The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate Penetration Tester (L1)
1-2 yearsSkills to master
- Mastering fundamental tools (Burp, Nmap), understanding common vulnerabilities (OWASP Top 10), writing clear findings, and strictly adhering to RoE. Basically, proving you can execute tasks reliably under supervision.
You're ready to move on when
- Consistently delivering accurate findings on assigned tasks.
- Demonstrating a strong grasp of basic exploitation techniques.
- Proactively asking questions and showing a keen interest in learning more advanced methods.
- Successfully completing an OSCP or similar practical certification.
- 2
Security Analyst (with offensive focus)
2-3 yearsSkills to master
- Beyond general security operations, you'd need to have actively sought out opportunities to perform vulnerability assessments, run basic penetration tests, and spend time in offensive security labs. You'd need to show a clear passion for breaking things.
You're ready to move on when
- Having a portfolio of personal projects, CTF achievements, or bug bounty findings.
- Demonstrating a strong understanding of common attack vectors and defence evasion techniques.
- Being able to articulate how you'd approach a penetration test for a given system.
- Successfully completing an OSCP or similar practical certification.
- 3
Software Developer (with security interest)
3-4 yearsSkills to master
- Leveraging your deep understanding of how applications are built to identify subtle coding flaws and architectural weaknesses. You'd need to pivot your mindset from building to breaking, and gain hands-on experience with offensive tools and methodologies.
You're ready to move on when
- Having actively sought out security-focused development roles or projects.
- Demonstrating a strong understanding of secure coding practices and common application vulnerabilities.
- Successfully completing an OSCP or a relevant application security certification (e.g., OSWE).
- Being able to articulate how a developer's perspective enhances penetration testing.