The first thing I noticed was a pattern. Last autumn, three of my best pen testers - all London-based, all with CREST certifications - vanished to California within weeks of each other. Not coincidence. Just economics.
There's a brutal equation at work here that UK employers need to face: Silicon Valley will pay your ethical hackers double what you're offering, throw in equity that might actually be worth something, and give them problems at a scale most British security professionals can only dream about.
The brain drain is real, it's accelerating, and if you're trying to build or maintain a security team in 2026, you're feeling it.
The compensation gap is worse than you think
Let's talk actual numbers. In my corner of recruitment, I'm seeing UK-based penetration testers with 5+ years of experience topping out around £95-110K in London. The same professional, with the same skills, will command $180-220K base (roughly £140-170K) in Silicon Valley - before stock options, signing bonuses, and the rest.
For senior security researchers, particularly those with AI safety experience or zero-day discovery track records, the gulf becomes an ocean. One candidate I placed last month - a specialist in ML model security testing - jumped from £125K at a UK fintech to a $280K base package at a major Valley tech firm.
But salary is just the start of it.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
More than money: the scale equation
Money gets them on the plane. What keeps them there is working on systems used by billions, not thousands.
Talked with a former GCHQ-adjacent security researcher recently. She'd turned down three UK offers before accepting a role with one of the ARR titans. Her reasoning stuck with me: "In the UK I'd be working on systems used by thousands. Here I'm finding vulnerabilities in products used by billions."
That's the emotional pull Silicon Valley has mastered. Beyond cash, it's the impact that pulls people there. When you've spent years honing the ability to think like an attacker, you want your defensive work to matter at maximum scale.
Combine that with access to the most advanced security tooling and research budgets that don't require six approval signatures for a £2,000 test environment, and you've got a compelling case.
The cultural element nobody talks about
UK security culture can be oddly deferential. Too hierarchical. There's still this lingering notion that security researchers should be grateful for a seat at the table.
Silicon Valley flipped that script years ago. Security researchers there are kingmakers, not service providers. They're brought in at the architecture phase, not as last-minute compliance checkers.
One London CISO I worked with summarised it perfectly: "In the UK, security is a cost centre. In Silicon Valley, it's a competitive advantage."
That mindset difference translates to day-to-day autonomy. Ethical hackers want to be trusted to pursue interesting vectors without constantly justifying their existence to procurement teams who see them as an expensive luxury.
The remote work factor
I thought the remote revolution might stem the tide. Surely UK security professionals could command Valley-adjacent salaries while working from their Hackney flats or Cotswolds cottages?
Not quite working out that way.
The most strategic Valley firms are requiring in-person presence for security roles. They'll let the marketing team go remote, but not the people who understand their crown jewels and attack surfaces.
Why? Security is collaborative, requires intense trust, and benefits from osmotic knowledge transfer. Also, bluntly, the most interesting security challenges involve physical access to hardware labs, RFID systems, and prototype environments.
So what can UK employers actually do?
Stop assuming competitive UK market rates are globally competitive. If you want to keep top security talent from emigrating, you need to bridge at least part of that compensation gap.
But assuming you can't double salaries overnight (and most can't), here's what I've seen work:
1. Create research time that actually happens
Every company claims to offer "20% time" or "innovation Fridays." But how often do those get sacrificed to client emergencies or deployment schedules?
The best security employers I work with treat research time as sacred. It's not a perk; it's business critical. One London security consultancy actually blocks client meetings on Thursdays so their pen testers can pursue independent research threads.
And they publish the results under the researchers' own names - not sanitised under a corporate brand. Attribution matters enormously to security professionals building personal brands.
2. Path to equity that means something
British companies are terrible at this. Stock options that vest over geological timescales with so many liquidation preferences they're effectively worthless.
If you're a UK startup competing for security talent, make your equity grants genuinely valuable and comprehensible. One Cambridge security firm I work with redesigned their entire equity structure after losing three researchers in a quarter. The new approach? Shorter vesting periods, clear valuation metrics, and quarterly updates on what those shares might actually be worth.
3. Surgical use of contracting models
Sometimes the best way to keep a security researcher is to not employ them full-time. For specialists with niche expertise, I've seen success with structured consulting relationships that pay premium day rates for focused work.
This model satisfies the researcher's need for variety and the employer's need for specialised skills without requiring exclusivity that can't be financially justified.
How does this help retention? It creates spaces for your security talent to do varied work while maintaining their relationship with you. It's not perfect, but it beats watching them disappear to Mountain View.
Build careers, not just jobs
The most successful security employers I work with take a long view of talent development, building career pipelines rather than filling headcount slots.
A London-based bank I recruit for has established a remarkable security talent pipeline. They sponsor university CTF competitions, offer meaningful internships where students actually get to do real security work (not just coffee runs), and maintain relationships with talent even when they leave.
Their CISO deliberately encourages security staff to do external conference presentations, contributes to open source security tooling, and has created informal alumni networks that often result in boomerang hires returning with Silicon Valley experience.
Specialisation is your friend
You can't compete with Meta or Google on breadth, so don't try. Instead, become the absolute pinnacle for a specific security niche.
A Manchester firm I work with has become the go-to for automotive security research. They don't try to match Silicon Valley salaries across the board, but they've created such a concentration of expertise in their vertical that researchers focused on that domain choose them over bigger names.
Generalists will always be vulnerable to poaching.
A hard truth to end on
Some brain drain is inevitable. The UK security community benefits from having alumni in senior Valley positions. They become champions for UK talent, create knowledge transfer channels, and sometimes even fund UK security startups.
Rather than fighting an unwinnable battle to plug every leak in the talent dam, smart UK employers are focusing on building sustainable security team models that can absorb some turnover while maintaining institutional knowledge.
But it starts with honesty about the problem. The compensation gap is real. The opportunity gap is real. UK employers who acknowledge this reality instead of hand-waving it away are the only ones who stand a chance of building security teams that last.
For those recruiting security researchers right now, this is the hardest market I've seen in eight years of specialist work. But at least now you know why.
Find specialist cybersecurity recruiters who understand the unique challenges of placing ethical hackers and security researchers in today's competitive landscape.
Hannah Fletcher is an agritech and sustainability recruitment specialist who occasionally ventures into cybersecurity talent trends. She writes about the intersection of technology talent markets and sector-specific recruitment challenges.

