Penetration testers (ethical hackers) simulate cyberattacks against networks, applications and infrastructure to identify security weaknesses before criminals do. Most UK testers work for specialist security consultancies, Big Four firms or in-house security teams at banks and large enterprises, though independent contracting is unusually common in this field compared with other IT roles. Salaries range from around GBP 28,000 for a junior tester to GBP 130,000 or more for a principal consultant, with experienced contractors charging GBP 400--GBP 1,000 per day. This guide covers salary bands and estimated take-home pay after Income Tax and National Insurance for 2026/27.
| Level | Salary range | Notes |
|---|---|---|
| Junior / Associate Penetration Tester | GBP 28,000--GBP 38,000 | CompTIA Security+ or CPSA; working towards CRT |
| Penetration Tester (CREST Registered) | GBP 42,000--GBP 55,000 | CRT-qualified; leads standard web/infra engagements |
| Senior Penetration Tester | GBP 58,000--GBP 78,000 | CCT or OSCP/OSCE; scopes and leads complex engagements |
| Principal Consultant / Head of Offensive Security | GBP 90,000--GBP 130,000+ | Practice leadership; red team programme ownership |
| Freelance / Contract Penetration Tester | GBP 400--GBP 1,000/day | Independent or limited company; IR35 status dependent |
CREST certification level is the dominant pay driver in this field alongside seniority; CHECK (NCSC) status adds a further premium for government-sector work.
2026/27 UK rates for permanent employment. Personal Allowance GBP 12,570. Contractor take-home differs substantially depending on IR35 status -- see the day rate calculator.
| Scenario | Gross | Income tax | NI | Net/year | Net/month | Keep % |
|---|---|---|---|---|---|---|
| Junior (entry) | GBP 30,000 | GBP 3,486 | GBP 1,394 | GBP 25,120 | GBP 2,093/mo | 84% |
| Junior (top) | GBP 38,000 | GBP 5,086 | GBP 2,034 | GBP 30,880 | GBP 2,573/mo | 81% |
| CREST Registered (typical) | GBP 48,000 | GBP 7,086 | GBP 2,834 | GBP 38,080 | GBP 3,173/mo | 79% |
| Senior Tester (typical) | GBP 68,000 | GBP 14,632 | GBP 3,371 | GBP 49,997 | GBP 4,166/mo | 74% |
| Principal Consultant (London) | GBP 110,000 | GBP 33,432 | GBP 4,211 | GBP 72,357 | GBP 6,030/mo | 66% |
For contract day-rate take-home, use the day rate calculator or the contractor take-home calculator.
Entry into penetration testing typically comes via a cyber security or computer science degree, a cyber apprenticeship, or a career change from a wider IT or systems administration background combined with self-study and entry-level certifications. CREST, the UK's leading accreditation body for the sector, provides the dominant career ladder: CPSA (foundation), CRT (Registered Tester, needed to sign off most client-facing engagements independently) and CCT (Certified, the senior practitioner standard). Offensive Security's OSCP and OSCE certifications are also widely respected and often required by employers alongside or instead of CREST grades.
Specialist security consultancies (NCC Group, Pen Test Partners, Bulletproof, F-Secure Consulting and similar) employ the largest concentration of testers and offer the clearest technical progression ladder, typically running engagements across many client sectors. Big Four and large IT consultancies run offensive security practices as part of broader cyber risk services, often paying comparably but with more client-relationship and reporting overhead. In-house security teams at banks, insurers, telecoms and large retailers employ testers directly, particularly for continuous or high-frequency testing programmes, generally offering better work-life balance and benefits than consultancy but a narrower breadth of engagement types. Government and defence-sector testing, gated by NCSC CHECK status, forms a further distinct segment with its own clearance and pay structure.
London and the wider South East host the majority of consultancy and financial-services in-house roles and pay a clear premium, but penetration testing is unusually remote-friendly compared with many other professions on this site -- engagements are typically delivered against defined scopes and reports rather than requiring daily physical presence, so a meaningful share of testers work fully or largely remotely for employers based anywhere in the UK, somewhat narrowing the effective regional pay gap for experienced practitioners.
Self-employment and limited-company contracting are considerably more common in penetration testing than in most other technology disciplines. Because assessments are naturally project-based and organisations often need only periodic or annual testing, many experienced testers move to independent or small-boutique contracting once they have built a CREST-accredited track record and client network, trading the stability of permanent employment for higher day rates, variety of client work and greater control over their schedule -- subject to navigating IR35 status on each engagement.