● Career

Cybersecurity careers by domain

Explore job families and certification issuers — two ways to map credentials to your path.

Purple Team

Bridges offensive tests with defensive improvements and detection validation.

Roles in this job family

  • Purple Team Engineer

    Mid-level

    Runs collaborative exercises and verifies new detections.

  • Purple Team Lead

    Senior

    Plans joint red/blue schedules and tracks coverage metrics.

Related certifications

PenTest+

PenTest+

CompTIA PenTest+

CompTIA

Intermediate penetration testing certification covering planning, scanning, exploitation, and reporting.

Recruiter appeal
4.4
Difficulty
Medium
Community

CySA+

CySA+

CompTIA Cybersecurity Analyst

CompTIA

Analyst-level credential covering threat detection, vulnerability management, and security monitoring operations.

Recruiter appeal
4.4
Difficulty
Medium
Community

OSCP

OSCP

Offensive Security Certified Professional

Offensive Security

Hands-on penetration testing certification focused on identifying vulnerabilities and exploiting them in controlled lab environments.

Recruiter appeal
4.8
Difficulty
Hard
Community

GCIH

GCIH

GIAC Certified Incident Handler

GIAC / SANS

Incident handling credential focused on detecting intrusions, collecting evidence, and coordinating effective response workflows.

Recruiter appeal
4.5
Difficulty
Medium
Community

OSWE

OSWE

Offensive Security Web Expert

Offensive Security

Advanced web application penetration testing exam focused on white-box review, custom exploits, and complex app logic bypasses.

Recruiter appeal
4.7
Difficulty
Hard
Community

OSEP

OSEP

Offensive Security Experienced Penetration Tester

Offensive Security

Advanced red-team style exam emphasizing evasion, Active Directory attack chains, and operational tradecraft beyond OSCP.

Recruiter appeal
4.7
Difficulty
Hard
Community

CCT INF

CCT INF

CREST Certified Tester — Infrastructure

CREST

Advanced CREST qualification for infrastructure penetration testing: network and operating-system layer assessment, report writing, and hands-on exploitation. Recognized for UK NCSC CHECK and equivalent to roughly 5–6 years of pentest experience.

Recruiter appeal
4.7
Difficulty
Hard
Community

GPEN

GPEN

GIAC Penetration Tester

GIAC / SANS

Penetration testing certification validating skills in scoping engagements, executing attacks, and reporting actionable findings.

Recruiter appeal
4.6
Difficulty
Medium
Community

LPT

LPT

Licensed Penetration Tester Master

EC-Council

Elite EC-Council practical license for senior pentesters; often earned via exceptional CPENT performance or dedicated LPT track.

Recruiter appeal
4.6
Difficulty
Hard
Community

CCT

CCT

CREST Certified Tester

CREST

UK/EU-recognized practical penetration testing exam for consultants delivering CREST-accredited client engagements.

Recruiter appeal
4.6
Difficulty
Hard
Community

CRTO

CRTO

Certified Red Team Operator

Zero Point Security

Red team operations certification covering C2 tradecraft, evasion, and adversary simulation beyond pure AD exploitation.

Recruiter appeal
4.6
Difficulty
Hard
Community

OSED

OSED

Offensive Security Exploit Developer

Offensive Security

Advanced Windows exploit development (EXP-401) — stack overflows, DEP/ASLR bypass, and custom shellcode for senior offensive researchers.

Recruiter appeal
4.6
Difficulty
Hard
Community

OSED

OSED

Offensive Security Exploit Developer

Offensive Security

Offensive Security Exploit Developer — professional certification mapped from the Paul Jerimy security certification roadmap.

Recruiter appeal
4.6
Difficulty
Hard
Community

PNPT

PNPT

Practical Network Penetration Tester

TCM Security

Practical pentest exam with report writing; popular career bridge before OSCP.

Recruiter appeal
4.5
Difficulty
Medium
Community

GWAPT

GWAPT

GIAC Web Application Penetration Tester

GIAC / SANS

Deep web application security testing certification covering authentication, session management, and modern app attack surfaces.

Recruiter appeal
4.5
Difficulty
Hard
Community

SC-200

SC-200

Microsoft Security Operations Analyst

Microsoft

SOC analyst path using Microsoft Sentinel and Defender for threat detection and incident response.

Recruiter appeal
4.4
Difficulty
Medium
Community

GSEC

GSEC

GIAC Security Essentials

GIAC / SANS

Broad technical security baseline covering networking, IAM, crypto, and defense fundamentals.

Recruiter appeal
4.4
Difficulty
Medium
Community

CPENT

CPENT

Certified Penetration Testing Professional

EC-Council

Advanced 24-hour practical penetration test simulating multi-segment enterprise networks, AD, and evasion techniques.

Recruiter appeal
4.4
Difficulty
Hard
Community

CPTS

CPTS

HTB Certified Penetration Testing Specialist

Hack The Box

Practical penetration testing certification built on Hack The Box Academy labs and a multi-machine capstone exam.

Recruiter appeal
4.4
Difficulty
Medium
Community

BSCP

BSCP

Burp Suite Certified Practitioner

PortSwigger

Web application security exam proving ability to find and exploit vulnerabilities using Burp Suite in timed practical scenarios.

Recruiter appeal
4.4
Difficulty
Medium
Community

Learning resources