The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Mid-Level Penetration Tester
3-5 yearsSkills to master
- Independently executing standard web and network penetration tests, strong reporting skills, basic exploit adaptation, and effective communication of findings.
You're ready to move on when
- Consistently delivering high-quality penetration test reports with minimal supervision.
- Successfully identifying and exploiting a wide range of common vulnerabilities.
- Proactively seeking out opportunities to learn new tools and techniques.
- Demonstrating strong ethical conduct and adherence to Rules of Engagement.
- 2
Security Analyst (with offensive focus)
4-6 yearsSkills to master
- Deep understanding of defensive security operations (SOC, incident response), vulnerability management, and a growing interest in offensive techniques, often having some self-taught hacking skills.
You're ready to move on when
- Has identified and triaged numerous vulnerabilities in a defensive role.
- Has a strong understanding of how attackers operate from a defensive perspective.
- Has actively pursued offensive security training or certifications (e.g., OSCP).
- Demonstrates a keen interest in 'breaking' systems, not just defending them.
- 3
Experienced Developer (with security specialisation)
5-8 yearsSkills to master
- Deep knowledge of secure coding practices, application architecture, and a strong ability to read and understand code. Has actively sought out security vulnerabilities in their own or others' codebases.
You're ready to move on when
- Has led secure code reviews or implemented security features in applications.
- Has a strong understanding of common application-layer vulnerabilities from a developer's perspective.
- Has actively participated in bug bounty programmes or CTFs.
- Can demonstrate a solid understanding of offensive security methodologies and tools.