United Kingdom · Technical roles · Mid-Level (2-5 years)

Penetration Tester

Here is the whole job, in plain words. What it is, a real day, what you decide, how you're judged, how people get here and where they go next. Then the part no course gives you: twelve AI tutors who learn your work.

  • Experience bandMid-Level (2-5 years)
  • Direct reportsNo direct reports
  • Reports toSenior Penetration Tester
  • UK framework levelUsually a coordinator, or early in a professional job

Also advertised as Security Tester · Ethical Hacker · Mid-Level Security Analyst (Penetration Focus)

Built on an analysis of 43,079 real UK job descriptions · grounded in qualifications employers recognise

Start with a free Future Fluency check, tuned to Penetration Tester

Ten quick questions, one per Future Fluency, asked against this role rather than a generic one. About five minutes, and no card.

Start the check, free

1What this role really is

This role is all about finding weaknesses before the bad guys do. You'll be the one trying to break into systems, not to cause trouble, but to help our clients make their digital defences stronger. It's a hands-on job where you'll get to use a bunch of cool tools and techniques to poke and prod at networks, applications, and sometimes even people (ethically, of course!). You're not just running scans; you're thinking like an attacker, trying to chain together vulnerabilities to get to the crown jewels. It's challenging, often frustrating, but incredibly rewarding when you uncover a critical flaw that could have caused real damage.

2What you'd actually use

The tools this job runs on, and how well you'd need to know each one.

NmapIntermediate

Executing various scan types (`-sV`, `-sC`, `-p-`) for network reconnaissance and service enumeration. You'll know how to interpret the results and tailor your scans.

Nessus/OpenVASIntermediate

Running credentialed/uncredentialed vulnerability scans and triaging initial results to identify obvious weaknesses and false positives. You'll be good at filtering the noise.

Metasploit FrameworkIntermediate

Using existing modules to exploit known vulnerabilities, generating payloads, and performing basic post-exploitation activities with guidance. You'll be able to get a shell.

Burp Suite Professional / OWASP ZAPAdvanced

Using Repeater, Intruder (for fuzzing), and Scanner to manipulate requests, identify common OWASP Top 10 flaws, and perform advanced manual web application testing. This will be your bread and butter for web apps.

John the Ripper / HashcatIntermediate

Running basic dictionary and brute-force attacks against provided hash lists using standard and custom wordlists. You'll be cracking passwords (ethically, of course).

Python (Basic)Intermediate

Reading and modifying simple scripts for parsing tool output, automating repetitive tasks, and interacting with basic APIs. You don't need to be a developer, but you should be comfortable with scripting.

BashIntermediate

Using basic command-line utilities (`grep`, `awk`, `sed`) for text manipulation, scripting simple workflows, and navigating Linux systems during post-exploitation. Your command-line skills should be solid.

Jira / Confluence / Dradis / PlexTracIntermediate

Documenting findings accurately, entering evidence and vulnerability details into our reporting platforms, and tracking project progress. This is where your meticulous precision really shines.

3What you get to decide, and how that grows

Power in a job isn't your title. It's what you're allowed to decide. Here's how it grows as you move up.

The choiceComing inWhere you are nowThe step above
Technical Approach (e.g., tool selection, methodology steps)Follows prescribed steps; asks for tool recommendations; all approaches reviewed.Chooses appropriate tools and methodology steps for routine tasks; consults Senior Tester for novel scenarios.Designs and refines testing methodologies; selects and customises tools for complex engagements; approves junior/mid-level approaches.
Client Communication (e.g., reporting findings, asking questions)Escalates all client contact to supervisor; drafts findings for review.Communicates routine findings and asks clarifying questions directly with client technical teams; escalates sensitive issues.Leads client debriefs; manages client expectations; handles sensitive discussions; reviews junior/mid-level communications.
Scope & Risk Management (e.g., out-of-scope findings, potentially disruptive tests)Immediately escalates any out-of-scope findings or potential risks to supervisor.Identifies and flags out-of-scope items; proposes alternative testing approaches for risky scenarios, always with senior approval.Defines and negotiates scope with clients; assesses and mitigates risks for complex tests; has authority to pause or modify testing for safety.
Time & Resource Allocation (within an engagement)Follows daily task assignments; reports progress hourly.Manages time for assigned tasks and segments of engagements; flags potential delays early.Allocates resources (hours, tools) for entire engagements; adjusts plans for unforeseen challenges; manages junior tester workloads.

4How you'll be judged

The scoreboard, honestly: the hard targets, how often each one is actually looked at, and the quiet human signals that never make it onto a dashboard.

Valid Vulnerabilities Identified
The number of genuine, exploitable vulnerabilities you uncover during a standard engagement.
Target · >15 per standard engagement (web app or network)

On a recent web app test, you found 18 unique, exploitable flaws, including 2 critical SQL injections and 3 high-severity XSS vulnerabilities.

Report Accuracy & Clarity
The percentage of your draft reports that require significant corrections or clarifications from a Senior Tester before client delivery.
Target · <5% error rate on report drafts requiring senior review

Your last five reports only needed minor grammatical tweaks and no technical corrections, showing a 0% error rate on technical content.

Methodology Adherence
How consistently you follow our established penetration testing execution standards (PTES) and internal checklists.
Target · 100% compliance with PTES checklist on all projects

Every phase of your last network test was documented and cross-referenced against the PTES checklist, ensuring nothing was missed.

Engagement Efficiency
How effectively you manage your time and complete testing activities within the allocated project hours.
Target · Within 10% of estimated hours for 90% of engagements

You completed a 40-hour web app test in 42 hours, staying well within the acceptable variance, even with unexpected client delays.

Proactive Issue Identification
Your ability to spot potential problems or scope changes early in an engagement and raise them before they become blockers.
  • You're the one who flags a missing VPN configuration for client access before testing starts, or identifies a critical system that wasn't in scope but should be. You'll bring these up in daily stand-ups or directly to the Project Manager, not wait until it's a crisis.
Effective Communication of Findings
How well you explain complex technical vulnerabilities and their business impact to both technical and non-technical client contacts.
  • Clients consistently praise your ability to 'speak their language' in debriefs. You can explain a SQL injection to a developer and then translate the business risk to a non-technical manager in the same meeting, without losing anyone. Your reports are clear and actionable, not just a dump of technical jargon.
Independent Problem Solving
Your capacity to work through technical challenges and unexpected roadblocks during testing without constant supervision.
  • When you hit a tricky WAF or a custom authentication mechanism, you'll spend a few hours researching, trying different approaches, and documenting your attempts before asking for help. You'll come to your Senior Tester with 'I've tried X, Y, and Z, and here's what happened' rather than 'It's not working, what do I do?'
Ethical Conduct & Professionalism
Maintaining the highest standards of ethical behaviour, confidentiality, and professional conduct throughout all engagements.
  • You immediately flag any accidental access to out-of-scope data or sensitive information, even if no one else saw it. Clients feel comfortable with you on their systems, and you handle sensitive data responsibly. You're never tempted to 'just quickly check' something not in scope.

5Would you like it

The honest version. What people enjoy, and what grinds them down.

What people enjoy
The Thrill of the Hunt

You get a genuine kick out of finding a critical vulnerability that no one else spotted. It's like solving a complex puzzle, and the 'aha!' moment when an exploit finally works is what keeps you going.

Spending an entire afternoon trying different payloads against a tricky WAF, and then finally getting that SQL error message to pop up—that's your kind of victory.

Continuous Learning & Skill Mastery

You're constantly looking for new techniques, tools, and attack vectors. The idea of being 'done learning' is terrifying. You enjoy diving deep into new technologies to understand how they can be broken.

You'll be reading about a new Active Directory attack technique one evening and then trying to replicate it in your home lab the next day, just to see how it works.

Making a Real Impact on Security

You're not just finding bugs; you're helping clients protect their data and their customers. Seeing a client take your recommendations seriously and fix a critical flaw is incredibly satisfying.

The most rewarding part of an engagement is often the client debrief, where you can clearly explain the risks and see them genuinely committed to fixing the issues you've found.

What frustrates people
  • The Report is the Product: You might spend 80% of your time on brilliant, creative hacking, but your value is judged almost entirely on the quality and clarity of your 100-page report. Report writing is tedious and non-negotiable, and it will take up a significant chunk of your time.
  • The 'Scanner Jockey' Phase: Early in your career, you'll spend countless hours running automated scans and then sifting through thousands of findings to eliminate the 95% that are false positives. It's a necessary but grueling part of the job, and it's not always exciting.
  • Restrictive Testing Windows: 'You can test our critical payment gateway, but only between 2:00 AM and 4:00 AM on Sunday. And if anything goes down, it's on you.' Expect late nights and early mornings, often on weekends, for certain engagements.
  • Client Denial: Presenting a critical, exploitable finding only to have the client's senior developer insist 'that's not a bug, it's a feature' or 'no real user would ever do that.' It can be frustrating to convince people of obvious risks.
  • The Agony of 'Out of Scope': Finding that glaring vulnerability that would give you keys to the kingdom... on a server that the client explicitly declared was out of scope for the test. You can't touch it, you can't report it, and you have to just walk away.
  • The Burnout is Real: The pressure to constantly learn, the late-night testing windows, and the adversarial nature of the work can lead to significant burnout if you don't actively manage your own well-being and set boundaries.
What this role does not give you
  • A predictable 9-to-5 schedule every day – client testing windows often dictate odd hours.
  • A 'hero' role where you're always celebrated for your technical prowess – sometimes you're just the bearer of bad news.
  • A job where every piece of your work leads to immediate, visible remediation – clients have their own priorities and timelines.
  • A role focused purely on blue team defence or incident response – this is offensive security, through and through.

6Who you work with

This role directly contributes to our reputation for delivering thorough and impactful security assessments. Your findings help clients strengthen their security posture, which, frankly, keeps them coming back. You'll also help shape the quality of our reports and the effectiveness of our testing methodologies, making us a more credible and trusted partner in the market.

Inside the business
  • Senior Penetration Testers (for guidance and review)
  • Project Managers (for engagement planning and delivery)
  • Technical Leads (for methodology and tooling discussions)
Outside the business
  • Client Technical Teams (developers, sysadmins)
  • Client Project Managers (for scheduling and scope)
  • Client Security Teams (for remediation advice)

7What you need before you start

Not a wish list. The things you would be expected to already have.

  • A foundational understanding of information security principles, including confidentiality, integrity, and availability.
  • Demonstrable experience (2-5 years) in a technical IT role, ideally with some exposure to security operations, system administration, or network engineering.
  • Familiarity with common penetration testing methodologies and tools, even if only in a lab environment.
  • A strong ethical compass and a clear understanding of the 'rules of engagement' in security testing.
  • The ability to independently research and learn new technical concepts and attack techniques.

8What to practise next

Where the job is going, and what to do about it starting this week.

Custom Tooling & Exploit Development

While off-the-shelf tools are great, the most impactful findings often come from custom scripts or modified exploits tailored to a specific environment. You'll need to build your own to find the really hidden gems.

Python for security scripting · API interaction and automation · Understanding exploit primitives · Payload generation and evasion

  • This week: Pick a repetitive task you do manually and write a small Python script to automate part of it.
  • This month: Dive deeper into Python security libraries (e.g., Scapy, Requests, Impacket) and build a simple network scanner or web fuzzer.
  • Month 2: Try to modify an existing Metasploit module or write a simple custom post-exploitation script.
  • Month 3: Participate in a Capture The Flag (CTF) event that involves exploit development challenges.

Quick win: Start reading the source code of your favourite open-source security tools. Understanding how they work internally is the first step to modifying them.

9Staying current once you are in

What people here do to keep up
  • Actively participate in security communities (e.g., OWASP local chapters, DEF CON groups, online forums).
  • Regularly practice on platforms like Hack The Box, TryHackMe, or VulnHub to keep your skills sharp and learn new techniques.
  • Attend industry conferences (e.g., Black Hat, DEF CON, BSides) to stay current with the latest threats and network with peers.
  • Contribute to open-source security projects or develop your own small tools/scripts.
  • Read security research papers, blogs, and vulnerability disclosures regularly.

10How the AI economy is changing work like this

Before we ask anything of you, here's what we can already say about AI and work of this kind:

The new skill this role is being asked for: Prompt Engineering & LLM Integration

Competitors are already using Large Language Models (LLMs) to draft reports in 10 minutes that used to take 2 hours. Testers who figure this out will outproduce their peers significantly. It's not future-state; it's happening now.

We'll only ever tell you what we can actually back up. No hype, no scare tactics.

Your PlanIllustration

Built for Penetration Tester

5 units that map to this job, from the qualifications that cover it.

  1. Cyber security testing, vulnerabilities and controlsNCFE · covers 4 of 10 standardsLevel 3
  2. The Application and Deployment of Security Tools and Best PracticeThe Learning Machine · covers 3 of 10 standardsLevel 3
  3. Testing IT & Telecoms SystemsPearson Education Ltd · covers 2 of 10 standardsLevel 4
  4. Security+Cambridge OCR · covers 2 of 10 standardsLevel 3
  5. Carrying out Information Security Risk AssessmentCity & Guilds Limited · covers 2 of 10 standardsLevel 4
These are the real units behind this job, in the order they rank for it. Nothing here is marked done, because this plan has not been started by anyone yet. Yours would fill in as you go.

The rising capability

Zavmo analysis

What's rising in its place

This is where the work is heading, and the higher pay with it. Get fluent here and the shift stops being a threat and starts being your edge.

Prompt Engineering & LLM Integration

Competitors are already using Large Language Models (LLMs) to draft reports in 10 minutes that used to take 2 hours. Testers who figure this out will outproduce their peers significantly. It's not future-state; it's happening now.

  • Context windows and token limits
  • Temperature settings for different tasks
  • RAG architectures for proprietary data
  • Output validation and hallucination detection
  • Prompt chaining for complex analysis

Cloud Security Posture Management (CSPM) & Cloud Native Exploitation

More and more clients are moving to the cloud (AWS, Azure, GCP). Knowing how to identify and exploit misconfigurations in cloud environments is rapidly becoming a core skill, not a niche one. It's a completely different attack surface.

  • IAM misconfigurations in cloud
  • Serverless function vulnerabilities
  • Container security (Docker, Kubernetes)
  • Cloud service exploitation techniques
  • Cloud logging and monitoring bypasses

What you’ll use

Skills this role draws on

Technical

  • OWASP Top 10 & ASVS
  • Penetration Testing Execution Standard (PTES)
  • MITRE ATT&CK Framework
  • Active Directory (AD) Exploitation
  • Vulnerability Triage & CVSS Scoring
  • Network Protocol Analysis

The pathway

How you actually get there, here

How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.

  1. 1

    Junior Penetration Tester / Associate Security Tester

    1-2 years

    Skills to master

    • Mastering basic scanning tools (Nmap, Nessus), understanding common web vulnerabilities (OWASP Top 10), meticulous documentation, and strict adherence to methodology.

    You're ready to move on when

    • Consistently finding basic to medium-severity vulnerabilities on routine targets.
    • Producing accurate and well-structured draft reports with minimal oversight.
    • Demonstrating a strong ethical mindset and attention to detail during testing.
  2. 2

    Security Analyst (with offensive focus)

    2-3 years

    Skills to master

    • Developing a solid understanding of threat intelligence, incident response processes, and vulnerability management, with a keen interest in how systems are attacked.

    You're ready to move on when

    • Actively participating in threat hunting or vulnerability assessment activities.
    • Proactively identifying and researching potential attack vectors against internal systems.
    • Demonstrating a strong desire to transition from defence to offence.
  3. 3

    System Administrator / Network Engineer (with security interest)

    3-4 years

    Skills to master

    • Deepening knowledge of operating system internals, network protocols, and infrastructure security, often through self-study and personal projects in offensive security.

    You're ready to move on when

    • Having built and secured personal lab environments for testing.
    • Consistently identifying and patching vulnerabilities in systems they manage.
    • Showing a natural curiosity about how systems can be bypassed or exploited.

11Where this role leads

The long view:Your journey as a Penetration Tester is just beginning here. We're committed to helping you grow, whether that's becoming a world-class technical expert, a respected team leader, or even a future CISO. It's a challenging but incredibly rewarding path, and we're excited to see where you take it.

Pay & demand

The figure is the median for full-time employees in the ONS occupation this job title codes to (Cyber security professionals), from the April 2025 survey — about six months old when published, as ASHE always is. It is that occupation's middle, not this role's. Half earn more.

The ten Future Fluencies

Zavmo analysis

The credential is what you can do today. These are what keep you valuable.

A qualification proves you can do the job as it's defined today. These ten are what decide whether you're still the obvious person for it in five years. They're the capabilities employers are now writing into senior roles faster than people are learning them. Zavmo weaves them through whatever you study, so you come out with both: the credential and the fluency.

The highlighted ones are the Fluencies your role leans on hardest, from how Penetration Tester is actually changing. In about two minutes, the free confidence check asks where you stand on each of the ten. That's the whole check, and it's what makes the plan yours rather than generic.

12The team that's yours

No two people are taught the same way. This is one-to-one, not one-to-many.

Zavmo is a hyper-personalised AI learning platform. Twelve virtual tutors, each with a different way of teaching, and one orchestration agent that picks the right one for the moment. So every single lesson is shaped around you, your role, and the way you learn. Not a course everyone sits through. A conversation built for you, and no one else.

…and nine more, matched to you after your first chat. Meet all twelve

13What it feels like

A conversation, not a course

Because your tutor knows your role, your projects and your last session, learning sounds like this. And it's different for every single person:

Cyber security testing, vulnerabilities and controlsLevel 3

Applied to your work in Penetration Tester

This unit aims to provide learners with an understanding of common types of cyber security testing, vulnerabilities, and controls. Learners will be able to reduce or remove potential cyber security vulnerabilities and apply appropriate cyber security controls, understanding the importance of testing, reporting, and retesting after changes.

How the thinking builds
  1. Remember
  2. Understand
  3. Apply
  4. Analyse
  5. Evaluate
  6. Create
An illustration of a Zavmo lesson, built from this role’s own route. The unit, its objective and every criterion above are the awarding body’s own words, not an example.

One to one, not one to many

No two people run this the same way

A course is written once and handed to everyone. This is assembled around you, and keeps changing as it learns you. Five things it reads, and what each one changes.

  1. Your actual work Every lesson is taught against a live piece of your own work, not a worked example from a textbook.
  2. What you already know The first conversation finds your starting point, so you skip what you can already do and spend the time on what you cannot.
  3. The conditions you learn under Not a learning-styles quiz. The evidence does not support those. The dimensions the research does back, read once and used to shape the plan.
  4. How far you got last time It picks up mid-thought. The tutor knows what you said, what you struggled with, and what it asked you to try.
  5. Which tutor suits the moment Twelve of them, each for a different kind of thinking. The one who walks you through a first idea is not the one who stress-tests it.

See how you learn, free. Eight questions, no sign-up. A directional taster; the diagnostic inside Zavmo goes deeper and keeps adapting.

DemonstrateIllustration

Evidenced on your work in Penetration Tester

You do not finish by watching something. You finish by showing it on the work you already do, against the measures this job is judged on.

  • Valid Vulnerabilities IdentifiedThe number of genuine, exploitable vulnerabilities you uncover during a standard engagement.On a recent web app test, you found 18 unique, exploitable flaws, including 2 critical SQL injections and 3 high-severity XSS vulnerabilities.>15 per standard engagement (web app or network)
  • Report Accuracy & ClarityThe percentage of your draft reports that require significant corrections or clarifications from a Senior Tester before client delivery.Your last five reports only needed minor grammatical tweaks and no technical corrections, showing a 0% error rate on technical content.<5% error rate on report drafts requiring senior review
  • Methodology AdherenceHow consistently you follow our established penetration testing execution standards (PTES) and internal checklists.Every phase of your last network test was documented and cross-referenced against the PTES checklist, ensuring nothing was missed.100% compliance with PTES checklist on all projects
  • Engagement EfficiencyHow effectively you manage your time and complete testing activities within the allocated project hours.You completed a 40-hour web app test in 42 hours, staying well within the acceptable variance, even with unexpected client delays.Within 10% of estimated hours for 90% of engagements
These are this job's own measures, with its own targets. Nothing is marked evidenced, because nobody has started this yet. Yours would fill in from the work you bring.

Your passport

This isn't a certificate you file away. It's a passport to the life you're designing.

Every credit you earn and every fluency you build adds up: evidence where it counts, carried with you. Zavmo keeps the map: where you are, where you're heading, and the next step, at your pace, around your life. From Penetration Tester to Senior Penetration Tester (L3), and whatever you decide comes after.

Level 3 · in progressAI Fluency→ Senior Penetration Tester (L3)→ your design
Where this takes you

Your journey as a Penetration Tester is just beginning here. We're committed to helping you grow, whether that's becoming a world-class technical expert, a respected team leader, or even a future CISO. It's a challenging but incredibly rewarding path, and we're excited to see where you take it.

See Your Progress GrowIllustration
Penetration Tester
  • OWASP Top 10 & ASVS
  • Penetration Testing Execution Standard (PTES)
  • MITRE ATT&CK Framework
  • Active Directory (AD) Exploitation
  • Vulnerability Triage & CVSS Scoring
  • Network Protocol Analysis
This is your Mind Palace on learn.zavmo.ai. Every skill above comes from this role's own record, not an example borrowed from another job. A node lights up when you evidence it, and what you build stays yours between jobs. That is the part a course cannot do.

14The detail, folded away

Everything else the record holds

The career branches in full, how AI is already showing up in the day-to-day, and the questions people ask about this job. Here when you want them, out of the way while you decide.

Where it leads next, rung by rung

Where it leads

The career path, and where it branches

Penetration Tester is a start, not a ceiling. Each step below asks for new skills and hands back more autonomy.

  1. Senior Penetration Tester (L3)

    3-5 years in this role

    You'll move from independently executing standard tests to leading complex engagements, mentoring junior testers, and making significant technical decisions within projects. You'll be the go-to expert for specific attack types.

    • Advanced Exploit Development: Modifying existing exploits, writing custom scripts for unique targets, and understanding payload evasion techniques.
    • Red Teaming Operations: Participating in or leading multi-stage, objective-based security assessments that simulate real-world attacks.
    • Methodology Development: Contributing to and refining our internal penetration testing methodologies and best practices.
    • Strategic Tool Selection: Evaluating and recommending new tools or platforms to enhance our testing capabilities.
Working with AI on the job

Working with AI

Where AI is starting to help

Let's be real, a lot of penetration testing involves repetitive tasks, sifting through mountains of data, and writing up findings. What if you could spend less time on the tedious bits and more time on the really interesting, complex hacking? That's where AI comes in. We're not talking about replacing you; we're talking about giving you a serious superpower.

Our AI Productivity Hub is packed with tools and best practices designed specifically for Penetration Testers. Imagine cutting down on manual reconnaissance, getting smarter insights from scan results, and drafting reports in a fraction of the time. This isn't just theory; it's practical, hands-on AI that you'll use day-to-day to make your work faster, smarter, and frankly, a lot more fun.

Automated Reconnaissance & OSINT

Use AI-powered tools to continuously scan public sources like GitHub, Shodan, and social media for leaked credentials, exposed subdomains, and employee information related to your target. It'll consolidate all that messy data into a clean, digestible brief, saving you hours of manual digging. Think of it as having a tireless digital detective working for you 24/7.

Smart Log & Scan Analysis

Feed massive vulnerability scan outputs (from Nessus, OpenVAS, etc.) or web server logs into an AI model. It'll instantly identify anomalous patterns, prioritise findings that are actually likely to be exploitable, and filter out common false positives. No more sifting through thousands of low-priority alerts – the AI helps you focus on what really matters.

AI-Assisted Report Generation

After you've got the technical details of a finding (vulnerability type, affected parameter, payload), an AI assistant can draft the vulnerability description, explain the business impact, and suggest remediation steps in clear, professional language. This can seriously cut down on the most tedious part of the job: report writing. You'll still review and refine, of course, but the heavy lifting is done.

Exploit & Payload Suggestion

Based on the identified service, version, and operating system of a target, an AI tool can research and suggest relevant public exploits, configuration weaknesses, or even custom payload options from a vast knowledge base. It's like having a super-fast research assistant that knows all the common ways to break things.

Common questions

Common questions

How do you become a Penetration Tester?

Common routes in include Junior Penetration Tester / Associate Security Tester (1-2 years), Security Analyst (with offensive focus) (2-3 years) and System Administrator / Network Engineer (with security interest) (3-4 years). Times vary with prior experience.

Where can a Penetration Tester progress to?

This role can lead on to Senior Penetration Tester (L3) (3-5 years in this role), depending on the skills you build.

What level is a Penetration Tester in the UK?

This role aligns to RQF Level 3 on the UK framework, a guide to the depth of qualification it maps to, not a hard entry bar.

What new skills matter most for a Penetration Tester?

Increasingly, Prompt Engineering & LLM Integration and Cloud Security Posture Management (CSPM) & Cloud Native Exploitation. These are the areas where the higher-paid, future-proof work is heading.

The honest bit

You’ve started things before

Most of them were built for a room full of people who aren’t you. A cohort moves on whether or not your week allowed it, and by the third week the thing you’re behind on becomes the reason you stop opening it.

There’s no cohort here, and no timetable to fall behind. Before anything starts, Zavmo asks when you’re sharpest and how long you can realistically sit down for, then builds the sessions around those answers. A bad fortnight changes your pace. It doesn’t put you behind.

And you only pay once you start learning. Searching and planning are free, and you can cancel any time — so the cost of finding out is an afternoon, not a year.

What it costs

Less than one coaching session. Every month.

A single career-coaching hour costs more than a month of this, and it ends when the hour does. Zavmo doesn't. It's £70 a month, about £2.30 a day, for a companion that knows a Penetration Tester, works on the job you actually do, and keeps going at your pace rather than a timetable's.

  • Searching and planning stay free. You only pay when you start learning.
  • Your credits are yours. Regulated, and they don't vanish when a subscription ends.
  • Cancel any time and billing stops. No notice period, no minimum term.

Your path, personalised

You have the map. Walking it is the part we do together.

This route runs to 10 national skill standards. That is a real journey.

Zavmo shapes a learning experience as unique as you are. It fits how you learn, your pace and the work you already do. Every step stays benchmarked to recognised national standards. That’s the plan for becoming a Penetration Tester: personal to you, and it still counts. The first steps are free.

Independent research finds well-designed intelligent tutoring performs nearly as well as one-to-one human tutoring: VanLehn (2011), Educational Psychologist.

A private tutor in the UK averages £35–40 an hour . Zavmo is £70/month.

A real plan on learn.zavmo.ai: Ofqual-regulated units, credits, and a three-month run at your own pace.
Start free No commitment. See your first steps free.

15Where to go from here

Other roles at Level 3

Same depth of qualification, different job. Useful if the work appeals but this particular role does not.

Other roles in Technical roles

Stay in the field you know and move sideways rather than up.

If you leave this industry

The skills you'll gain here are highly transferable. You could move into broader security consulting, security architecture, incident response, or even product security roles in tech companies. The ability to think like an attacker is valuable everywhere.

Not sure this is the right direction?

Work out what you actually want from work first, then come back and see which roles fit it. Takes about ten minutes.

This role profile is © 2026Growth Engineering Technologies Ltd. Built from UK occupational standards and regulated qualification data, and written for Zavmo.

You're not behind. You're right on time. The shift is only just beginning. Your role won't look the same in two years. Be the one who leads the change, not the one it happens to. Build my plan, free Here's the first ten minutes: a 2-minute confidence check → your personalised roadmap → meet the tutors matched to you. No card, cancel any time. No card. Build your plan, see your roadmap and meet the twelve tutors matched to you. All free. When you're ready to start learning, it's £70 a month, billed monthly. Cancel any time and billing stops.