Share on social networks!

Pentesting jobs: why Spanish companies can't find enough ethical hackers.

More and more companies are seeking professionals capable of attacking their own systems before a cybercriminal can. Demand for penetration testing jobs is growing at over 201% annually, but the supply of qualified professionals is not keeping pace.

What is pentesting and why is it being talked about so much now?

Pentesting (or penetration testing) involves simulating real cyberattacks against an organization's systems to detect vulnerabilities before an attacker can exploit them. Those who perform this professionally are called pentesters or ethical hackers, and their work has become one of the most sought-after roles in cybersecurity.

It's not a new discipline, but its importance in the job market has changed significantly in recent years. Three factors explain this:

  • The sustained increase in cyberattacks against Spanish companies.
  • The entry into force of regulatory frameworks such as the NIS2 directive, which obliges many organizations to audit and demonstrate the security of their systems.
  • The structural shortage of professionals specializing in offensive security, a more technical and minority profile within the sector.

The result is a market where pentesting job offers often arrive before there are enough qualified candidates to fill them.

How many jobs are there really in cybersecurity and pentesting in Spain?

The data from latest sector study by INCIBE and CONETIC, The figures presented in March 2026 give an idea of the magnitude of the sector: cybersecurity already employs more than 164,000 professionals in Spain, a figure that has grown by more than 351% between 2021 and 2025 and represents a quarter of all employment in the ICT sector.

Despite this growth, the gap between supply and demand for talent remains. Various industry sources estimate the current shortage at between 20,000 and 30,000 unfilled cybersecurity positions in Spain, with demand growing at a rate of between 20.1% and 25.1% annually, according to data collected by the Spanish Confederation of Technology, Communications and Electronics Companies (CONETIC). Within that group, penetration testing is one of the most sought-after profiles and, at the same time, one of the most difficult to find, because it requires a combination of technical knowledge and practical experience that cannot be acquired solely through theoretical training.

Added to this is the pressure generated by the incidents themselves: INCIBE managed more than 122,000 cybersecurity incidents in 2025, a 261% increase over the previous year. Each of these incidents is, in a way, an argument in favor of hiring someone who can anticipate the problem before it occurs.

How much can you earn working in pentesting?

Salaries for this profile vary depending on experience, city, and type of company (consulting firms typically offer more competitive entry-level positions in exchange for rapid advancement; companies pay more for senior roles). As a guide, and based on various salary reports and job portals consulted in 2026:

  • Pentester junior: between €24,000 and €35,000 gross per year.
  • Profile with medium experience (3-6 years): between €35,000 and €50,000 gross per year.
  • Senior or red team profile: between €50,000 and €75,000 gross per year, with higher ceilings in uncommon specializations such as advanced cloud security, hardware hacking or OT/industrial security.

To put these figures into context: the average gross annual salary in Spain for any sector was €29,540 in 2024, according to the INE (National Institute of Statistics). A penetration tester with a couple of years of experience usually earns more than that average, and a senior technician more than doubles it without much difficulty.

What are companies really looking for when they hire a penetration tester?

Here's one of the points most frequently repeated by those managing recruitment processes in the sector: theoretical training alone isn't enough. Companies need people capable of handling a real-life incident from day one, not just passing a multiple-choice exam.

This explains why highly practical certifications, such as the OSCP, carry so much weight in the offensive arena, compared to those more focused on management or compliance. It also explains why many companies prefer to invest in internal training for existing staff: almost half of Spanish organizations rely on training their own team to fill cybersecurity vacancies, although only two out of ten internal positions are successfully filled this way, precisely because of the lack of candidates with sufficient practical experience.

How to enter the world of pentesting if you come from another technical background

The good news is that penetration testing is one of the few areas of cybersecurity where there isn't a single entry point. Professionals with prior training in development, systems administration, networking, or even other engineering fields usually have a sufficient foundation to specialize, provided they supplement that foundation with specific offensive knowledge: exploiting web vulnerabilities, auditing networks and infrastructure, Active Directory, cloud environments, and penetration testing methodologies recognized in the industry.

It is precisely at this point that specialized training makes the difference between a resume that gets stuck at the interview stage and one that lands the job. Programs like the Master's Degree in Cybersecurity from EIP Postgraduate Programyes They are designed to cover that gap: they combine the fundamentals of defensive security with specific modules on ethical hacking and pentesting, with a practical approach designed to ensure that students enter the job market with the real-world exposure that companies are demanding.

What to expect from the sector in the coming years

All indicators point to continued growth in penetration testing employment, not just sporadically, but steadily: increased regulation, a larger attack surface (cloud, IoT, AI), more incidents handled each year, and a pool of professionals that is not yet growing at the same rate as demand. For those considering specializing in this field, the current market offers something unusual in the tech industry: sustained demand, above-average salaries from the first year, and an entry path that doesn't necessarily require starting from scratch.

If you want to assess whether this path makes sense for your profile, you can consult the syllabus and career opportunities of Master's degree in cybersecurity from EIP and compare its content with what job offers in the sector are asking for today.

Hello
Subscribe to our newsletter to stay up to date with all the latest news

We don't spam! Read our Privacy Policy for more information.

EIP

Leave a comment

EIP International Business School informs you that the data in this form will be processed by Mainjobs Internacional Educativa y Tecnológica, SAU as the party responsible for this website. The purpose of collecting and processing personal data is to manage your subscription to the newsletter as well as to send commercial information about the services of the data controller. The legitimacy is the explicit consent of the interested party. Data will not be transferred to third parties, except under legal obligation. You may exercise your rights of access, rectification, limitation and deletion of data at cumplimiento@grupomainjobs.com, as well as the right to lodge a complaint with the supervisory authority. You can consult additional and detailed information on Data Protection in the Privacy Policy that you will find on our website.