Hiring a pentester: the skills you need to check
How to hire a pentester: define the need, the technical and reporting skills to check, hands-on assessment and the costly mistakes to avoid along the way.
Hiring a pentester looks simple on paper: find someone who can attack a system to reveal its weaknesses. In practice, the title covers very different jobs, CVs all look alike, and a bad hire costs you unusable reports or an early departure. This guide helps you define the need, know what to check and avoid the most common traps.
Start by defining the real need
Before looking for a profile, be clear about what you expect from penetration testing. Three questions prevent most misunderstandings.
In-house or consultancy? An in-house pentester tests the same estate over time. They learn your architecture, follow up on fixes and often work closely with developers. In a consultancy, they run short engagements for varied clients, with a heavy share of writing and debriefing. The two jobs call for different strengths: depth and internal diplomacy on one side, fast adaptation and rigorous deliverables on the other.
What scope? Web applications and APIs, internal network and Active Directory, cloud, mobile, industrial systems: an excellent web specialist can struggle on a Windows domain. State the main scope and the secondary ones. Our article on the pentester job description explains how to describe them.
What level of autonomy? A junior will need a lead to review reports and frame their first engagements. A senior should be able to run a test end to end, from scoping to debrief. If nobody on the team can mentor, do not hire a junior hoping they will train themselves.
Technical skills to check
The expected skills depend on scope, but some apply to almost every role.
- Methodology: splitting a test into phases (reconnaissance, mapping, vulnerability discovery, exploitation, post-exploitation), keeping records and staying within the authorised scope.
- Manual exploitation: going beyond scanner output, understanding why a vulnerability exists and demonstrating its real impact.
- Solid fundamentals: HTTP and authentication for web, network protocols, how Windows and Linux work, Active Directory mechanics for internal tests.
- Chaining: combining several minor weaknesses to reach a meaningful objective. This is often what sets a senior apart.
- Tooling and automation: knowing the usual tools, and being able to write a small script when a tool falls short.
- Risk judgement: knowing when not to run an action that could disrupt production, and warning people before doing so.
The table below sums up what to check first, by scope.
| Scope | Check first | Warning sign |
|---|---|---|
| Web and API | Business logic, access control, session handling, injections | Only talks about vulnerabilities a scanner found |
| Internal and Active Directory | Enumeration, privilege escalation, attack paths, lateral movement | Lists tool names without explaining what they exploit |
| Cloud | Identity and permissions, service configuration, resource exposure | Confuses configuration review with penetration testing |
| Mobile | Local storage, client to server traffic, bypassing protections | Has never instrumented an app |
The skills people forget to check
Many hiring processes focus on technique and miss what gives a penetration test its value to the business: the deliverable.
Writing a useful report
A penetration test is only worth what it lets you fix. The report needs an executive summary, reproducible technical detail and prioritised recommendations. Ask for a sample report, anonymised or from a training environment. You will see straight away whether the person can prioritise and explain.
Debriefing and persuading
A pentester presents findings to teams who sometimes built the system under test. They must stay factual, avoid an accusing tone and suggest realistic fixes. A short role play of a few minutes is enough to assess this. To prepare it, our set of pentester interview questions includes ready-to-use debriefing questions.
Respecting the rules of engagement
Ethics and contractual rigour are not negotiable. A good candidate brings up rules of engagement, scope, test windows and data confidentiality without being asked. If they talk lightly about testing without authorisation, treat it as a serious red flag.
Assess through practice
A purely verbal interview cannot separate someone who knows the vocabulary from someone who can do the work. For a pentester, a hands-on exercise is the most reliable way to gauge level.
An effective process fits in four steps:
- A first conversation about background, scopes covered and expectations.
- A time-boxed hands-on lab on a deliberately vulnerable environment close to your scope. Never on your production systems.
- An approach review with a peer: the candidate explains what they tried, what failed and what they would have done with more time.
- A final conversation with the manager about how the team works and the terms of the role.
The third step tells you the most. A candidate who did not find everything but reasons methodically is often worth more than one who found things fast but cannot explain why. To design a fair exercise and a scoring grid, see our guide on assessing cybersecurity skills.
Public contributions (tools, technical write-ups, CTF results, vulnerability disclosures) are a useful complement. They show curiosity and consistency, but they do not replace an assessment on a scope close to the job.
Costly traps
- Hiring on certifications alone. A recognised offensive certification proves effort and a foundation, not the ability to run an engagement on your estate. Our article on certifications in hiring explains how to read them.
- Confusing pentesting with vulnerability scanning. If the job is mostly running automated tools and formatting their output, say so. A real pentester will leave quickly.
- Having technique assessed by someone who does not practise it. Without a competent peer, the technical interview rewards confidence over real skill.
- Using years of experience as the only bar. Very strong profiles come from CTFs, development or system administration. See our guide on hiring career changers.
- Setting an oversized exercise. A test that eats a whole weekend filters out employed candidates, who are often the best.
- Hiding the share of writing. A hire who finds out that half their time goes into reports is likely to move on fast.
- Letting the process drag. Good pentesters get several approaches. A slow process with no feedback between steps loses you the candidates you wanted.
What attracts a good pentester
Pay matters, but it is not the only lever. For this job, several things often weigh just as much:
- time set aside for research, R&D or internal tooling;
- a training budget and the chance to attend conferences or play CTFs;
- varied engagements and an interesting technical scope;
- peer review of reports, which helps people grow;
- clear working arrangements: remote work, travel, any on-call duty.
Bring these up in the very first conversation. They often tip the balance against a competing offer.
In short
To hire a pentester, first define the setting, the scope and the autonomy you expect. Check method, manual exploitation and judgement, but also the ability to write and debrief. Assess with a hands-on lab followed by a discussion with a peer, keep the process short and be open about what the job involves day to day.
Looking for a pentester and want to get the hire right? At Cyber Recrut, a recruiter and a security practitioner frame the need with you, then our shortlisted candidates prove their skills on hands-on labs built around your scope. See how we work or tell us about your hire.