BBLABS v2BBLABSv2
>Home>Labs
>New labs

Latest 3 labs

Loading…

View all labs →
>Creators>Ranking
>Learn

Learn bug bounty

AcademyGuides, cheatsheets and glossaryVulnerabilitiesXSS, SQLi, IDOR, SSRF and moreHunter RoadmapYour step-by-step bug bounty pathBlogBug bounty guides and news
>Business>Pricing
ES
Log inLog in
>Home>Labs>New labs>Creators>Ranking>Learn>Business>Pricing
ES
Sign inCreate account

Contact

Practice, learn and hack

Bug bounty practice platform with labs based on real reports. Learn ethical hacking in safe environments.

contact→

Follow us

YouTube
@0xGorka
X
@gorkaelbochi
LinkedIn
gorka-el-bochi-morillo
Instagram
@_.gorkaaa.b
Email
team@bblabs.es

Access every lab from €7.99/mo

New labs every week. Cancel anytime.

Create account

BBLabs is the bug bounty labs platform where you learn bug bounty with real vulnerabilities extracted from paid reports on HackerOne, Bugcrowd and Intigriti. Here you practice web hacking —XSS, SQLi, IDOR, SSRF, CSRF and more— in downloadable environments, capture the flag, read the writeup and apply the technique on active bug bounty programs.

BBLabs is the alternative to HackTheBox, TryHackMe and PentesterLab for those who want to practice bug bounty with real reports instead of artificial CTFs. From €7.99/mo, no commitment.

→ Learn bug bounty from scratch→ How to do bug bounty step by step→ Real bug bounty reports→ BBLabs for companies and academiesLabsAcademyVulnerabilitiesToolsHunter rankingXSS labsIDOR labsSSRF labsCSRF labsHackTheBox alternativeHack4u alternativeTryHackMe alternativePortSwigger alternativePentesterLab alternativeBug Bounty Labs comparisonHackerOne to practiceOffSec / OSCP alternativeINE / eWPT alternativeHTB Academy alternativeDVWA alternativeJuice Shop alternativeVulnHub alternativePentesterAcademy alternativeRoot-Me alternativeHackTheBox vs TryHackMeBest bug bounty platforms 2026BlogSpoilersWhat is bug bounty?How much do you earn in bug bounty?OWASP Top 10 explainedBest sites to practice web hackingHow to become an ethical hacker from scratchBurp Suite tutorial (Spanish)OSCP guide and prepGoogle Dorks for bug bountyHow much an ethical hacker earns in SpainBug bounty tools 2026Best cybersecurity certifications 2026Burp Suite tutorialsqlmap tutorialffuf web fuzzingnuclei tutorialHTTP Request SmugglingWAF bypassPrompt injection (LLM)Google Dorks
Made withand code
TermsPrivacyComparisonES

© 2026 BBLABS v2 — All rights reserved

back to blog
career

How much an ethical hacker / pentester earns in Spain (2026)

How much an ethical hacker or pentester earns in Spain in 2026: salary ranges by seniority (junior, mid, senior, red team), the difference between an employment salary and bug bounty income, career paths and how to land your first job.

GEB

Gorka El Bochi

Founder of BBLABS

2026-07-2112 min read
#salary#career#pentester#employment#ethical-hacker

Quick answer: In Spain (2026), an ethical hacker or pentester earns, roughly, between €24,000–35,000 gross per year as a junior, €35,000–50,000 with mid-level experience, and €50,000–75,000 or more as a senior or in red team. These are rough ranges that vary by city, company and setup (remote work for foreign companies pays more). Careful: that's an employment salary, different from the variable income of bug bounty.

How much does an ethical hacker earn in Spain?

Before giving figures, a distinction almost nobody makes that changes everything: "ethical hacker" can mean two completely different income models.

  1. Employment (pentester / red teamer / offensive security analyst): you earn a fixed salary working at a company or consultancy. Stable, with a payroll, holidays and a contract.
  2. Bug bounty: you earn variable rewards for each flaw you report in public programs. No boss, no salary, no guarantee. I detail it in how much you earn in bug bounty.

This article is about the first model: the employment salary in Spain. Mix them up and you'll get the wrong idea about both.

All the figures that follow are rough ranges for the Spanish market, rounded and indicative. The real salary depends on the city, the size of the company, your specialization and —increasingly— whether you work remotely for a foreign company.

Pentester salary in Spain by seniority

Junior / offensive security analyst (0–2 years)

Roughly €24,000–35,000 gross per year. You come in doing guided pentests, helping with web and infrastructure audits, and learning the company's methodology. Here, having a good portfolio and some entry-level certification carries a lot of weight.

Mid pentester (2–4 years)

Roughly €35,000–50,000. You now run audits end to end, write reports without supervision and specialize (web, infra, cloud, mobile). This is the range where an OSCP or other recognized certs push the salary upward.

Senior / lead pentester (5+ years)

Roughly €50,000–70,000, and above in some cases. You lead projects, define methodology, act as a technical reference and deal with clients. Deep specialization (for example, cloud or application security) pays.

Red team / elite specialist

From €65,000–90,000+, with high ceilings at large companies, banking or tech. The red team simulates real, sustained attacks; it's among the best paid within offensive security. Adding scarce profiles (exploiting, reversing, advanced cloud) shoots the range up.

The remote factor

A 2026 nuance: more and more Spanish professionals work remotely for foreign companies (USA, rest of Europe) earning at international rates. There the ranges comfortably exceed the local market. If your profile and English allow it, it's the lever that moves the salary most.

Employment salary vs bug bounty income (don't confuse them)

This is the most common confusion, so I'll make it clear:

Employment (pentester) Bug bounty
Type of income Fixed salary Variable rewards
Stability High (payroll) None guaranteed
Ceiling Limited by the role Very high but uncertain
Requirements Contract, often hybrid Only results
Taxation Payroll Variable income to declare
  • A pentester with a good salary has predictable income: they know what they earn at the end of the month.
  • A bug bounty hunter can make €5,000 one month and €0 the next two. The ceiling is very high (the best exceed six figures a year), but the real median for someone starting out is low and many don't make a living from it alone. The honest figures are in how much you earn in bug bounty.

The usual and sensible approach: start with employment (stability + paid learning) and do bug bounty in parallel as a supplement and showcase. They're not mutually exclusive; they reinforce each other.

Career paths in ethical hacking

"Pentester" isn't the only destination. Offensive security opens several doors, with salaries in similar or higher ranges:

  • Pentester / security auditor: the classic, at a consultancy or in-house.
  • Red teamer: advanced, continuous adversary simulation.
  • Application Security (AppSec) engineer: security integrated into the development cycle; highly in demand and well paid.
  • Cloud security: offensive security on AWS/GCP/Azure. The scarcity of profiles pushes salaries up.
  • SOC analyst / blue team: more defensive, a good entry door into the sector.
  • Full-time bug bounty hunter: for the top who achieve stable income by reporting.

The demand for cybersecurity profiles in Spain exceeds the supply, which keeps salaries trending upward and makes it easy to change companies to raise pay.

How to land your first ethical hacking job?

The sector values what you can demonstrate, more than degrees. To land your first role:

  1. Build a public portfolio. Writeups of solved labs and CTFs, a GitHub with your scripts, a technical blog. It's your real calling card.
  2. Have a public hunter profile. A ranking of solved flaws and demonstrable activity says more than any CV. Reproducing real flaws in labs and showing it is direct evidence that you can do the job.
  3. Get an entry-level certification. An eJPT to validate fundamentals, and in the medium term the OSCP if you're going into infra pentesting. Many HR filters ask for them.
  4. Master what pays. Access control, injections, SSRF, business logic: the OWASP Top 10 families that show up in every audit. Train them with an ordered path.
  5. Move within the community. Events, Discords, team CTFs. Many first opportunities come from word of mouth, not from a job portal.

The winning combination for a first job is usually: solid fundamentals + a recognizable cert + a portfolio proving you already do the work. That last part is what almost nobody has and what differentiates you most.

What does your salary as an ethical hacker depend on?

Within the ranges above, your specific salary moves based on several factors:

  • Location. Madrid and Barcelona pay above the national average; in small cities or the public sector the ranges drop. Remote breaks this rule: it decouples you from the local market.
  • Type of company. A security consultancy, a big tech firm, banking or a startup pay in very different ways. Banking and large tech firms tend to be at the top end.
  • Specialization. Scarce profiles —cloud security, exploitation, reversing, application security— pay better than the generalist. Specialization is the most profitable lever in the medium term.
  • Certifications. An OSCP or other recognized certs help you pass filters and negotiate a band. They don't raise the salary on their own, but they open doors that would otherwise be closed.
  • Languages. Good English opens up the international remote market, where the ranges far exceed Spanish ones.
  • A demonstrable public profile. Writeups, a lab ranking, CTFs, talks. Arriving with evidence that you already do the work puts you above a bare CV.

Bug bounty as a supplement: numbers with your feet on the ground

Many people dream of quitting their job and living off bug bounty. The realistic path is the opposite: use employment as a stable base and bug bounty as a supplement that, over time, can grow.

  • At first, bug bounty rarely covers a salary. It's common to spend months with small or zero income while you learn.
  • With fluency, a supplement of a few hundred to a few thousand euros a year is a reasonable goal for someone who dedicates hours consistently.
  • Only a minority turn bug bounty into their main income, and it's usually after years of track record. The honest figures are in how much you earn in bug bounty.

The advantage of bug bounty isn't just the extra money: it's that it makes you a better professional and builds you a public profile that boosts your employment career. The two paths feed each other.

The sector in Spain: demand and future

Cybersecurity is one of the few tech sectors with more openings than qualified professionals in Spain. That means several things for you:

  • High employability if you demonstrate real skills, even without years of experience.
  • Mobility to raise your salary: changing companies periodically is usually the fastest route to a higher pay.
  • A growing ceiling as you specialize and as international remote comes into play.

The barrier isn't demand: it's proving you can do the work. And that's trained through practice (real-case labs), not promises.

Frequently asked questions (FAQ)

How much does a junior pentester earn in Spain?
Roughly, between €24,000 and €35,000 gross per year, depending on city, company and your entry profile (portfolio and certs).

Do you earn more in bug bounty or with a pentester job?
Employment gives stable, predictable income; bug bounty has a much higher but uncertain and variable ceiling. The most sensible thing at first is to combine a salary with bug bounty as a supplement.

Do I need a degree to work as an ethical hacker?
It helps, but it's not essential. A demonstrable portfolio and hands-on certifications weigh much more. There are great professionals without a university degree.

Which certification do I get first to work?
To validate fundamentals, an eJPT is usually a good first step; for infrastructure pentesting, the OSCP is the industry standard. Always check the specific requirements of the roles you're aiming for.

Conclusion

In Spain, an employed ethical hacker earns roughly between €24,000 (junior) and €75,000+ (senior/red team), with international remote pushing the ceilings considerably higher. But don't confuse that stable salary with the variable income of bug bounty: they're different models that complement each other. To get in, what really makes the difference isn't a degree, but proving you can do the work: build a portfolio, get an entry-level cert and train the flaw pattern with real-case labs and an ordered path.

share
share:
hunters training
650

hunters training

labs from real reports
50

labs from real reports

completions
380

completions

in bounties practiced
$200,000

in bounties practiced

40 flags captured this week·Real reports from HackerOne · Bugcrowd · Intigriti·No commitment·Free Academy
BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.

Create free accountSee the labs

No card · free Academy · cancel anytime

[RELATED_POSTS]

Continue Reading

guides

How much you earn in bug bounty (real figures 2026)

What bug bounty really pays: average rewards by vulnerability type and severity, what top hunters earn, the reality for beginners and why most people don't make a living from it.

2026-06-25•12 min read
guides

How to become an ethical hacker from scratch: 2026 roadmap (no prior experience)

How to become an ethical hacker from scratch with no prior experience: what it is, whether you need to program, whether it's legal and the step-by-step roadmap (fundamentals → web → OWASP Top 10 → labs → first bug bounty). With realistic timelines and the mistakes that hold you back.

2026-07-21•14 min read
guides

OSCP guide: what it is, how to prepare and whether it's worth it (2026)

OSCP guide: what it is, what the exam evaluates (infrastructure pentest, Active Directory, 24h + report), who it's for, how to prepare, OSCP vs eJPT vs eWPT and why it's infrastructure pentesting, not web bug bounty (complementary).

2026-07-21•13 min read