Explore

Offensive security

Penetration Tester

Paid to break in, and then to write it all down.

Typical pay

$85k-$160k

How you get in

Security foundation plus OSCP or equivalent

Outlook

Strong; offensive security talent is scarce

Penetration testers attack systems with permission to find vulnerabilities before criminals do. The hacking is the fun part and roughly a third of the job; the report is the deliverable clients actually pay for.

A day in the life

  1. 9:00aScope confirmation and rules of engagement with the client
  2. 9:30aReconnaissance and enumeration of the target
  3. 12:00pLunch
  4. 1:00pExploitation attempts and privilege escalation
  5. 3:30pDocument findings with reproduction steps and evidence
  6. 5:00pWrite the report — the actual deliverable

How to get in

Security analyst into offensive

Duration

2-4 years

Cost

$1,500-$8,000

Credential

OSCP (Offensive Security Certified Professional)

  1. Build a foundation in networking, Linux and systems administration first
  2. Work in a SOC or security engineering role
  3. Practice constantly on legal platforms — Hack The Box, TryHackMe, CTFs
  4. Earn the OSCP, which is the industry's practical benchmark

Certification-led with a lab

Duration

1-2 years

Cost

$2,000-$10,000

Credential

OSCP, plus PNPT or CRTP

  1. Build a home lab and learn to attack it
  2. Stack practical, hands-on certifications rather than multiple-choice ones
  3. Publish write-ups and CTF results as public evidence of skill
  4. Apply to consultancies, which hire more openly on demonstrated ability

Developer into application security

Duration

1-3 years

Cost

$1,000-$6,000

Credential

OSWE or web-focused certifications

  1. Work as a software developer and learn how applications actually break
  2. Specialize in web and API security testing
  3. Add application security certifications
  4. Developers who pivot are unusually effective at finding real logic flaws

What people love

  • · Genuinely fascinating technical work
  • · Strong pay and remote-friendly
  • · Certifications matter more than degrees
  • · Legal, authorized offensive security

What wears people down

  • · Not entry level — requires networking and systems depth first
  • · Report writing is most of the deliverable
  • · Client scoping constraints limit what you can actually test
  • · Certification path is expensive and demanding

From people doing it

Add yours