How to Become a Professional Penetration Tester: 7 Steps From Zero

Laptop on a neat desk beside a monitor, a typical workstation for starting penetration testing


Level: beginner. This guide assumes a laptop, an internet connection and no security background. It answers one narrow question: how do you turn an interest in breaking things into a legitimate career, in seven steps, without touching a system you are not allowed to touch?

Plenty of material online will happily show you how to attack somebody else’s website. That is the wrong place to start, and the fastest way to a criminal record. The route that works is unglamorous: learn how the systems actually work, practise only against environments built to be broken, and produce written evidence that you can think clearly under pressure.

What Penetration Testing Actually Involves

Penetration testing is authorised, time-boxed testing of a system you do not own, carried out so the owner learns where their defences are weak. The work has three parts, and only one of them is technical. You decide what to test and how far to go. You find and prove issues carefully, so nobody wastes a week chasing a false alarm. Then you write a report a busy engineer can act on without a meeting to explain it. Clients pay for that last part as much as for the finding itself.

A good tester is closer to a translator between an attacker and a patch than to a rockstar. The people who last in this work are methodical and comfortable saying “I could not confirm this”, because an honest negative result beats a frightening theory. Testing style varies enormously between a two-day external network assessment and a three-month web application review, so the shape of the report changes with it.

The 7 Step Plan at a Glance

Here is the plan before the detail. Steps 1 to 3 build the substrate. Steps 4 to 7 turn it into something a client will pay for.

Step What you actually do What proves you did it Rough time, part time
1. Foundations Networking, Linux, HTTP and TLS at working depth You can explain why a connection or request failed 3 to 6 months
2. Scripting and code reading Automate repetitive work; review code for flaws A small script you wrote, in a public repository 2 to 4 months
3. Legal grounding Learn what authorisation means and how rules of engagement work You can draft a scope and rules of engagement Alongside steps 1 and 2
4. Authorised practice Work through deliberately vulnerable labs and machines Write-ups of what you found and how you proved it Ongoing, a few hours a week
5. Certification One exam that tests something, if a gap remains The badge, plus the labs behind it 1 to 3 months of prep
6. Portfolio Two or three full written reports in a professional shape A public portfolio a hiring manager can read 2 to 3 months
7. First engagement Internship, freelance, bounty or volunteer project A signed report you can name in an interview 3 to 12 months, unpredictable

Steps 1 to 3 — The Foundations You Cannot Skip

Step 1, the technical substrate. You need to know how traffic moves before you can talk about a misconfiguration. That means TCP/IP, DNS, HTTP and TLS at a practical depth — deep enough that you can explain in a report why a request failed. The HTTP documentation on MDN is the reference working testers reach for. Linux is the working environment: you want to be comfortable with file permissions, processes and services, sockets and listening ports, packet capture, certificate inspection from the command line, and reading system configuration without fear. You are not aiming to be a kernel engineer, only to stop being surprised by a system you have been asked to assess.

Step 2, scripting and code reading. Python is the tool of choice, and the goal is not to become a software engineer. It is to automate the boring third of a workflow — parsing output, checking a list of hosts, extracting a field from a response — and to read code well enough to spot the flaw a scanner will miss. Security review is largely code reading, and the official Python tutorial is the right start.

Step 3: the legal side is not paperwork, it is the job

Every engagement starts with a document saying exactly what you may touch, when, how hard, what happens if you break something, and who to call at 3am. NIST SP 800-115 puts planning and authorisation ahead of technique for this reason, and our article on the methodology covers what that document must contain.

The legal position is not subtle. In the United Kingdom, section 1 of the Computer Misuse Act 1990 makes unauthorised access an offence in its own right. In Nigeria, the Cybercrimes (Prohibition, Prevention, Etc.) Act 2015 and its amendments cover unauthorised access and interference with computer systems. None of this is legal advice, but the rule has no exceptions: if you cannot point at written permission from someone entitled to give it, there is no job to do.

Steps 4 to 7 — Turning Practice Into a Career

Steps 4 to 7: labs, certificates, portfolio and first work

Steps 4 and 5 do different jobs. Step 4 is free and repeatable. TryHackMe offers guided paths for absolute beginners; Hack The Box runs machines that resemble real engagements more closely. Each machine sits inside an environment the operator built to be attacked, so you are authorised by design. What matters is not the badge but the write-up afterwards: what you found, how you proved it, how you cleaned up, and what you would fix first.

Step 5 is the certificate, and the honest framing is that most entry-level exams test vocabulary and exam technique rather than real capability. Employers know this, which is why evidence from your own testing outweighs a badge. Some practitioner certifications are harder and better respected. The material behind the Offensive Security Certified Professional, published by Offensive Security, is the standard example of a course built around hands-on work rather than a multiple-choice paper. Vendor-neutral tracks from CompTIA, (ISC)² and GIAC sit at different depths. Read the current exam blueprint, and treat any certificate bought without practising afterwards as expensive stationery.

Steps 6 and 7. A portfolio is not a list of badges. It is two or three complete written reports shaped like real ones: scope, method, findings with reproducible evidence, severity and business impact, remediation, and a retest result. The OWASP Web Security Testing Guide is the best free reference for what a thorough method should cover, and MITRE ATT&CK supplies the shared vocabulary for describing what an adversary does.

The first engagement is where most people stall. The cheapest routes are an internship, a small freelance job, a bug bounty run by a vendor on its own product, or a volunteer audit for an open-source project. Treat the first as cheap practice, not income: your goal is a clean, well-evidenced report and a reference, not a dramatic find. The SANS white paper library shows the rigour clients expect in writing.

Timelines, Pay and the Honest Limits

Be realistic about time. Alongside a full-time job, this is a multi-year build rather than a six-week one. People who reach a junior tester role commonly report 12 to 24 months of foundations, lab hours and portfolio work before their first paid test. We are deliberately not quoting a salary figure: pay varies enormously by country, sector, and whether you are employed or contracting, and any number offered without a source would be invented. What can be said honestly is that the gap between “can operate the tools” and “can find an issue, prove it and explain its business impact” is wide.

The real bottleneck is evidence, not knowledge. The bottom of this market is crowded with people holding certificates and nothing to show. If you take one thing from this article, make it steps 4 and 6: practise only where you are authorised, and write every result up so a stranger could follow it. For defensive background that makes findings easier to read, see our guides to password security and how an attack chain unfolds.

Frequently Asked Questions

How long does it take to become a penetration tester?

Part time, plan on a year of consistent study before you are a credible applicant, and closer to two before a first role is likely. The part that cannot be rushed is hours on real systems, because that is what employers buy.

Do I need a degree to work in penetration testing?

No, and there is no formal licence. A degree helps with a recruiter’s filter at some large organisations, but a strong portfolio has repeatedly carried people into roles without one. What matters is whether you can explain what you did, why it mattered, and what the owner should change.

Is penetration testing the same as ethical hacking?

Overlapping but not identical. Ethical hacking is the broad idea of using offensive techniques with permission. Penetration testing is the disciplined version: a defined scope, a documented method, a time box and a report. See our guide to the toolkit for the day-to-day difference.

Can I get experience by testing my own machines?

Yes, and a self-built lab is genuinely useful. Your own home network, a couple of virtual machines and a deliberately vulnerable platform give you the mechanics of an engagement without the stakes. What they cannot give you is exposure to someone else’s constraints, which is why a real client’s second opinion matters later.

Key Takeaways

  • Learn how systems work before you learn how to break them. Nobody can shortcut the foundations.
  • Written authorisation is the job, not the paperwork. No permission from the right person means no work.
  • Practise only in environments built for security testing, and keep a record of what the terms allow.
  • Write every lab result up. A write-up teaches more than the badge attached to it.
  • Treat most certificates as optional and read the exam blueprint before paying for one.
  • A portfolio of two or three professional-shaped reports outweighs a long list of badges.
  • Budget a year of part time study, and treat the first engagement as practice, not income.

Next, work out which tool does what in our guide to 15 penetration testing tools beginners should learn first, then follow the order of operations in network penetration testing step by step.

Sources: NIST SP 800-115, Technical Guide to Information Security Testing and Assessment; OWASP Web Security Testing Guide; MDN, HTTP documentation; MITRE ATT&CK; Offensive Security; TryHackMe; Hack The Box; SANS white papers.

0 Comments

Your email address will not be published. Required fields are marked *