JPJobPrepfull-stack interview
RoadmapsJS CompilerStar on GitHub

Career roadmap

Penetration Tester

Find the holes before someone else does, on systems you are authorised to test, and write it up so it gets fixed.

Time
9-14 months part-time
Entry bar
Strong systems and networking fundamentals. Not a first technology job.
Stages
5 · 25 topics
0/25 studied0%

Before you start Pentester

  • Networking and Linux at a confident level
  • Scripting in Python or Bash
  • A legal lab environment: your own VMs or a licensed platform

Scope, law and method

3-4 weeks · 0/5 topics

The part that makes this a profession rather than a crime: authorisation and process.

  1. Testing without written authorisation is a criminal offence in most jurisdictions.

    • Rules of engagement and scope documents
    • Computer misuse legislation basics
    • Safe harbour in bug bounty programmes
    • Handling out-of-scope discoveries
  2. Structured coverage beats ad-hoc poking, and clients pay for the structure.

    • PTES and OWASP testing guide
    • Black, grey and white box engagements
    • Time-boxing and coverage decisions
    • Evidence collection as you go
  3. You need somewhere legal to practise. This is the foundation of the whole track.

    • Isolated virtual lab setup
    • Vulnerable-by-design targets
    • Snapshots and safe resets
    • Licensed practice platforms
  4. Most of a test is enumeration. Rushing this is the classic beginner failure.

    • Passive information gathering
    • Port and service enumeration
    • Service version and technology fingerprinting
    • Attack surface mapping
  5. The deliverable is the report. Interviewers ask to see one.

    • Finding structure: impact, evidence, remediation
    • Risk rating consistently
    • Executive summary writing
    • Retest and verification

BuildWrite a rules-of-engagement document and a test plan for a lab target you own.

Web application testing

6-8 weeks · 0/5 topics

The majority of commercial penetration testing work is web applications.

  1. Not the list — the mechanics, the variations, and how each is verified.

    • Injection: SQL, command, template
    • Broken access control and IDOR
    • Authentication and session flaws
    • SSRF and its cloud impact
  2. Access control flaws are the most commonly found and most impactful category.

    • Horizontal and vertical privilege escalation
    • JWT and session token weaknesses
    • OAuth and SSO misconfiguration
    • Multi-tenancy isolation testing
  3. XSS remains ubiquitous, and modern variants require modern understanding.

    • Reflected, stored and DOM XSS
    • CSRF and SameSite behaviour
    • Content Security Policy bypasses
    • Prototype pollution
  4. APIs now carry most application logic, and are frequently under-tested.

    • REST and GraphQL specific issues
    • Mass assignment and excessive data exposure
    • Rate limiting and business logic abuse
    • API authentication weaknesses
  5. Burp Suite fluency is effectively a job requirement.

    • Burp Suite proxy, repeater, intruder
    • Extensions and custom automation
    • Automated scanning and its limits
    • Manual verification of every finding

BuildTest a deliberately vulnerable application end to end and produce a full professional report.

Network and infrastructure testing

6-8 weeks · 0/5 topics

Internal network testing, especially Active Directory, is core consultancy work.

  1. Service enumeration to initial access on an internal network.

    • Service enumeration and default credentials
    • Known vulnerability exploitation
    • Relay and man-in-the-middle attacks
    • Pivoting and tunnelling
  2. The single most valuable infrastructure testing skill in enterprise engagements.

    • Enumeration with BloodHound
    • Kerberoasting and AS-REP roasting
    • Delegation abuse
    • Credential harvesting and lateral movement
  3. Local escalation on both platforms, methodically rather than by script.

    • Windows privilege escalation paths
    • Linux escalation: SUID, capabilities, cron
    • Misconfiguration over exploitation
    • Automated enumeration then manual verification
  4. Different rules, different attack paths, and provider authorisation requirements.

    • IAM privilege escalation paths
    • Metadata service and SSRF chains
    • Storage and secret exposure
    • Provider testing policies
  5. Understanding detection is what makes a test realistic and a report useful.

    • How EDR detects common techniques
    • Testing detection coverage collaboratively
    • Purple team engagement style
    • Reporting detection gaps as findings

BuildCompromise a lab Active Directory domain from an unauthenticated foothold and document every step.

Reporting and client work

3-4 weeks · 0/5 topics

The technical work is half the job. The report is what the client actually buys.

  1. Reports are the interview artefact for this role. Bring a sanitised one.

    • Executive summary for non-technical readers
    • Reproducible steps with evidence
    • Business impact over CVSS alone
    • Actionable remediation advice
  2. Consistent, defensible severity is what separates professional reports from tool output.

    • CVSS scoring and its limitations
    • Contextual business impact
    • Chaining low findings into high impact
    • Defending a rating to a client
  3. Consultancy is a people business. Debriefs and difficult conversations are routine.

    • Scoping calls and expectation setting
    • Reporting critical findings mid-test
    • Debrief presentations
    • Handling defensive stakeholders
  4. Writing your own tooling is what distinguishes senior testers.

    • Python for custom exploitation
    • Automating repetitive enumeration
    • Modifying public proof-of-concept code safely
    • Maintaining a personal toolkit
  5. Legal, public evidence of ability, and a recognised route into the industry.

    • Programme selection and scope reading
    • Report quality and duplicate avoidance
    • Building a public profile
    • Disclosure etiquette

BuildProduce two full engagement reports, each with an executive summary and prioritised remediation.

Certification and interviews

6-10 weeks · 0/5 topics

This field hires on practical certification and demonstrated work more than any other.

  1. OSCP remains the recognised bar. Practical exams, not multiple choice.

    • OSCP structure and preparation
    • CREST and regional equivalents
    • Web-specific certifications
    • Exam strategy and time management
  2. Volume matters. Consistent lab work is the only reliable preparation.

    • Hack The Box and similar platforms
    • Keeping structured notes
    • Methodology refinement
    • Learning from write-ups after attempting
  3. Expect to explain an attack chain in detail and possibly perform one live.

    • Walk through a full compromise chain
    • Explain a vulnerability class deeply
    • Live lab exercise
    • Discussing a finding you are proud of
  4. Trust is the product. Interviews probe judgement more than tooling.

    • Handling accidental scope breaches
    • Sensitive data discovered during testing
    • Responsible disclosure decisions
    • Client confidentiality
  5. Write-ups, tools and bounty history are the accepted evidence.

    • Sanitised sample report
    • Public lab write-ups
    • Open-source security tooling
    • Disclosed vulnerabilities or CVEs

BuildPass a practical certification and publish sanitised write-ups of lab machines you compromised.

Pentester tools on your CV

  • Burp Suite
  • Nmap
  • BloodHound
  • Metasploit
  • Impacket
  • Python
  • Kali Linux
  • Hack The Box

What Pentester employers ask to see

  • A sanitised professional penetration test report
  • A practical certification such as OSCP
  • Public lab write-ups showing methodology
  • Disclosed vulnerabilities or published tooling

Consultancies, in-house red teams and bug bounty. Certification-driven hiring, and the report writing matters as much as the exploitation.

Content last reviewed 2026-08-31. Guidance only — no institute or paid placement is endorsed anywhere in this book.