Pentester job description: how to attract the right people
How to write a pentester job description that attracts the right candidates: structure, annotated template, scope, requirements, mistakes and where to post.
A good pentester reads a job ad the way they read an engagement scope: looking for concrete details and spotting anything that sounds hollow. A vague job description, or one copied from another role, drives away exactly the people you want. This guide gives you a structure, an annotated template and the wording mistakes to avoid, so your job description makes the right candidates want to reply.
What a pentester looks for in a job ad
Before writing, put yourself in the reader's place. An experienced pentester often gets several approaches a week. They open yours with a few precise questions in mind:
- What will I be testing? Web applications, Active Directory, cloud, mobile, IoT, red teaming: the type of work matters more than the title.
- In what setting? An internal team testing its own estate, or a consultancy running back-to-back client engagements. Day to day, these are different jobs.
- At what pace? Typical engagement length, share of time spent on reporting, travel, any on-call duty.
- How much technical freedom? Choice of tools, time set aside for research, R&D or internal tooling.
- Who is on the team? Level of peers, a technical lead, someone to review reports.
- How will I be assessed? A clear process that respects their time is a sign you are serious.
If your job description answers these six questions, you are already ahead of most ads out there.
The structure of a good job description
An effective job description fits on one page and follows a logical order: context, responsibilities, profile, conditions, then process. Keep sentences short and use lists. A reader should be able to scan it in a minute and know whether it is for them.
The title deserves attention. "Web and API Penetration Tester", "Active Directory Security Auditor" or "Senior Penetration Testing Consultant" are clear and searchable. Avoid catch-all titles like "Cybersecurity Expert" or internal job names nobody outside uses.
The annotated template
Here is a framework to adapt. Each block comes with a note on what it should contain.
1. Context
- Who you are, in two or three sentences: business, size of the security team, reporting line (CISO, CTO, offensive practice of a consultancy).
- Why the role exists: building an in-house capability, growing engagement volume, a replacement.
- Note: a pentester wants to know whether they are joining a structured team or will be the first offensive hire. Both can be attractive, as long as you say which.
2. Responsibilities
- Run penetration tests on a defined scope (see the next section).
- Write actionable reports: executive summary, technical detail, prioritised recommendations.
- Present findings to the relevant teams and support remediation.
- Contribute to the team's tooling, methodology and research.
- Note: list four to six real responsibilities, ordered by how much time they take. If reporting is a large part of the job, say so: it is often what surprises people after they join.
3. Profile
- Three to five must-have skills, written as observable abilities.
- Two to four nice-to-have skills, clearly separated.
- Note: the must-have versus nice-to-have split is covered below. It decides who dares to apply.
4. Conditions
- Location, remote work policy, travel frequency.
- Salary range.
- Training budget, research time, conferences or CTFs.
- Any security clearance requirement, and what it means in practice.
- Note: a published range filters early and saves pointless conversations. Research time and training budget are strong arguments for this profession.
5. Hiring process
- The steps, how many there are and roughly how long each takes.
- What the technical assessment looks like.
- Note: see the dedicated section below.
Be specific about the technical scope
"Penetration testing" means little without a scope. Skills differ a lot from one area to another, and an excellent web tester may struggle on Active Directory. State the main area or areas, and the secondary ones.
| Scope | What the role involves | What to state in the job description |
|---|---|---|
| Web and API | Business applications, authentication, business logic, REST or GraphQL APIs | Main technologies, share of grey or white box testing, any code review |
| Internal and Active Directory | Testing from the internal network, privilege escalation, AD attack paths | Size and complexity of the estate, Windows environments, use of Entra ID |
| Cloud | Configuration review and testing on AWS, Azure or GCP, IAM, containers | Providers in scope, balance between configuration audit and offensive testing |
| Mobile | Android and iOS apps, local storage, back-end communication | Platforms, access to source code, instrumentation tooling available |
If the role covers several areas, say which one dominates. A specialist then knows whether they will fit, and a generalist knows they are expected everywhere.
Must-have or nice-to-have: make the call
The endless list is the most common mistake. Fifteen requirements put off good candidates, who know they do not tick every box, and attract people who tick them all without real depth.
Must-have, for example for a mid-level web and AD role:
- Run a web penetration test end to end on your own, from scoping to report.
- Exploit common vulnerabilities manually, beyond what a scanner reports.
- Identify and exploit classic attack paths in Active Directory.
- Write a clear report for both technical and non-technical readers.
Nice-to-have:
- Experience on a cloud environment.
- Scripting to automate tasks (Python, PowerShell or similar).
- Public work: tools, write-ups, CTF results, vulnerability disclosures.
- A recognised offensive certification.
Phrase skills as actions, not keywords. "Can exploit a blind SQL injection" says far more than "OWASP expertise". For how much weight to give certifications, see our article on cybersecurity certifications in hiring.
Wording mistakes that drive people away
- Empty buzzwords: "passionate", "rockstar", "ninja". A pentester would rather read what they will do on Monday morning.
- Years of experience as the only bar: "5 years minimum" rules out strong people from CTFs or career changes, without guaranteeing anyone else's level. Describe the expected autonomy instead. Our article on hiring career changers in cybersecurity covers this.
- Mixing jobs: a role combining pentesting, SOC, GRC and network administration attracts nobody good at any of them.
- Certifications required for no reason: require one only if a client or a qualification demands it, and explain why.
- Silence about reporting: hiding the writing load leads to disappointment, then turnover.
- No salary: without a range, many approached candidates will not even take the time to reply.
Describe the assessment process
Pentesters are wary of two extremes: a process with no technical assessment at all, which suggests the team cannot judge skill, and a long take-home test eating their weekend. Describe a short, predictable process in the job description:
- A first conversation about background and expectations.
- A short hands-on exercise, on a lab close to the real job.
- A technical interview where the candidate walks a peer through their approach.
- A final conversation with the manager.
State how long the practical exercise takes and what it assesses. A realistic, time-boxed lab followed by a discussion of the approach tells you more than a multiple-choice quiz. We cover this approach in our guide to assessing cybersecurity skills, and the skills to check at each step in our article on hiring a pentester.
Where to post your job description
- Your careers page, with a stable URL: it is the reference candidates check.
- LinkedIn, ideally shared by the technical members of the team rather than only the company page.
- Technical communities: associations, meetups, French security conferences, specialist chat servers. Follow their posting rules.
- The CTF and training ecosystem, where you find people who practise regularly, including those who never browse job boards.
- Direct outreach, essential for this profession. The best people are rarely actively looking: a well-written job description then backs up a personal message.
In short
A good pentester job description sets out a precise scope, real responsibilities, a few genuine must-haves, transparent conditions and a respectful assessment process. It reads in a minute and gives the right candidate a concrete reason to reply.
Opening a pentester role and want help scoping it? At Cyber Recrut, a recruiter and a security practitioner build the job description with you, and our shortlisted candidates then prove their skills on hands-on labs matched to your scope. See how we work or share your hiring need.