Skip to content
Cyber Recrut

Becoming a pentester: skills, paths and first role

How to become a pentester: what the job really involves, the foundations to master, the paths in, practising legally and how to land a first offensive role.

Published on 8 min read

Penetration testing attracts a lot of people, and the picture most have of it is far from reality: less spectacular hacking, more method, writing and contractual rigour. The good news is that the path is open to you, as long as you take it in the right order. This guide shows you the job as it really is, the skills to build, the paths that lead there and how to land a first role.

The job as it really is

A pentester (or penetration tester) attacks a system with its owner's permission to reveal its weaknesses before an attacker does. The key word is "permission": everything happens within a written framework, with a scope, dates and rules of engagement.

A typical engagement runs like this:

  1. Scoping: understanding what the client wants tested, what is excluded, production constraints and who to call if something goes wrong.
  2. Reconnaissance: mapping the target, identifying exposed services, technologies and entry points.
  3. Finding and exploiting vulnerabilities: manually verifying what tools suggest, demonstrating real impact, chaining several weaknesses together.
  4. Writing the report: an executive summary, reproducible technical detail and prioritised recommendations.
  5. Debrief: presenting the findings to the teams concerned and answering their questions.

The last two steps take up a large share of the time. Many candidates discover this late. If writing puts you off, it is better to know before you start, and to work on it now.

Consultancy or in-house team

In a consultancy, you move through short engagements with a variety of clients: broad technical exposure, a fast pace, plenty of reports. In an in-house team, you test the same environment over time, follow remediation and work with developers and operations teams. Most first roles are in consultancies, which is why reporting carries so much weight in hiring.

The foundations to master before going offensive

The most common mistake is to start with attack tools. A pentester exploits systems they understand. Without the fundamentals, you will know how to run a command, but not why it works or what to do when it fails.

AreaWhat to understandWhy it matters
NetworkingTCP/IP, DNS, HTTP and HTTPS, segmentation, firewallsKnowing what is reachable and how traffic flows
SystemsWindows and Linux, permissions, services, processes, scheduled tasksPrivilege escalation requires knowing how permissions work
Active DirectoryAuthentication, Kerberos, groups, delegationMost internal tests in companies go through it
WebSessions, authentication, access control, APIsA large share of engagements cover web applications
ProgrammingReading code, writing scripts (Python, Bash, PowerShell)Adapting a tool, automating a task, understanding a vulnerability

Add solid technical English: documentation, vulnerability write-ups and much of the tooling are in English.

Offensive skills

Once those foundations are in place, specialising in offensive work goes much faster:

  • Testing methodology: following clear phases, keeping a record of everything you do, staying within scope.
  • Manual exploitation: going beyond a scanner's output and proving a flaw is actually exploitable.
  • Privilege escalation and lateral movement: getting from limited access to a meaningful objective.
  • Chaining: combining several minor weaknesses. This is often what separates a confirmed profile from a beginner.
  • Judgement: knowing when not to run an action that could disrupt production, and warning the client first.

The underrated skills

Writing, the ability to explain a technical risk to a non-technical audience and a sense of client service matter as much as technique for your progression. A clear report is what the client keeps from your work.

The paths into pentesting

There is no single route, but some are more direct than others.

  1. A degree in IT or cybersecurity: an apprenticeship or internship in an offensive team is a valuable accelerator.
  2. From system and network administration: you already know the environments you will attack, especially Active Directory. It is a very good starting point for internal testing.
  3. From software development: you read code and understand frameworks and APIs. That is a major asset for application and web testing.
  4. From the SOC or incident response: you know attack techniques from the defensive side and how they leave traces. Moving to offensive work is a natural step.
  5. A career change from a non-technical job: possible, but rarely direct. Going through a technical role first (support, administration, SOC) makes the next step far more realistic.

If you are torn between defence and offence, our guide to becoming a SOC analyst describes an entry point that is often more accessible for a first job, and good preparation for offensive work.

In France, accessing or remaining in a computer system without authorisation is a criminal offence (articles 323-1 and following of the Code pénal), and most countries have similar laws. There is no exception for curiosity or good intentions. All your practice must happen on environments you own or that are built for the purpose.

The right training grounds

  • A personal lab: a few virtual machines, a deliberately misconfigured Active Directory domain, a vulnerable web application designed for learning.
  • Training platforms: they offer machines and scenarios you can attack legally, from beginner to advanced.
  • CTFs: in a team or solo, they train problem solving under time pressure.
  • Bug bounty programmes: they provide a legal framework for vulnerability research, as long as you follow their rules and scope strictly.

Document to prove it

Practice only counts in hiring if it shows. Write up the machines you solve or, better, write a full report on your own lab, structured like a client deliverable: summary, vulnerabilities ranked by severity, evidence, recommendations. It is the most convincing document you can bring to an interview, because it shows both technique and writing.

Certifications

An offensive certification with a practical exam can help you get past the first filters and gives structure to your learning. It replaces neither regular practice nor the ability to write. Choose it for the scope you are aiming at (web, internal, cloud) rather than for its fame. Our article on cybersecurity certifications explains how employers read them.

Landing your first role

Where to apply

  • Audit and consulting firms: they hire the most junior profiles, with supervision and report reviews.
  • In-house offensive teams: rarer, and often open to people who already have some experience.
  • Apprenticeships and final-year internships: the most direct route if you are still studying.
  • Adjacent roles: configuration audits, code review, vulnerability management. They often lead to pentesting internally.

A CV that shows what you can do

Highlight your write-ups, your lab, your CTF results and an excerpt of a report rather than a list of tools. State the scopes you have actually practised. Our guide to writing a convincing cybersecurity CV details the method.

Preparing for the interview

Expect a practical assessment: a time-boxed lab, then a discussion of your approach. Recruiters look at your method, what you do when you are stuck and how clearly you explain, more than at the number of flaws found. To see what you will be asked, read the pentester interview questions we suggest to employers, along with our advice on passing a technical cybersecurity interview.

Questions to ask before accepting

A first offensive role shapes your progression. Before signing, find out:

  • Who reviews my reports, and how are my first engagements supervised?
  • Which scopes will I work on, and can I change over time?
  • How much time goes to research, self-study or training?
  • How are remote work, client travel and any out-of-hours testing handled?
  • Is the role really penetration testing, or mostly formatted automated scanning?

Pay varies with region, type of organisation, scope and level of autonomy. Compare offers on all of these, and on the quality of supervision, which matters a great deal early in your career.

In short

Becoming a pentester first takes solid fundamentals in networking, systems, Active Directory and the web, then a rigorous offensive method and a real ability to write. Practise only on authorised environments, document your work like a client deliverable, and aim for a first role where real supervision will help you grow.

Aiming for a penetration testing role? Join the Cyber Recrut network for free: our shortlisted candidates prove their skills on hands-on labs, so you get noticed for what you can do rather than for the lines on your CV. You can also see how we work.

Related articles