There are many, many firms that bill for web scanning and static analysis. Their business model boils down to, buy a bunch of tools for <$10,000, resell their usage on engagements for >$5,000 per week. They leave a trail of horror stories in their wake eventually. Starting a consulting shop is a great opportunity if you have the requisite skill/experience, and can differentiate yourself from the snake oil salesmen of the industry and the monolithic firms everyone knows.
The industry for internal security engineers as well as outside security consultants is growing at a healthy pace. In my circles, people usually need to widely advertise a position to get it filled by someone qualified. In one case, a friend of mine at a tech company informed me that he had only one candidate pass the phone screen in three months despite posting the position here on HN, on /r/netsec, etc.
Consulting firms are a different sort of beast because they are usually always hiring. Every security consultant added to a growing firm directly increases the total amount of potential revenue, and most successful firms have to start turning away work at a certain point (for example, I no longer take on work for network security because I find it unenjoyable, I would much rather work on reverse engineering and application security engagements).
Everything I've said is US-centric, but hopefully it's reasonably helpful and relevant to you in the UK. I know a few bug bounty-turned-security-consultant people in the UK and they seem to be reasonably well off, but they could be outliers (in fact they are, skill-wise).