9Getting Employed as a Pentester
The goal of this journey is to be employed as a pentester. In this chapter, we will discuss helpful tips for gaining such employment. These tips are ones that have been shared with students and future pentesters over the years. There are indeed people who have been hired directly into pentesting jobs without prior IT or infosec experience. So, if you prepare well, you can get a job as a pentester without such prior experience.
Job Descriptions
“Pentester” and “ethical hacker” are not always listed as a job title. Human Resources uses similar titles across infosec roles as they do for IT roles. Having fewer titles to deal with makes it easier for HR to manage.
Here are some common job titles that may involve pentesting responsibilities:
- Infosec or Security Analyst
- Infosec or Security Engineer
- Infosec or Security Consultant
When looking for pentesting jobs, you must review the job description. The terms “pentesting” or “ethical hacking” will typically be found there. Also look for “pentesting tools,” “techniques,” and “methodologies” in the job description. Nessus or Nexpose vulnerability scanners and web app pentesting tools like Burp Suite, OWASP ZAP, Web Inspect, and AppScan may also appear within the job description. Knowledge of the OWASP Top 10 Most Critical Application Security Risks is commonly sought, especially in web app pentesting ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access