More and more companies are seeking professionals capable of attacking their own systems before a cybercriminal can. Demand for penetration testing jobs is growing at over 201% annually, but the supply of qualified professionals is not keeping pace.
What is pentesting and why is it being talked about so much now?
Pentesting (or penetration testing) involves simulating real cyberattacks against an organization's systems to detect vulnerabilities before an attacker can exploit them. Those who perform this professionally are called pentesters or ethical hackers, and their work has become one of the most sought-after roles in cybersecurity.
It's not a new discipline, but its importance in the job market has changed significantly in recent years. Three factors explain this:
- The sustained increase in cyberattacks against Spanish companies.
- The entry into force of regulatory frameworks such as the NIS2 directive, which obliges many organizations to audit and demonstrate the security of their systems.
- The structural shortage of professionals specializing in offensive security, a more technical and minority profile within the sector.
The result is a market where pentesting job offers often arrive before there are enough qualified candidates to fill them.
How many jobs are there really in cybersecurity and pentesting in Spain?
The data from latest sector study by INCIBE and CONETIC, The figures presented in March 2026 give an idea of the magnitude of the sector: cybersecurity already employs more than 164,000 professionals in Spain, a figure that has grown by more than 351% between 2021 and 2025 and represents a quarter of all employment in the ICT sector.
Despite this growth, the gap between supply and demand for talent remains. Various industry sources estimate the current shortage at between 20,000 and 30,000 unfilled cybersecurity positions in Spain, with demand growing at a rate of between 20.1% and 25.1% annually, according to data collected by the Spanish Confederation of Technology, Communications and Electronics Companies (CONETIC). Within that group, penetration testing is one of the most sought-after profiles and, at the same time, one of the most difficult to find, because it requires a combination of technical knowledge and practical experience that cannot be acquired solely through theoretical training.
Added to this is the pressure generated by the incidents themselves: INCIBE managed more than 122,000 cybersecurity incidents in 2025, a 261% increase over the previous year. Each of these incidents is, in a way, an argument in favor of hiring someone who can anticipate the problem before it occurs.
How much can you earn working in pentesting?
Salaries for this profile vary depending on experience, city, and type of company (consulting firms typically offer more competitive entry-level positions in exchange for rapid advancement; companies pay more for senior roles). As a guide, and based on various salary reports and job portals consulted in 2026:
- Pentester junior: between €24,000 and €35,000 gross per year.
- Profile with medium experience (3-6 years): between €35,000 and €50,000 gross per year.
- Senior or red team profile: between €50,000 and €75,000 gross per year, with higher ceilings in uncommon specializations such as advanced cloud security, hardware hacking or OT/industrial security.
To put these figures into context: the average gross annual salary in Spain for any sector was €29,540 in 2024, according to the INE (National Institute of Statistics). A penetration tester with a couple of years of experience usually earns more than that average, and a senior technician more than doubles it without much difficulty.
What are companies really looking for when they hire a penetration tester?
Here's one of the points most frequently repeated by those managing recruitment processes in the sector: theoretical training alone isn't enough. Companies need people capable of handling a real-life incident from day one, not just passing a multiple-choice exam.
This explains why highly practical certifications, such as the OSCP, carry so much weight in the offensive arena, compared to those more focused on management or compliance. It also explains why many companies prefer to invest in internal training for existing staff: almost half of Spanish organizations rely on training their own team to fill cybersecurity vacancies, although only two out of ten internal positions are successfully filled this way, precisely because of the lack of candidates with sufficient practical experience.
How to enter the world of pentesting if you come from another technical background
The good news is that penetration testing is one of the few areas of cybersecurity where there isn't a single entry point. Professionals with prior training in development, systems administration, networking, or even other engineering fields usually have a sufficient foundation to specialize, provided they supplement that foundation with specific offensive knowledge: exploiting web vulnerabilities, auditing networks and infrastructure, Active Directory, cloud environments, and penetration testing methodologies recognized in the industry.
It is precisely at this point that specialized training makes the difference between a resume that gets stuck at the interview stage and one that lands the job. Programs like the Master's Degree in Cybersecurity from EIP Postgraduate Programyes They are designed to cover that gap: they combine the fundamentals of defensive security with specific modules on ethical hacking and pentesting, with a practical approach designed to ensure that students enter the job market with the real-world exposure that companies are demanding.
What to expect from the sector in the coming years
All indicators point to continued growth in penetration testing employment, not just sporadically, but steadily: increased regulation, a larger attack surface (cloud, IoT, AI), more incidents handled each year, and a pool of professionals that is not yet growing at the same rate as demand. For those considering specializing in this field, the current market offers something unusual in the tech industry: sustained demand, above-average salaries from the first year, and an entry path that doesn't necessarily require starting from scratch.
If you want to assess whether this path makes sense for your profile, you can consult the syllabus and career opportunities of Master's degree in cybersecurity from EIP and compare its content with what job offers in the sector are asking for today.






























