Explore
Offensive security
Penetration Tester
Paid to break in, and then to write it all down.
Typical pay
$85k-$160k
How you get in
Security foundation plus OSCP or equivalent
Outlook
Strong; offensive security talent is scarce
Penetration testers attack systems with permission to find vulnerabilities before criminals do. The hacking is the fun part and roughly a third of the job; the report is the deliverable clients actually pay for.
A day in the life
- 9:00aScope confirmation and rules of engagement with the client
- 9:30aReconnaissance and enumeration of the target
- 12:00pLunch
- 1:00pExploitation attempts and privilege escalation
- 3:30pDocument findings with reproduction steps and evidence
- 5:00pWrite the report — the actual deliverable
How to get in
Security analyst into offensive
Duration
2-4 years
Cost
$1,500-$8,000
Credential
OSCP (Offensive Security Certified Professional)
- Build a foundation in networking, Linux and systems administration first
- Work in a SOC or security engineering role
- Practice constantly on legal platforms — Hack The Box, TryHackMe, CTFs
- Earn the OSCP, which is the industry's practical benchmark
Certification-led with a lab
Duration
1-2 years
Cost
$2,000-$10,000
Credential
OSCP, plus PNPT or CRTP
- Build a home lab and learn to attack it
- Stack practical, hands-on certifications rather than multiple-choice ones
- Publish write-ups and CTF results as public evidence of skill
- Apply to consultancies, which hire more openly on demonstrated ability
Developer into application security
Duration
1-3 years
Cost
$1,000-$6,000
Credential
OSWE or web-focused certifications
- Work as a software developer and learn how applications actually break
- Specialize in web and API security testing
- Add application security certifications
- Developers who pivot are unusually effective at finding real logic flaws
What people love
- · Genuinely fascinating technical work
- · Strong pay and remote-friendly
- · Certifications matter more than degrees
- · Legal, authorized offensive security
What wears people down
- · Not entry level — requires networking and systems depth first
- · Report writing is most of the deliverable
- · Client scoping constraints limit what you can actually test
- · Certification path is expensive and demanding