Penetration Tester
You are paid to break in, with permission and in writing, and then explain exactly how.
No degree needed Hard, and the hardest part is the report rather than the exploit.
Everything here is for testing systems you own or have written permission to test. Unauthorised access is a criminal offence in most countries, including under the Computer Fraud and Abuse Act in the US and the Computer Misuse Act in the UK. Written authorisation, defined scope, agreed dates. No exceptions.
Can I actually do this?
Genuinely open without a degree — this field cares about demonstrable skill more than almost any other here. But it is rarely an entry-level job. In our reading of how these roles are advertised, people tend to arrive from help desk, networking, sysadmin or defensive security rather than straight off the street, and the free training below is excellent and deep.
Who it suits. People who are relentlessly curious about how a system can be made to misbehave, and who can write it up afterwards without gloating.
Runway. A year or more, realistically. This is not a first job in tech for most people.
Coming from support or defensive security? That is the normal route. You already know how systems are actually configured, which is where the holes are. Security Analyst Help Desk / IT Support
Also advertised as
The route
Four stations, in order. Each one is a thing you finish before the next matters.
-
Station one
Learn it free
Only the best few, deliberately. Every one of these is free to use — the pill on each card says exactly what is and isn't free.
PortSwigger Web Security Academy
Free to learn · no certificate
The best free offensive-security training that exists, from the makers of Burp Suite. Free labs and material, no certificate; PortSwigger's separate Burp certification is paid.
Verified 2026-07-27
OWASP Web Security Testing Guide
Free to learn · no certificate
The methodology. Free and open. This is what turns poking at a site into a repeatable test you can charge for.
Verified 2026-07-27
OWASP Top 10
Free to learn · no certificate
The vocabulary every interview uses. Free.
Verified 2026-07-26
-
Station two
Attest strategically
This field does have certifications that carry real weight, and several are expensive and hands-on. We are not naming one here because we have not verified current pricing and exam terms to this project's standard. What we can say plainly: do the free PortSwigger labs first. They cost nothing, they are harder than most paid courses, and if you cannot finish them a certificate will not help you.
Nothing here is worth paying for
No credential needed
This field does have certifications that carry real weight, and several are expensive and hands-on. We are not naming one here because we have not verified current pricing and exam terms to this project's standard. What we can say plainly: do the free PortSwigger labs first. They cost nothing, they are harder than most paid courses, and if you cannot finish them a certificate will not help you.
Checked 2026-07-27
-
Station three
Prove it
A certificate says you passed a test. These say you can do the job.
A write-up of a lab you solved
Not the exploit — the reasoning. What you tried, what failed, why the successful path worked. Reports are the deliverable in this job.
A finding with a real business impact statement
Explain what an attacker could actually do to the organisation, in the language of someone who does not read code.
Evidence you stayed in scope
Show a rules-of-engagement document you worked to. Employers screen hard for people who understand authorisation, because the ones who do not are a liability.
-
Station four
Get hired
Search these exact titles
Who hires for this. Security consultancies (the usual first employer), large in-house security teams, and government.
Written lab reports are checkable by anyone who reads them, and they evidence the part of the job that is hardest to fake. That is our reasoning about what is inspectable, not a hiring statistic we have verified.
On salaryWe don't publish salary estimates. Numbers copied between blogs drift from reality, and a wrong number costs you real negotiating power. When we have a verified public source, it goes here with its date.
Where this route continues
- Security Analyst — many move between offence and defence
- Security Analyst — sideways move
- DevOps Engineer — sideways move
This page last verified 2026-07-27 · How we verify
PortSwigger Web Security Academy (7,145 chars) and the OWASP WSTG (5,836 chars) fetched and READ 2026-07-27. OWASP Top 10 carried from the 2026-07-26 verification.