How much an ethical hacker or pentester earns in Spain in 2026: salary ranges by seniority (junior, mid, senior, red team), the difference between an employment salary and bug bounty income, career paths and how to land your first job.
Gorka El Bochi
Founder of BBLABS
Quick answer: In Spain (2026), an ethical hacker or pentester earns, roughly, between €24,000–35,000 gross per year as a junior, €35,000–50,000 with mid-level experience, and €50,000–75,000 or more as a senior or in red team. These are rough ranges that vary by city, company and setup (remote work for foreign companies pays more). Careful: that's an employment salary, different from the variable income of bug bounty.
Before giving figures, a distinction almost nobody makes that changes everything: "ethical hacker" can mean two completely different income models.
This article is about the first model: the employment salary in Spain. Mix them up and you'll get the wrong idea about both.
All the figures that follow are rough ranges for the Spanish market, rounded and indicative. The real salary depends on the city, the size of the company, your specialization and —increasingly— whether you work remotely for a foreign company.
Roughly €24,000–35,000 gross per year. You come in doing guided pentests, helping with web and infrastructure audits, and learning the company's methodology. Here, having a good portfolio and some entry-level certification carries a lot of weight.
Roughly €35,000–50,000. You now run audits end to end, write reports without supervision and specialize (web, infra, cloud, mobile). This is the range where an OSCP or other recognized certs push the salary upward.
Roughly €50,000–70,000, and above in some cases. You lead projects, define methodology, act as a technical reference and deal with clients. Deep specialization (for example, cloud or application security) pays.
From €65,000–90,000+, with high ceilings at large companies, banking or tech. The red team simulates real, sustained attacks; it's among the best paid within offensive security. Adding scarce profiles (exploiting, reversing, advanced cloud) shoots the range up.
A 2026 nuance: more and more Spanish professionals work remotely for foreign companies (USA, rest of Europe) earning at international rates. There the ranges comfortably exceed the local market. If your profile and English allow it, it's the lever that moves the salary most.
This is the most common confusion, so I'll make it clear:
| Employment (pentester) | Bug bounty | |
|---|---|---|
| Type of income | Fixed salary | Variable rewards |
| Stability | High (payroll) | None guaranteed |
| Ceiling | Limited by the role | Very high but uncertain |
| Requirements | Contract, often hybrid | Only results |
| Taxation | Payroll | Variable income to declare |
The usual and sensible approach: start with employment (stability + paid learning) and do bug bounty in parallel as a supplement and showcase. They're not mutually exclusive; they reinforce each other.
"Pentester" isn't the only destination. Offensive security opens several doors, with salaries in similar or higher ranges:
The demand for cybersecurity profiles in Spain exceeds the supply, which keeps salaries trending upward and makes it easy to change companies to raise pay.
The sector values what you can demonstrate, more than degrees. To land your first role:
The winning combination for a first job is usually: solid fundamentals + a recognizable cert + a portfolio proving you already do the work. That last part is what almost nobody has and what differentiates you most.
Within the ranges above, your specific salary moves based on several factors:
Many people dream of quitting their job and living off bug bounty. The realistic path is the opposite: use employment as a stable base and bug bounty as a supplement that, over time, can grow.
The advantage of bug bounty isn't just the extra money: it's that it makes you a better professional and builds you a public profile that boosts your employment career. The two paths feed each other.
Cybersecurity is one of the few tech sectors with more openings than qualified professionals in Spain. That means several things for you:
The barrier isn't demand: it's proving you can do the work. And that's trained through practice (real-case labs), not promises.
How much does a junior pentester earn in Spain?
Roughly, between €24,000 and €35,000 gross per year, depending on city, company and your entry profile (portfolio and certs).
Do you earn more in bug bounty or with a pentester job?
Employment gives stable, predictable income; bug bounty has a much higher but uncertain and variable ceiling. The most sensible thing at first is to combine a salary with bug bounty as a supplement.
Do I need a degree to work as an ethical hacker?
It helps, but it's not essential. A demonstrable portfolio and hands-on certifications weigh much more. There are great professionals without a university degree.
Which certification do I get first to work?
To validate fundamentals, an eJPT is usually a good first step; for infrastructure pentesting, the OSCP is the industry standard. Always check the specific requirements of the roles you're aiming for.
In Spain, an employed ethical hacker earns roughly between €24,000 (junior) and €75,000+ (senior/red team), with international remote pushing the ceilings considerably higher. But don't confuse that stable salary with the variable income of bug bounty: they're different models that complement each other. To get in, what really makes the difference isn't a degree, but proving you can do the work: build a portfolio, get an entry-level cert and train the flaw pattern with real-case labs and an ordered path.
hunters training
labs from real reports
completions
in bounties practiced
Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime
What bug bounty really pays: average rewards by vulnerability type and severity, what top hunters earn, the reality for beginners and why most people don't make a living from it.
How to become an ethical hacker from scratch with no prior experience: what it is, whether you need to program, whether it's legal and the step-by-step roadmap (fundamentals → web → OWASP Top 10 → labs → first bug bounty). With realistic timelines and the mistakes that hold you back.
OSCP guide: what it is, what the exam evaluates (infrastructure pentest, Active Directory, 24h + report), who it's for, how to prepare, OSCP vs eJPT vs eWPT and why it's infrastructure pentesting, not web bug bounty (complementary).