Application Security (AppSec)
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Application Security skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Application Security over the 6 months to 20 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
20 May 2024
Same period 2023 Same period 2022
Rank 501 469 552
Rank change year-on-year -32 +83 -41
Permanent jobs citing Application Security 443 626 953
As % of all permanent jobs advertised in the UK 0.44% 0.63% 0.59%
As % of the Processes & Methodologies category 0.52% 0.66% 0.61%
Number of salaries quoted 297 378 527
10th Percentile £47,000 £37,500 £37,500
25th Percentile £56,250 £56,250 £50,625
Median annual salary (50th Percentile) £75,000 £77,500 £70,000
Median % change year-on-year -3.23% +10.71% +7.69%
75th Percentile £88,750 £95,000 £87,500
90th Percentile £105,500 £111,250 £109,250
UK excluding London median annual salary £65,000 £60,000 £55,000
% change year-on-year +8.33% +9.09% -8.33%

All Process and Methodology Skills
UK

Application Security is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 85,108 95,066 155,930
As % of all permanent jobs advertised in the UK 85.18% 95.58% 95.78%
Number of salaries quoted 59,794 56,135 83,138
10th Percentile £29,071 £34,000 £33,645
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,180 £60,000
Median % change year-on-year -10.10% +1.97% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +10.53%

Application Security
Job Vacancy Trend

Job postings citing Application Security as a proportion of all IT jobs advertised.

Job vacancy trend for Application Security in the UK

Application Security
Salary Trend

3-month moving average salary quoted in jobs citing Application Security.

Salary trend for Application Security in the UK

Application Security
Salary Histogram

Salary distribution for jobs citing Application Security over the 6 months to 20 May 2024.

Salary histogram for Application Security in the UK

Application Security
Top 15 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Application Security within the UK over the 6 months to 20 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England -16 397 £75,000 -6.25% 110
London +50 230 £75,000 -14.29% 47
Work from Home +33 201 £71,250 -5.00% 69
UK excluding London -80 178 £65,000 +8.33% 62
North of England +19 66 £61,853 -2.98% 21
South East -11 56 £71,250 +39.02% 21
North West -16 38 £60,000 -7.69% 11
Midlands -17 23 £57,500 -4.17% 8
West Midlands +6 22 £57,500 -13.53% 7
Yorkshire +74 19 £79,842 +27.75% 7
South West -16 17 £75,000 -25.00% 8
Scotland -56 16 £50,000 +9.29% 1
North East +5 9 £62,500 +31.58% 3
Wales +10 2 £65,000 +74.98% 1
East Midlands -21 1 £44,500 -19.09% 1

Application Security
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 12 (2.71%) SharePoint
2 10 (2.26%) Microsoft Exchange
3 2 (0.45%) Confluence
3 2 (0.45%) IIS
4 1 (0.23%) Apache
4 1 (0.23%) Blackberry Enterprise Server
4 1 (0.23%) Drupal
4 1 (0.23%) nginx
Applications
1 10 (2.26%) Microsoft Office
2 6 (1.35%) Microsoft Excel
Business Applications
1 2 (0.45%) SAP GRC
1 2 (0.45%) SAP S/4HANA
Cloud Services
1 161 (36.34%) Azure
2 109 (24.60%) AWS
3 57 (12.87%) Microsoft 365
4 24 (5.42%) Cloud Computing
4 24 (5.42%) GCP
4 24 (5.42%) SaaS
5 21 (4.74%) Entra ID
6 18 (4.06%) PaaS
7 17 (3.84%) IaaS
8 16 (3.61%) Azure AKS
9 14 (3.16%) Power Platform
10 12 (2.71%) Azure DevOps
11 10 (2.26%) Serverless
12 8 (1.81%) Azure Sentinel
13 6 (1.35%) Azure Service Bus
13 6 (1.35%) Azure Service Fabric
14 4 (0.90%) Azure App Service
14 4 (0.90%) PowerApps
15 3 (0.68%) AWS Lambda
15 3 (0.68%) Dynamics 365
Communications & Networking
1 101 (22.80%) Firewall
2 79 (17.83%) WAN
3 65 (14.67%) Network Security
4 52 (11.74%) VPN
5 44 (9.93%) LAN
6 43 (9.71%) Internet
7 34 (7.67%) SD-WAN
8 17 (3.84%) Wireless
9 10 (2.26%) Intrusion Detection
10 8 (1.81%) TCP/IP
10 8 (1.81%) Wireshark
11 4 (0.90%) BGP
11 4 (0.90%) Ethernet VPN
11 4 (0.90%) F5 BIG-IP GTM
11 4 (0.90%) F5 BIG-IP LTM
11 4 (0.90%) HTTP
11 4 (0.90%) MPLS
11 4 (0.90%) OSPF
11 4 (0.90%) tcpdump
11 4 (0.90%) Unified Communications
Database & Business Intelligence
1 16 (3.61%) SQL Server
2 10 (2.26%) Relational Database
3 9 (2.03%) Azure SQL Database
4 8 (1.81%) CockroachDB
5 7 (1.58%) NoSQL
5 7 (1.58%) SQL Server Integration Services
5 7 (1.58%) SQL Server Reporting Services
6 4 (0.90%) RDBMS
7 3 (0.68%) Amazon RDS
7 3 (0.68%) Data Lake
7 3 (0.68%) Looker
8 2 (0.45%) Elasticsearch
8 2 (0.45%) MySQL
9 1 (0.23%) Geospatial Data
9 1 (0.23%) PostgreSQL
9 1 (0.23%) Power BI
Development Applications
1 41 (9.26%) Burp Suite
2 36 (8.13%) Metasploit
3 13 (2.93%) Jenkins
4 9 (2.03%) Sonatype Nexus
5 8 (1.81%) Jaeger
6 7 (1.58%) Git
7 5 (1.13%) Selenium
7 5 (1.13%) SoapUI
8 3 (0.68%) Moq
8 3 (0.68%) Postman
8 3 (0.68%) SpecFlow
8 3 (0.68%) Visual Studio
9 2 (0.45%) Bitbucket
9 2 (0.45%) Cypress.io
9 2 (0.45%) JIRA
9 2 (0.45%) WebDriver
10 1 (0.23%) Gradle
10 1 (0.23%) Grunt
10 1 (0.23%) Maven
10 1 (0.23%) MSI
General
1 139 (31.38%) Social Skills
2 100 (22.57%) Finance
3 60 (13.54%) Analytical Skills
4 52 (11.74%) Retail
5 35 (7.90%) Inclusion and Diversity
6 34 (7.67%) Law
7 19 (4.29%) Banking
7 19 (4.29%) Telecoms
8 18 (4.06%) Marketing
9 15 (3.39%) Legal
9 15 (3.39%) Public Sector
10 12 (2.71%) Financial Institution
10 12 (2.71%) Health Technology
11 9 (2.03%) Documentation Skills
11 9 (2.03%) Tech for Good
12 8 (1.81%) Presentation Skills
13 6 (1.35%) Manufacturing
14 5 (1.13%) Influencing Skills
15 2 (0.45%) Local Government
16 1 (0.23%) Police
Job Titles
1 154 (34.76%) Architect
2 119 (26.86%) Senior
3 91 (20.54%) Security Architect
4 49 (11.06%) Lead
5 47 (10.61%) Penetration Tester
6 46 (10.38%) Tester
7 42 (9.48%) Analyst
7 42 (9.48%) Lead Architect
8 41 (9.26%) Security Analyst
9 39 (8.80%) Security Engineer
10 31 (7.00%) Lead Security Architect
11 25 (5.64%) Consultant
11 25 (5.64%) Senior Analyst
12 24 (5.42%) Senior Security Analyst
13 21 (4.74%) Infrastructure Architect
14 20 (4.51%) Senior Architect
15 19 (4.29%) Developer
16 18 (4.06%) CISSP Analyst
17 17 (3.84%) Infrastructure Engineer
18 16 (3.61%) Senior IT Security Analyst
Libraries, Frameworks & Software Standards
1 24 (5.42%) OAuth
2 17 (3.84%) REST
2 17 (3.84%) Web Services
3 14 (3.16%) SAML
4 13 (2.93%) .NET
5 12 (2.71%) HTML
5 12 (2.71%) Middleware
6 11 (2.48%) SailPoint
7 10 (2.26%) CSS
7 10 (2.26%) React
7 10 (2.26%) RESTful
8 9 (2.03%) .NET Framework
8 9 (2.03%) Entity Framework
8 9 (2.03%) Kafka
8 9 (2.03%) Vue
9 8 (1.81%) OAuth2
9 8 (1.81%) OpenTelemetry
9 8 (1.81%) Spring Boot
10 7 (1.58%) web3js
11 6 (1.35%) HTML5
Miscellaneous
1 80 (18.06%) Management Information System
2 46 (10.38%) Distributed Denial-of-Service
3 26 (5.87%) Security Posture
4 23 (5.19%) PKI
5 20 (4.51%) Public Cloud
6 19 (4.29%) Self-Motivation
7 14 (3.16%) Data Centre
7 14 (3.16%) Distributed Systems
8 13 (2.93%) Cloud Native
8 13 (2.93%) Greenfield Project
9 12 (2.71%) Replication
10 11 (2.48%) Cyber Threat
10 11 (2.48%) Mobile App
11 10 (2.26%) Product Ownership
11 10 (2.26%) Robotics
12 8 (1.81%) Hybrid Cloud
13 7 (1.58%) Blockchain
13 7 (1.58%) Web3
14 4 (0.90%) IoT
15 3 (0.68%) Data Structures
Operating Systems
1 85 (19.19%) Linux
2 70 (15.80%) Windows
3 36 (8.13%) Ubuntu
3 36 (8.13%) VMS
4 33 (7.45%) Kali Linux
5 19 (4.29%) Windows Server
6 8 (1.81%) Android
6 8 (1.81%) Apple iOS
7 2 (0.45%) Unix
7 2 (0.45%) Windows 10
8 1 (0.23%) Red Hat Enterprise Linux
8 1 (0.23%) Windows Server 2019
Processes & Methodologies
1 173 (39.05%) Cybersecurity
2 137 (30.93%) Information Security
3 104 (23.48%) OWASP
4 99 (22.35%) DevSecOps
5 93 (20.99%) Penetration Testing
6 91 (20.54%) Problem-Solving
7 86 (19.41%) Security Architecture
8 85 (19.19%) Computer Science
9 83 (18.74%) Cloud Security
10 82 (18.51%) CI/CD
11 67 (15.12%) Agile
12 65 (14.67%) Security Testing
13 62 (14.00%) DevOps
14 58 (13.09%) Vulnerability Management
15 57 (12.87%) Secure Coding
16 56 (12.64%) SIEM
17 54 (12.19%) Identity Access Management
18 50 (11.29%) Security Operations
19 48 (10.84%) Threat Modelling
20 46 (10.38%) Identity Management
Programming Languages
1 51 (11.51%) SQL
2 38 (8.58%) Python
3 28 (6.32%) Java
4 27 (6.09%) PowerShell
5 26 (5.87%) JavaScript
6 17 (3.84%) C#
7 9 (2.03%) Kusto Query Language
7 9 (2.03%) TypeScript
8 8 (1.81%) Go
8 8 (1.81%) R
9 7 (1.58%) C
9 7 (1.58%) T-SQL
10 5 (1.13%) Scala
11 4 (0.90%) Bash
12 3 (0.68%) C++
12 3 (0.68%) PHP
12 3 (0.68%) Ruby
13 2 (0.45%) Dart
13 2 (0.45%) Lua
13 2 (0.45%) Objective-C
Qualifications
1 128 (28.89%) CISSP
2 120 (27.09%) Degree
3 81 (18.28%) CISM
4 59 (13.32%) Computer Science Degree
5 58 (13.09%) Security Cleared
6 56 (12.64%) Cisco Certification
7 52 (11.74%) (ISC)2 CCSP
8 51 (11.51%) CCSP
9 49 (11.06%) Azure Certification
10 45 (10.16%) AWS Certification
11 41 (9.26%) DV Cleared
12 33 (7.45%) CCSK
13 19 (4.29%) CREST Certified
14 18 (4.06%) GIAC
14 18 (4.06%) OSCP
14 18 (4.06%) SC Cleared
15 17 (3.84%) SANS
16 14 (3.16%) PCI QSA
17 13 (2.93%) CHECK Team Member
17 13 (2.93%) Microsoft Certification
Quality Assurance & Compliance
1 94 (21.22%) NIST
2 37 (8.35%) ISO/IEC 27001
3 24 (5.42%) GRC
3 24 (5.42%) PCI DSS
4 17 (3.84%) GDPR
5 13 (2.93%) COBIT
5 13 (2.93%) Cyber Essentials
5 13 (2.93%) SOC 2
6 9 (2.03%) NCSC
6 9 (2.03%) NIST 800
7 6 (1.35%) Accessibility
7 6 (1.35%) Actionable Recommendations
7 6 (1.35%) Web Application Security Consortium
8 5 (1.13%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
8 5 (1.13%) QA
8 5 (1.13%) SLA
9 4 (0.90%) Cyber Essentials PLUS
9 4 (0.90%) WCAG
10 3 (0.68%) HIPAA
10 3 (0.68%) ISO 31000
System Software
1 64 (14.45%) Active Directory
2 60 (13.54%) Docker
3 14 (3.16%) VMware Infrastructure
4 10 (2.26%) Hyper-V
5 4 (0.90%) Microsoft Virtual Server
5 4 (0.90%) Virtual Servers
6 3 (0.68%) VMware ESXi
7 2 (0.45%) Virtual Machines
8 1 (0.23%) vSphere
Systems Management
1 85 (19.19%) Kubernetes
2 56 (12.64%) Terraform
3 48 (10.84%) Ansible
4 46 (10.38%) Single Sign-On
5 12 (2.71%) Computer Emergency Response Teams
6 9 (2.03%) Nmap
7 8 (1.81%) Kiali
7 8 (1.81%) Microsoft Intune
8 7 (1.58%) Nessus
9 5 (1.13%) Suricata
10 4 (0.90%) CSIRT
10 4 (0.90%) HP Fortify
11 3 (0.68%) QRadar
11 3 (0.68%) vCenter Server
12 1 (0.23%) CASB
12 1 (0.23%) WMI
12 1 (0.23%) WSUS
Vendors
1 97 (21.90%) Microsoft
2 18 (4.06%) Splunk
3 15 (3.39%) VMware
4 13 (2.93%) CyberArk
5 11 (2.48%) BeyondTrust
5 11 (2.48%) ServiceNow
6 10 (2.26%) Qualys
7 8 (1.81%) AppDynamics
7 8 (1.81%) Juniper
8 7 (1.58%) Cisco
9 5 (1.13%) F5
9 5 (1.13%) Palo Alto
10 4 (0.90%) Google
10 4 (0.90%) OpenAI
11 3 (0.68%) IBM
11 3 (0.68%) Oracle
11 3 (0.68%) SAP
11 3 (0.68%) Veracode
12 2 (0.45%) Darktrace
12 2 (0.45%) HP