Skip to content
h4ckercademy
Back to the blog

What does an ethical hacker earn in Spain?

August 14, 20265 min read

It's the question everyone asks and almost nobody answers with numbers. Here they are, with the caveat up front: these are ranges observed in published job ads and in industry conversations in Spain, not official statistics. Use them to orient yourself, not to quote in a negotiation.

The ranges, by level

Gross annual figures, full time, Spain.

LevelExperienceUsual range
Junior0-2 years€22,000 - €30,000
Mid2-5 years€30,000 - €45,000
Senior5+ years€45,000 - €65,000
Specialist / Lead8+ years€65,000 - €90,000

Two clarifications that change how you should read that:

  • The junior band is deceptively wide. A consultancy billing by the hour and needing volume will pay near the floor. A product company with its own security team starts considerably higher, but hires far fewer juniors.
  • From senior onwards the range explodes by specialism. A generalist pentester is not the same as someone doing cloud infrastructure security, reverse engineering or industrial systems auditing.

Why the same profile earns double

Four factors explain almost all of the gap.

1. Consultancy versus product

In consultancy you learn extremely fast because you touch twenty clients a year, but you're a billable cost and the margin comes out of your salary. At a product company you're an investment, and the range rises.

The classic path is to enter consultancy, burn two or three years, and jump. That jump is usually worth 20% to 40%.

2. Specialisation

Generalist is what's most abundant. What's scarce, and therefore paid:

  • Advanced Active Directory and hybrid environments. Half of Spanish corporate pentesting goes through here.
  • Cloud security (AWS, Azure, GCP). The industry moved and the profiles didn't.
  • Hardware and embedded systems. Few people, and the ones there are tend to be very good. If it appeals to you, the Flipper Zero course is a very reasonable way in.
  • Reverse engineering and malware analysis. The highest ceiling and also the steepest curve.

3. Remote work for companies abroad

A remote contract with a European or US company, paid on their scale while living in Spain, is the biggest single salary jump available in this field. It's also the most competitive: you need real English and a public profile that survives international comparison.

4. Knowing how to negotiate

It sounds like a cliché, but in this particular field it weighs a lot because technical people negotiate badly. Two pieces of advice worth money:

  • Don't give the first number. If they insist, give a range whose floor is your target.
  • A counteroffer when you already have another offer on the table is the only lever that reliably works.

Freelance and bug bounty

Freelance: a day of pentesting typically bills between €400 and €900, depending on specialism and client. That sounds great until you subtract the months without projects, social security contributions, VAT, the holidays nobody pays you for, and the time spent selling. For it to genuinely pay off you need recurring clients, and that's two or three years of building.

Bug bounty: the income distribution is brutally uneven. A handful of researchers live very well off it and the vast majority make a modest supplement. Its real value, especially at the start, isn't the money: it's having public, verifiable findings to show.

What raises your pay and what doesn't

Raises it:

  • Specialising in something with few available professionals.
  • Changing company. Yes, it's still the most effective mechanism.
  • Writing well. The pentester who produces impeccable reports ends up handling the big clients.
  • English. It's the difference between the Spanish market and the whole market.
  • Speaking publicly: talks, articles, published tooling.

Doesn't raise it as much as you'd expect:

  • Collecting certifications. The first opens doors, the fourth doesn't. On which are worth it and in what order, see cybersecurity certifications.
  • Knowing lots of tools. That's assumed.
  • Seniority on its own. Five years doing the same thing is one year repeated five times.

Is it worth getting in today?

Yes, with two honest caveats.

First: the entry bar has risen. Eight years ago handling Metasploit was enough. Today a junior is expected to understand Active Directory, move around in cloud, and write a presentable report.

Second: the first rung is the hardest. Getting the first job costs considerably more than the second, and that first year pays little. From there the curve is among the best in tech, and demand still outstrips supply.

If you're deciding whether to take the step, the full route — what to study, in what order and how long it really takes — is in how to become an ethical hacker from scratch.

And if you want to start today without spending a euro, the Kali Linux course is free and takes you from an empty virtual machine to your first documented audit. It's the best possible test of whether you enjoy this before investing two years in it.

Carry on here

The course this article leads into

Frequently asked questions

What does a junior pentester earn in Spain?

Junior consultancy roles typically advertise between €22,000 and €30,000 gross per year. In product companies or firms with an in-house security team, the entry range usually starts somewhat higher.

What does a senior pentester earn?

With five or more years and a specialism, the normal band in Spain is €45,000 to €65,000. Above that you find highly specialised profiles, people leading teams, and those working remotely for companies abroad.

Does Red Team pay more than Blue Team?

At equal experience they're fairly level. Red Team has better image and Blue Team has more open positions, so supply and demand end up balancing the pay.

Is bug bounty worth it as income?

As a primary income, for very few people. As a supplement — and above all as a way to build a public track record of findings to show in an interview — it's very much worth it.

#career#salaries#ethical hacking#jobs

Keep reading

h4ckercademy

The whole catalogue on one subscription

A single monthly or yearly payment and access to every course, the current ones and whatever comes next.

See pricing