How To Become A Pentester
How To Become A Pentester
How To Become A Pentester
So
you
want
to
learn
how
to
hack
and
think
you
need
a
degree.
If
you
have
the
time
and
the
money
to
pursue
a
degree
in
computer
science,
by
all
means
take
the
opportunity
and
pursue
it.
While
it
is
not
necessary
to
have
this
degree,
it
would
be
one
of
the
optimal
paths
to
take
under
perfect
conditions
to
get
your
foot
in
the
door
at
an
entry-level
position.
You
must
know
the
fundamentals.
That
being
said,
I
part
ways
with
some
in
the
industry
here
as
some
believe
you
need
many
years
of
experience
as
a
network
administrator
or
security
engineer
etc.
first
before
moving
on
to
pentesting.
I
actually
believe
that
this
isnt
a
requirement
and
think
you
can
learn
both
concurrently
depending
on
your
skill
level
and
willingness
to
learn.
They
complement
each
other.
If
you
are
dedicated
you
can
read
both
types
of
books,
take
both
types
of
classes
and
experiment
with
both
sides
of
the
same
coin.
Learning
how
to
pentest
doesnt
prevent
you
from
concurrently
learning
how
networks
work.
However,
learning
how
to
pentest
and
hack
without
learning
how
networks
work
is
never
going
to
happen
for
you,
so
go
get
those
fundamentals
down.
As
you
gain
experience,
you
can
start
to
branch
out
to
some
other
languages
as
well.
This
knowledge
base
will
make
you
more
attractive
in
interviews
and
make
you
a
much
better
pentester.
Start
by
watching
some
YouTube
videos
and
then
go
and
modify
or
try
to
recreate
those
applications
on
your
own.
The
best
way
to
find
a
job
is
to
first
look
at
your
current
employer
to
see
if
you
can
tweak
your
position
or
move
to
another
in
the
company.
The
next
best
route
would
be
to
intern
somewhere
if
you
can.
If
you
cant
do
it
those
ways
you
can
always
start
your
search
by
going
to
job
searching
sites
such
as
the
Federal
Government
(USAJobs.gov),
CareerBuilder,
Monster.com,
Indeed.com
and
Dice.com.
Be
on
the
lookout
for
titles
such
as
Information
Security
Analyst,
Information
Security
Auditor,
Information
Security
Engineer,
IT
Security
Consultant,
and
of
course
Penetration
Tester.
Of
course
you
can
search
for
common
keywords
such
as
Kali,
Nessus,
Wireshark,
Metasploit,
Burp
Suite
and
nmap.
These
will
always
vary
and
change
over
time,
but
you
should
be
able
to
come
up
with
a
few
different
combinations
and
find
some
openings
without
issue.
As
with
any
job
this
depends
on
many
variables,
but
Ive
included
a
general
range
for
you
here:
It
isnt
uncommon
for
entry-level
positions
to
be
between
55k-70k,
mid-
level
to
be
between
70k-100k
and
senior
level
to
be
between
100k-
140k.
https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applicati
ons_Directory_Project#tab=On-Line_apps
If
you
do
this
test
yourself
you
will
get
different
results
because
of
a
different
sample,
but
you
will
most
likely
see
fairly
similar
results.
I
did
not
expect
the
CISSP
to
be
mentioned
as
often
as
it
was
for
penetration
testing
positions,
but
it
just
goes
to
show
how
popular
that
certification
is
in
the
eyes
of
employers
no
matter
what
spectrum
of
IT
Security
you
land
on.
Some
of
you
may
argue
that
the
OSCP
certification
is
the
best
of
these
to
get
and
I
wouldnt
argue
with
you.
Again,
this
isnt
scientific
and
I
dont
have
an
opinion
at
all,
but
this
should
give
you
an
idea
of
what
companies
are
looking
for.
GPEN
The
objective
for
us
right
now
is
to
get
to
a
point
where
we
can
get
that
experience,
and
these
certifications
are
still
some
of
the
more
popular
certifications
that
a
HR
Manager
at
some
company
will
be
looking
for.
CISSP
GPEN
We
can
see
that
the
CISSP
certification
requirement
is
heavy,
so
if
you
dont
meet
the
experience
requirements
I
would
come
back
to
it
at
a
later
date.
I
actually
did
that
myself.
I
started
with
a
couple
others
such
as
C|EH
before
later
getting
the
CISSP.
Another
CISSP
option
is
by
becoming
an
associate
and
getting
the
experience
along
the
way
until
you
reach
the
requirements
for
the
full
certification.
After
getting
some
certifications,
I
considered
getting
even
more
until
I
realized
that
it
really
just
doesnt
matter
all
that
much.
It
is
just
my
personal
opinion
that
certifications
should
be
used
as
a
tool
to
get
you
where
you
need
to
be,
but
after
you
are
there,
experience
alone
is
king.