GWAPT
GWAPT
GIAC Web Application Penetration Tester
GIAC / SANS
Deep web application security testing certification covering authentication, session management, and modern app attack surfaces.
● Career
Explore job families and certification issuers — two ways to map credentials to your path.
Focuses on web APIs, mobile apps, and business logic flaws.
Tests OWASP Top 10, auth flows, and API authorization.
Reviews iOS/Android binaries, storage, and transport security.
GWAPT
GIAC Web Application Penetration Tester
GIAC / SANS
Deep web application security testing certification covering authentication, session management, and modern app attack surfaces.
OSWE
Offensive Security Web Expert
Offensive Security
Advanced web application penetration testing exam focused on white-box review, custom exploits, and complex app logic bypasses.
OSCP
Offensive Security Certified Professional
Offensive Security
Hands-on penetration testing certification focused on identifying vulnerabilities and exploiting them in controlled lab environments.
eJPT
eLearnSecurity Junior Penetration Tester
INE / eLearnSecurity
Entry-level pentest credential validating reconnaissance, exploitation basics, and report writing in lab environments.
HTB CBBH
Hack the Box Certified Bug Bounty Hunter
Hackthebox
Hack the Box Certified Bug Bounty Hunter — professional certification on the Paul Jerimy security certification roadmap.
OSEP
Offensive Security Experienced Penetration Tester
Offensive Security
Advanced red-team style exam emphasizing evasion, Active Directory attack chains, and operational tradecraft beyond OSCP.
CCT INF
CREST Certified Tester — Infrastructure
CREST
Advanced CREST qualification for infrastructure penetration testing: network and operating-system layer assessment, report writing, and hands-on exploitation. Recognized for UK NCSC CHECK and equivalent to roughly 5–6 years of pentest experience.
GPEN
GIAC Penetration Tester
GIAC / SANS
Penetration testing certification validating skills in scoping engagements, executing attacks, and reporting actionable findings.
LPT
Licensed Penetration Tester Master
EC-Council
Elite EC-Council practical license for senior pentesters; often earned via exceptional CPENT performance or dedicated LPT track.
CCT
CREST Certified Tester
CREST
UK/EU-recognized practical penetration testing exam for consultants delivering CREST-accredited client engagements.
CRTO
Certified Red Team Operator
Zero Point Security
Red team operations certification covering C2 tradecraft, evasion, and adversary simulation beyond pure AD exploitation.
OSED
Offensive Security Exploit Developer
Offensive Security
Advanced Windows exploit development (EXP-401) — stack overflows, DEP/ASLR bypass, and custom shellcode for senior offensive researchers.
OSED
Offensive Security Exploit Developer
Offensive Security
Offensive Security Exploit Developer — professional certification mapped from the Paul Jerimy security certification roadmap.
PNPT
Practical Network Penetration Tester
TCM Security
Practical pentest exam with report writing; popular career bridge before OSCP.
PenTest+
CompTIA PenTest+
CompTIA
Intermediate penetration testing certification covering planning, scanning, exploitation, and reporting.
CPENT
Certified Penetration Testing Professional
EC-Council
Advanced 24-hour practical penetration test simulating multi-segment enterprise networks, AD, and evasion techniques.
CPTS
HTB Certified Penetration Testing Specialist
Hack The Box
Practical penetration testing certification built on Hack The Box Academy labs and a multi-machine capstone exam.
BSCP
Burp Suite Certified Practitioner
PortSwigger
Web application security exam proving ability to find and exploit vulnerabilities using Burp Suite in timed practical scenarios.
CRT
CREST Registered Tester
CREST
UK/EU recognized practical penetration testing qualification — common prerequisite before CREST CCT in consulting firms.
S-EHL
SECO Ethical Hacking Leader
SECO Institute
Top tier of the SECO ethical hacking track for experienced professionals: requires expert-level knowledge (S-EHE or equivalent such as OSCP) plus at least three years of relevant work experience. Focus on leadership, complex engagements, and continuous professional development.