The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Penetration Tester (L3)
3-5 years as a SeniorSkills to master
- Leading complex engagements, developing custom tools, mentoring junior staff, and beginning to engage with mid-level stakeholders. You'll need to show you can handle end-to-end projects and guide others.
You're ready to move on when
- Successfully led at least 5-7 complex web application or network penetration tests from kick-off to final report.
- Consistently identified critical vulnerabilities that automated scanners missed.
- Provided effective technical mentorship to 2-3 junior testers, helping them achieve significant skill growth.
- Demonstrated strong communication skills by presenting findings to cross-functional teams and influencing remediation.
- 2
Security Consultant (Offensive Focus) from Consultancy
8-12 years in a consultancy roleSkills to master
- Managing client engagements, scoping projects, delivering high-quality reports, and working across diverse technical environments. You'll need to adapt to an in-house context and focus on long-term impact rather than just project delivery.
You're ready to move on when
- Managed multiple client penetration testing engagements simultaneously, delivering on time and budget.
- Developed expertise across various industries and technical stacks.
- Proven ability to translate client requirements into clear testing methodologies and deliverables.
- Strong track record of building client relationships and managing expectations.