The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior Penetration Tester
3-5 years as a Senior TesterSkills to master
- Leading complex engagements end-to-end, mentoring junior testers, taking ownership of client relationships, making technical decisions independently, and beginning to contribute to methodology improvements.
You're ready to move on when
- Consistently delivering high-quality, impactful findings without significant oversight.
- Proactively identifying and solving project-level challenges.
- Receiving positive feedback from clients and junior team members on your leadership and guidance.
- Demonstrating an interest in the commercial and strategic aspects of penetration testing.
- 2
From Lead Penetration Tester
2-3 years as a Lead TesterSkills to master
- Designing complex testing strategies, developing new methodologies, influencing senior stakeholders, managing small project budgets, and taking accountability for significant outcomes.
You're ready to move on when
- Successfully architecting and delivering multiple complex, multi-faceted engagements.
- Having a proven track record of developing new testing capabilities or improving existing ones.
- Being recognised as a subject matter expert who can influence technical direction.
- Demonstrating strong leadership potential and a desire to manage people directly.
- 3
From Security Consultant (with PT specialisation)
5-8 years in a consulting roleSkills to master
- Deepening hands-on technical exploitation skills, understanding the nuances of managed service delivery, and adapting consulting frameworks to offensive security operations.
You're ready to move on when
- Bringing a strong client-facing background and commercial awareness.
- Having a solid foundation in security architecture and risk management.
- A demonstrable passion for hands-on offensive security and a desire to lead a technical team.
- Successfully translating client business needs into actionable penetration testing scopes.