Open Web Application Security Project (OWASP)
UK

The following table provides summary statistics for permanent job vacancies with a requirement for OWASP skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited OWASP over the 6 months to 20 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
20 May 2024
Same period 2023 Same period 2022
Rank 590 603 549
Rank change year-on-year +13 -54 -37
Permanent jobs citing OWASP 312 413 960
As % of all permanent jobs advertised in the UK 0.31% 0.42% 0.59%
As % of the Processes & Methodologies category 0.37% 0.43% 0.62%
Number of salaries quoted 222 213 503
10th Percentile £50,000 £45,245 £42,500
25th Percentile £57,500 £56,250 £52,500
Median annual salary (50th Percentile) £70,000 £84,000 £65,000
Median % change year-on-year -16.67% +29.23% -3.70%
75th Percentile £84,919 £95,000 £85,000
90th Percentile £97,375 £114,750 £100,000
UK excluding London median annual salary £70,000 £67,500 £57,500
% change year-on-year +3.70% +17.39% -4.17%

All Process and Methodology Skills
UK

OWASP is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 85,108 95,066 155,930
As % of all permanent jobs advertised in the UK 85.18% 95.58% 95.78%
Number of salaries quoted 59,794 56,135 83,138
10th Percentile £29,071 £34,000 £33,645
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,180 £60,000
Median % change year-on-year -10.10% +1.97% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,250
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +10.53%

OWASP
Job Vacancy Trend

Job postings citing OWASP as a proportion of all IT jobs advertised.

Job vacancy trend for OWASP in the UK

OWASP
Salary Trend

3-month moving average salary quoted in jobs citing OWASP.

Salary trend for OWASP in the UK

OWASP
Salary Histogram

Salary distribution for jobs citing OWASP over the 6 months to 20 May 2024.

Salary histogram for OWASP in the UK

OWASP
Top 15 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing OWASP within the UK over the 6 months to 20 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England +11 283 £70,000 -17.65% 71
UK excluding London +10 185 £70,000 +3.70% 44
Work from Home +89 171 £70,000 -15.15% 45
London +8 103 £70,000 -17.65% 33
South East +35 67 £70,000 -6.67% 20
North of England +20 45 £79,842 +69.88% 13
South West +3 40 £70,000 -34.20% 4
North West -8 30 £61,206 +36.77% 9
East of England +5 17 £65,000 -27.78% 3
Yorkshire +69 11 £79,842 -15.96% 1
West Midlands +13 7 £77,500 +31.91%
Midlands -7 7 £77,500 +31.91% 1
Scotland -79 7 £33,250 -27.32%
North East - 4 £79,842 - 3
Wales - 2 £72,500 - 2

OWASP
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 14 (4.49%) CMS
2 8 (2.56%) Confluence
3 6 (1.92%) EPiServer
4 5 (1.60%) IIS
5 3 (0.96%) Apache
5 3 (0.96%) Apache Spark
5 3 (0.96%) NServiceBus
Cloud Services
1 154 (49.36%) Azure
2 88 (28.21%) AWS
3 39 (12.50%) SaaS
4 36 (11.54%) Azure DevOps
5 19 (6.09%) Serverless
6 13 (4.17%) Cloud Computing
7 12 (3.85%) Entra ID
8 10 (3.21%) IaaS
8 10 (3.21%) PaaS
9 8 (2.56%) Microsoft 365
10 7 (2.24%) AWS Lambda
10 7 (2.24%) Pulumi
11 6 (1.92%) Azure API Management
11 6 (1.92%) Azure Service Bus
11 6 (1.92%) Azure Service Fabric
12 5 (1.60%) Azure Key Vault
12 5 (1.60%) Azure Monitor
13 4 (1.28%) Azure Sentinel
13 4 (1.28%) Azure Storage
14 3 (0.96%) OpenShift
Communications & Networking
1 35 (11.22%) Network Security
2 33 (10.58%) SD-WAN
2 33 (10.58%) WAN
3 22 (7.05%) Firewall
4 18 (5.77%) Internet
5 13 (4.17%) Wireless
6 11 (3.53%) Intrusion Detection
7 6 (1.92%) VPN
8 2 (0.64%) DNS
8 2 (0.64%) SSL
8 2 (0.64%) TCP/IP
8 2 (0.64%) VoIP
8 2 (0.64%) Wireshark
9 1 (0.32%) HTTP
9 1 (0.32%) IPv4
Database & Business Intelligence
1 42 (13.46%) SQL Server
2 19 (6.09%) Oracle Database
3 9 (2.88%) MongoDB
4 7 (2.24%) Azure SQL Database
5 4 (1.28%) InfluxDB
5 4 (1.28%) Relational Database
6 3 (0.96%) Elasticsearch
6 3 (0.96%) Redis
6 3 (0.96%) SQL Server Analysis Services
6 3 (0.96%) SQL Server Integration Services
6 3 (0.96%) SQL Server Reporting Services
7 2 (0.64%) MySQL
7 2 (0.64%) Power BI
8 1 (0.32%) Big Data
8 1 (0.32%) Data Lake
8 1 (0.32%) Data Warehouse
8 1 (0.32%) MariaDB
8 1 (0.32%) NoSQL
8 1 (0.32%) OLTP
Development Applications
1 55 (17.63%) Git
2 27 (8.65%) Visual Studio
3 17 (5.45%) NUnit
3 17 (5.45%) Oracle APEX
4 14 (4.49%) Burp Suite
5 13 (4.17%) Metasploit
6 10 (3.21%) Jenkins
6 10 (3.21%) Selenium
7 8 (2.56%) JIRA
8 7 (2.24%) Jasmine
8 7 (2.24%) MSTest
8 7 (2.24%) Postman
8 7 (2.24%) SoapUI
8 7 (2.24%) Team Foundation Server
8 7 (2.24%) TeamCity
8 7 (2.24%) Visual Studio Code
9 4 (1.28%) JMeter
9 4 (1.28%) Moq
9 4 (1.28%) Sonatype Nexus
10 3 (0.96%) Gradle
General
1 89 (28.53%) Social Skills
2 65 (20.83%) Finance
3 33 (10.58%) Marketing
4 26 (8.33%) Law
5 25 (8.01%) Analytical Skills
6 20 (6.41%) Inclusion and Diversity
7 17 (5.45%) Public Sector
8 14 (4.49%) Banking
9 11 (3.53%) Retail
10 10 (3.21%) Aerospace
10 10 (3.21%) Automotive
10 10 (3.21%) Telecoms
11 8 (2.56%) Legal
12 6 (1.92%) Presentation Skills
13 4 (1.28%) Welsh Language
14 2 (0.64%) Back Office
14 2 (0.64%) Influencing Skills
14 2 (0.64%) Police
15 1 (0.32%) Investment Banking
15 1 (0.32%) Mandarin Language
Job Titles
1 93 (29.81%) Architect
2 87 (27.88%) Senior
3 79 (25.32%) Developer
4 66 (21.15%) Security Architect
5 61 (19.55%) Lead
6 38 (12.18%) Security Manager
7 35 (11.22%) Senior Developer
8 33 (10.58%) Lead Architect
9 27 (8.65%) Lead Security Architect
10 26 (8.33%) .NET Developer
11 25 (8.01%) Technical Architect
12 23 (7.37%) Software Developer
13 19 (6.09%) Analyst
14 17 (5.45%) Security Analyst
15 16 (5.13%) Full Stack Developer
16 15 (4.81%) Lead Developer
17 14 (4.49%) Lead .NET Developer
18 12 (3.85%) Penetration Tester
18 12 (3.85%) Security Consultant
18 12 (3.85%) Senior Analyst
Libraries, Frameworks & Software Standards
1 76 (24.36%) .NET
2 54 (17.31%) REST
3 42 (13.46%) React
4 39 (12.50%) HTML
5 37 (11.86%) JSON
6 33 (10.58%) CSS
7 32 (10.26%) ASP.NET
8 27 (8.65%) .NET Framework
9 25 (8.01%) SOAP
9 25 (8.01%) Web Services
10 19 (6.09%) AngularJS
11 18 (5.77%) jQuery
11 18 (5.77%) OAuth
11 18 (5.77%) Vue
12 17 (5.45%) XML
13 16 (5.13%) .NET Core
14 13 (4.17%) Spring
15 12 (3.85%) HTML5
15 12 (3.85%) OAuth2
15 12 (3.85%) XSLT
Miscellaneous
1 56 (17.95%) Management Information System
2 34 (10.90%) IoT
3 33 (10.58%) Distributed Denial-of-Service
4 30 (9.62%) Product Ownership
5 24 (7.69%) Cloud Native
6 23 (7.37%) Mobile App
6 23 (7.37%) Security Posture
7 12 (3.85%) Self-Motivation
8 9 (2.88%) Data Centre
9 8 (2.56%) Distributed Systems
9 8 (2.56%) Public Cloud
10 5 (1.60%) Hybrid Cloud
10 5 (1.60%) Replication
11 4 (1.28%) Onboarding
12 3 (0.96%) Linux Command Line
12 3 (0.96%) Operational Technology
12 3 (0.96%) W3C
13 2 (0.64%) Cyber Threat
13 2 (0.64%) NHS
13 2 (0.64%) Security Operations Centre
Operating Systems
1 13 (4.17%) Linux
2 12 (3.85%) Kali Linux
3 7 (2.24%) Debian
3 7 (2.24%) Ubuntu
4 6 (1.92%) Unix
5 5 (1.60%) Apple iOS
6 3 (0.96%) Windows
7 1 (0.32%) Android
7 1 (0.32%) Mac OS
Processes & Methodologies
1 110 (35.26%) Agile
2 104 (33.33%) Application Security
3 91 (29.17%) Cybersecurity
4 87 (27.88%) Information Security
5 82 (26.28%) CI/CD
6 66 (21.15%) Mentoring
7 65 (20.83%) Secure Coding
8 59 (18.91%) Security Architecture
9 58 (18.59%) DevOps
9 58 (18.59%) Microservices
10 54 (17.31%) Penetration Testing
10 54 (17.31%) Test Automation
11 52 (16.67%) Problem-Solving
12 51 (16.35%) Vulnerability Management
13 49 (15.71%) SDLC
13 49 (15.71%) TDD
14 47 (15.06%) Coaching
15 45 (14.42%) Computer Science
16 38 (12.18%) DevSecOps
16 38 (12.18%) Software Engineering
Programming Languages
1 105 (33.65%) JavaScript
2 81 (25.96%) C#
3 78 (25.00%) SQL
4 48 (15.38%) Python
5 39 (12.50%) Java
6 24 (7.69%) TypeScript
7 17 (5.45%) PL/SQL
8 16 (5.13%) T-SQL
9 13 (4.17%) C
10 12 (3.85%) XPath
11 10 (3.21%) Bash
11 10 (3.21%) PowerShell
12 7 (2.24%) Bicep
13 6 (1.92%) R
13 6 (1.92%) Scala
14 4 (1.28%) Kusto Query Language
14 4 (1.28%) Swift
15 3 (0.96%) Shell Script
16 2 (0.64%) PHP
16 2 (0.64%) Ruby
Qualifications
1 80 (25.64%) CISSP
2 62 (19.87%) CISM
3 49 (15.71%) AWS Certification
3 49 (15.71%) Degree
4 46 (14.74%) Azure Certification
5 39 (12.50%) (ISC)2 CCSP
6 38 (12.18%) Cisco Certification
7 37 (11.86%) CCSP
8 33 (10.58%) CCSK
9 31 (9.94%) Computer Science Degree
10 22 (7.05%) OSCP
11 19 (6.09%) GIAC
12 16 (5.13%) CREST Certified
13 14 (4.49%) CEH
14 13 (4.17%) CISA
14 13 (4.17%) SANS
15 11 (3.53%) DBS Check
16 10 (3.21%) CompTIA CySA+
16 10 (3.21%) HNC
16 10 (3.21%) HND
Quality Assurance & Compliance
1 93 (29.81%) NIST
2 38 (12.18%) ISO/IEC 27001
3 28 (8.97%) Cyber Essentials
4 26 (8.33%) PCI DSS
5 20 (6.41%) GDPR
6 16 (5.13%) NCSC
7 15 (4.81%) GRC
8 13 (4.17%) Cyber Essentials PLUS
9 10 (3.21%) COBIT
9 10 (3.21%) SLA
10 9 (2.88%) Accessibility
10 9 (2.88%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
11 7 (2.24%) PMO
12 6 (1.92%) Actionable Recommendations
12 6 (1.92%) NIST 800
12 6 (1.92%) Web Application Security Consortium
13 3 (0.96%) ISO 31000
13 3 (0.96%) SOC 2
13 3 (0.96%) WCAG
14 2 (0.64%) ISO 9000
System Software
1 64 (20.51%) Docker
2 7 (2.24%) Virtual Machines
3 3 (0.96%) Active Directory
4 1 (0.32%) Hyper-V
Systems Management
1 57 (18.27%) Kubernetes
2 33 (10.58%) Single Sign-On
3 14 (4.49%) Nmap
4 13 (4.17%) Nessus
5 12 (3.85%) Computer Emergency Response Teams
6 11 (3.53%) Terraform
7 7 (2.24%) MIIS
8 6 (1.92%) Grafana
9 5 (1.60%) Kibana
9 5 (1.60%) Suricata
10 2 (0.64%) QRadar
11 1 (0.32%) Ansible
Vendors
1 60 (19.23%) Microsoft
2 23 (7.37%) Oracle
3 17 (5.45%) Qualys
4 7 (2.24%) Splunk
5 5 (1.60%) Cisco
5 5 (1.60%) Juniper
5 5 (1.60%) Palo Alto
6 2 (0.64%) Google
6 2 (0.64%) IBM
6 2 (0.64%) Tanium
7 1 (0.32%) CA
7 1 (0.32%) VMware