyter
2 2 (2.20%) nginx
3 1 (1.10%) JBoss
3 1 (1.10%) SAS
3 1 (1.10%) Tomcat
3 1 (1.10%) WildFly
Cloud Services
1 34 (37.36%) Azure
2 32 (35.16%) AWS
3 12 (13.19%) Azure DevOps
4 11 (12.09%) GitHub
5 7 (7.69%) Akamai
5 7 (7.69%) Azure Functions
5 7 (7.69%) GitHub Actions
5 7 (7.69%) Power Platform
5 7 (7.69%) Serverless
6 6 (6.59%) Amazon EKS
6 6 (6.59%) Azure API Management
6 6 (6.59%) Azure Batch
6 6 (6.59%) Azure Key Vault
6 6 (6.59%) Azure Logic Apps
6 6 (6.59%) Azure Service Bus
6 6 (6.59%) Azure Storage
6 6 (6.59%) OpenShift
6 6 (6.59%) Power Automate
6 6 (6.59%) PowerApps
7 5 (5.49%) Cloudflare
Communications & Networking
1 20 (21.98%) Firewall
2 13 (14.29%) Network Security
3 5 (5.49%) DNS
4 4 (4.40%) Internet
4 4 (4.40%) Wireshark
5 3 (3.30%) HTTP
6 2 (2.20%) DHCP
6 2 (2.20%) TCP/IP
6 2 (2.20%) WAN
6 2 (2.20%) Wi-Fi
6 2 (2.20%) Wireless
7 1 (1.10%) FTP
7 1 (1.10%) SSL
7 1 (1.10%) VLAN
7 1 (1.10%) VPN
Database & Business Intelligence
1 15 (16.48%) SQL Server
2 9 (9.89%) MySQL
3 8 (8.79%) Big Data
3 8 (8.79%) Data Lake
3 8 (8.79%) Relational Database
4 6 (6.59%) Azure SQL Database
4 6 (6.59%) Data Warehouse
4 6 (6.59%) OLTP
5 3 (3.30%) RDBMS
6 2 (2.20%) Amazon Athena
6 2 (2.20%) NoSQL
7 1 (1.10%) Azure SQL Data Warehouse
7 1 (1.10%) CouchDB
7 1 (1.10%) Elasticsearch
7 1 (1.10%) Hazelcast
7 1 (1.10%) MongoDB
7 1 (1.10%) Oracle Database
7 1 (1.10%) Oracle Database 11g
7 1 (1.10%) PostgreSQL
7 1 (1.10%) Redis
Development Applications
1 18 (19.78%) Git
2 16 (17.58%) Jenkins
3 12 (13.19%) Burp Suite
4 8 (8.79%) Maven
5 7 (7.69%) Gradle
5 7 (7.69%) SonarQube
6 6 (6.59%) AppScan
6 6 (6.59%) GitLab
6 6 (6.59%) Visual Studio Team System
7 4 (4.40%) JIRA
8 3 (3.30%) CircleCI
8 3 (3.30%) Postman
8 3 (3.30%) Subversion
9 2 (2.20%) Cypress.io
9 2 (2.20%) RStudio
10 1 (1.10%) Mercurial
10 1 (1.10%) Metasploit
10 1 (1.10%) Mockito
10 1 (1.10%) Selenium
10 1 (1.10%) SoapUI
General
1 15 (16.48%) Finance
2 10 (10.99%) Analytical Skills
3 7 (7.69%) Banking
3 7 (7.69%) Retail
3 7 (7.69%) Social Skills
4 4 (4.40%) Public Sector
4 4 (4.40%) Telecoms
5 2 (2.20%) Manufacturing
5 2 (2.20%) Multimedia
6 1 (1.10%) Automotive
6 1 (1.10%) Influencing Skills
Job Titles
1 22 (24.18%) Consultant
2 17 (18.68%) Architect
2 17 (18.68%) Security Architect
3 16 (17.58%) Security Consultant
4 12 (13.19%) Security Engineer
5 10 (10.99%) Cybersecurity Consultant
6 8 (8.79%) Developer
7 7 (7.69%) Site Reliability Engineer
8 6 (6.59%) Senior
8 6 (6.59%) Site Engineer
9 5 (5.49%) Cybersecurity Architect
9 5 (5.49%) Lead
9 5 (5.49%) Site Manager
9 5 (5.49%) Site Reliability Manager
9 5 (5.49%) Software Engineer
10 4 (4.40%) Tester
11 3 (3.30%) Applications Developer
11 3 (3.30%) Java Engineer
11 3 (3.30%) Java Software Engineer
11 3 (3.30%) Penetration Tester
Libraries, Frameworks & Software Standards
1 9 (9.89%) Kafka
2 8 (8.79%) .NET
2 8 (8.79%) Elastic Stack
3 7 (7.69%) AngularJS
3 7 (7.69%) XML
4 6 (6.59%) ARM Templates
4 6 (6.59%) JSON
4 6 (6.59%) Web Services
5 3 (3.30%) gRPC
5 3 (3.30%) WebSockets
6 2 (2.20%) OAuth
6 2 (2.20%) REST
6 2 (2.20%) Spring
6 2 (2.20%) Symfony
7 1 (1.10%) OAuth2
7 1 (1.10%) OpenJDK
7 1 (1.10%) RabbitMQ
7 1 (1.10%) React
7 1 (1.10%) RESTful
7 1 (1.10%) Spring Boot
Miscellaneous
1 11 (12.09%) Data Centre
2 7 (7.69%) Distributed Denial-of-Service
2 7 (7.69%) IoT
2 7 (7.69%) Public Cloud
3 6 (6.59%) Management Information System
3 6 (6.59%) Mobile App
3 6 (6.59%) Security Posture
4 5 (5.49%) Cloud Native
5 3 (3.30%) Cyber Threat
5 3 (3.30%) Onboarding
6 2 (2.20%) Algorithms
6 2 (2.20%) Cyberattack
6 2 (2.20%) PKI
7 1 (1.10%) CBDC
7 1 (1.10%) Credit Risk
7 1 (1.10%) Data Protection Act
7 1 (1.10%) Digital Currency
7 1 (1.10%) Distributed Systems
7 1 (1.10%) Product Ownership
7 1 (1.10%) Team-Oriented Environment
Operating Systems
1 22 (24.18%) Linux
2 15 (16.48%) Windows
3 10 (10.99%) Unix
4 5 (5.49%) Windows Server
5 1 (1.10%) AIX
Processes & Methodologies
1 37 (40.66%) Application Security
2 36 (39.56%) Cybersecurity
3 35 (38.46%) DevOps
4 25 (27.47%) Information Security
5 24 (26.37%) CI/CD
6 22 (24.18%) Agile
7 19 (20.88%) Security Testing
8 18 (19.78%) Vulnerability Management
9 16 (17.58%) Problem-Solving
10 15 (16.48%) Test Automation
11 14 (15.38%) Continuous Integration
11 14 (15.38%) DevSecOps
11 14 (15.38%) Penetration Testing
12 12 (13.19%) Deployment Automation
12 12 (13.19%) Microservices
12 12 (13.19%) Migration
12 12 (13.19%) Security Management
12 12 (13.19%) Site Reliability Engineering
12 12 (13.19%) Threat Modelling
13 11 (12.09%) Information Security Management
Programming Languages
1 21 (23.08%) Python
2 16 (17.58%) PowerShell
3 15 (16.48%) Java
4 13 (14.29%) Bash
4 13 (14.29%) C#
5 8 (8.79%) Ruby
5 8 (8.79%) Shell Script
6 6 (6.59%) Groovy
7 4 (4.40%) Go
7 4 (4.40%) SQL
8 3 (3.30%) C
8 3 (3.30%) C++
8 3 (3.30%) JavaScript
8 3 (3.30%) PHP
9 2 (2.20%) Perl
9 2 (2.20%) R
10 1 (1.10%) Rust
Qualifications
1 7 (7.69%) ISACA
2 6 (6.59%) CREST Certified
3 5 (5.49%) Degree
4 4 (4.40%) CISM
4 4 (4.40%) CISSP
4 4 (4.40%) OSCP
4 4 (4.40%) SANS
5 3 (3.30%) Cisco Certification
5 3 (3.30%) CSSLP
5 3 (3.30%) Security Cleared
6 2 (2.20%) CCNP
6 2 (2.20%) CEH
6 2 (2.20%) CHECK Team Leader
6 2 (2.20%) Computer Science Degree
6 2 (2.20%) GIAC
6 2 (2.20%) Master's Degree
6 2 (2.20%) SC Cleared
7 1 (1.10%) AWS Certification
7 1 (1.10%) Azure Certification
7 1 (1.10%) CompTIA Security+
Quality Assurance & Compliance
1 32 (35.16%) NIST
2 18 (19.78%) ISO/IEC 27001
3 13 (14.29%) COBIT
4 12 (13.19%) GDPR
4 12 (13.19%) PCI DSS
5 8 (8.79%) QA
6 6 (6.59%) NCSC
7 3 (3.30%) GRC
8 2 (2.20%) ISO 22301
9 1 (1.10%) Accessibility
9 1 (1.10%) Actionable Recommendations
9 1 (1.10%) Cyber Essentials
9 1 (1.10%) Cyber Essentials PLUS
9 1 (1.10%) Disclosure Scotland
9 1 (1.10%) HIPAA
9 1 (1.10%) ISO 20022
9 1 (1.10%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
System Software
1 19 (20.88%) Docker
2 3 (3.30%) Active Directory
3 2 (2.20%) Virtual Machines
Systems Management
1 25 (27.47%) Terraform
2 21 (23.08%) Kubernetes
3 14 (15.38%) Ansible
4 8 (8.79%) Grafana
4 8 (8.79%) Nessus
4 8 (8.79%) Prometheus
5 7 (7.69%) Graylog
5 7 (7.69%) HP Fortify
5 7 (7.69%) Progress Chef
5 7 (7.69%) Puppet
6 6 (6.59%) WebInspect
7 3 (3.30%) Nagios
8 2 (2.20%) CASB
8 2 (2.20%) SCCM
8 2 (2.20%) SCOrch
8 2 (2.20%) Single Sign-On
9 1 (1.10%) Kibana
9 1 (1.10%) logstash
9 1 (1.10%) Nmap
9 1 (1.10%) OpenVAS
Vendors
1 17 (18.68%) Microsoft
2 10 (10.99%) Splunk
3 8 (8.79%) F5
4 7 (7.69%) Checkmarx
5 6 (6.59%) Imperva
5 6 (6.59%) Veracode
6 4 (4.40%) CrowdStrike
6 4 (4.40%) Qualys
6 4 (4.40%) SAP
6 4 (4.40%) Unisys
7 3 (3.30%) Oracle
8 2 (2.20%) Darktrace
8 2 (2.20%) Netskope
8 2 (2.20%) Palo Alto
8 2 (2.20%) VMware
9 1 (1.10%) CyberArk
9 1 (1.10%) Google
9 1 (1.10%) Okta
9 1 (1.10%) Rapid7
9 1 (1.10%) ServiceNow