● Career

Cybersecurity careers by domain

Explore job families and certification issuers — two ways to map credentials to your path.

Penetration Tester

Simulates real attacks to find exploitable weaknesses and produce remediation reports.

Roles in this job family

  • Junior Penetration Tester

    Junior

    Runs scoped tests, documents findings, and pairs with seniors.

  • Senior Penetration Tester

    Senior

    Leads engagements, chains exploits, and presents to executives.

Related certifications

OSCP

OSCP

Offensive Security Certified Professional

Offensive Security

Hands-on penetration testing certification focused on identifying vulnerabilities and exploiting them in controlled lab environments.

Recruiter appeal
4.8
Difficulty
Hard
Community

PenTest+

PenTest+

CompTIA PenTest+

CompTIA

Intermediate penetration testing certification covering planning, scanning, exploitation, and reporting.

Recruiter appeal
4.4
Difficulty
Medium
Community

eJPT

eJPT

eLearnSecurity Junior Penetration Tester

INE / eLearnSecurity

Entry-level pentest credential validating reconnaissance, exploitation basics, and report writing in lab environments.

Recruiter appeal
3.9
Difficulty
Easy
Community

PNPT

PNPT

Practical Network Penetration Tester

TCM Security

Practical pentest exam with report writing; popular career bridge before OSCP.

Recruiter appeal
4.5
Difficulty
Medium
Community

CEH

CEH

Certified Ethical Hacker

EC-Council

Ethical hacking certification covering reconnaissance, scanning, exploitation, and post-exploitation techniques from an attacker mindset.

Recruiter appeal
4.3
Difficulty
Medium
Community

OSWE

OSWE

Offensive Security Web Expert

Offensive Security

Advanced web application penetration testing exam focused on white-box review, custom exploits, and complex app logic bypasses.

Recruiter appeal
4.7
Difficulty
Hard
Community

OSEP

OSEP

Offensive Security Experienced Penetration Tester

Offensive Security

Advanced red-team style exam emphasizing evasion, Active Directory attack chains, and operational tradecraft beyond OSCP.

Recruiter appeal
4.7
Difficulty
Hard
Community

CCT INF

CCT INF

CREST Certified Tester — Infrastructure

CREST

Advanced CREST qualification for infrastructure penetration testing: network and operating-system layer assessment, report writing, and hands-on exploitation. Recognized for UK NCSC CHECK and equivalent to roughly 5–6 years of pentest experience.

Recruiter appeal
4.7
Difficulty
Hard
Community

GPEN

GPEN

GIAC Penetration Tester

GIAC / SANS

Penetration testing certification validating skills in scoping engagements, executing attacks, and reporting actionable findings.

Recruiter appeal
4.6
Difficulty
Medium
Community

LPT

LPT

Licensed Penetration Tester Master

EC-Council

Elite EC-Council practical license for senior pentesters; often earned via exceptional CPENT performance or dedicated LPT track.

Recruiter appeal
4.6
Difficulty
Hard
Community

CCT

CCT

CREST Certified Tester

CREST

UK/EU-recognized practical penetration testing exam for consultants delivering CREST-accredited client engagements.

Recruiter appeal
4.6
Difficulty
Hard
Community

CRTO

CRTO

Certified Red Team Operator

Zero Point Security

Red team operations certification covering C2 tradecraft, evasion, and adversary simulation beyond pure AD exploitation.

Recruiter appeal
4.6
Difficulty
Hard
Community

OSED

OSED

Offensive Security Exploit Developer

Offensive Security

Advanced Windows exploit development (EXP-401) — stack overflows, DEP/ASLR bypass, and custom shellcode for senior offensive researchers.

Recruiter appeal
4.6
Difficulty
Hard
Community

OSED

OSED

Offensive Security Exploit Developer

Offensive Security

Offensive Security Exploit Developer — professional certification mapped from the Paul Jerimy security certification roadmap.

Recruiter appeal
4.6
Difficulty
Hard
Community

GWAPT

GWAPT

GIAC Web Application Penetration Tester

GIAC / SANS

Deep web application security testing certification covering authentication, session management, and modern app attack surfaces.

Recruiter appeal
4.5
Difficulty
Hard
Community

CPENT

CPENT

Certified Penetration Testing Professional

EC-Council

Advanced 24-hour practical penetration test simulating multi-segment enterprise networks, AD, and evasion techniques.

Recruiter appeal
4.4
Difficulty
Hard
Community

CPTS

CPTS

HTB Certified Penetration Testing Specialist

Hack The Box

Practical penetration testing certification built on Hack The Box Academy labs and a multi-machine capstone exam.

Recruiter appeal
4.4
Difficulty
Medium
Community

BSCP

BSCP

Burp Suite Certified Practitioner

PortSwigger

Web application security exam proving ability to find and exploit vulnerabilities using Burp Suite in timed practical scenarios.

Recruiter appeal
4.4
Difficulty
Medium
Community

CRT

CRT

CREST Registered Tester

CREST

UK/EU recognized practical penetration testing qualification — common prerequisite before CREST CCT in consulting firms.

Recruiter appeal
4.4
Difficulty
Medium
Community

S-EHL

S-EHL

SECO Ethical Hacking Leader

SECO Institute

Top tier of the SECO ethical hacking track for experienced professionals: requires expert-level knowledge (S-EHE or equivalent such as OSCP) plus at least three years of relevant work experience. Focus on leadership, complex engagements, and continuous professional development.

Recruiter appeal
4.4
Difficulty
Hard
Community

Learning resources