The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Junior Penetration Tester / Associate Security Tester
1-2 yearsSkills to master
- Mastering basic scanning tools (Nmap, Nessus), understanding common web vulnerabilities (OWASP Top 10), meticulous documentation, and strict adherence to methodology.
You're ready to move on when
- Consistently finding basic to medium-severity vulnerabilities on routine targets.
- Producing accurate and well-structured draft reports with minimal oversight.
- Demonstrating a strong ethical mindset and attention to detail during testing.
- 2
Security Analyst (with offensive focus)
2-3 yearsSkills to master
- Developing a solid understanding of threat intelligence, incident response processes, and vulnerability management, with a keen interest in how systems are attacked.
You're ready to move on when
- Actively participating in threat hunting or vulnerability assessment activities.
- Proactively identifying and researching potential attack vectors against internal systems.
- Demonstrating a strong desire to transition from defence to offence.
- 3
System Administrator / Network Engineer (with security interest)
3-4 yearsSkills to master
- Deepening knowledge of operating system internals, network protocols, and infrastructure security, often through self-study and personal projects in offensive security.
You're ready to move on when
- Having built and secured personal lab environments for testing.
- Consistently identifying and patching vulnerabilities in systems they manage.
- Showing a natural curiosity about how systems can be bypassed or exploited.