Careerhelp

Penetration Tester

Get paid to break into companies' computer systems, with their written permission, so real attackers cannot.

Typical pay
$103,000a year
Time to qualify
3 to 6 yearsafter high school
Demand
Moderate
Licence needed
Noanyone can do it

Click through it

Start
Download the one-pagerPDF

Pay, the path, pros and cons and the facts on one printable page. Good for a wall or a guidance counsellor.

Or jump to a part

  1. 1.MoneyWhat you earn and what it costs to get there.5 screens
  2. 2.EducationThe exact path from high school to qualified.5 screens
  3. 3.OptionalThings you don't need, but that help.3 screens
  4. 4.ExtrasDay to day, pros and cons, where you'd work.4 screens
  5. 5.FactoidsThings people don't tell you.4 screens

Or read the whole thing here

Money

What you earn and what it costs to get there.

What penetration testers make

Typical

$103,000

Junior tester

$62,000

Senior or lead

$150,000

Job Bank pools penetration testers with all cybersecurity analysts (one group, NOC 21220). Its national median is $49.52 an hour, about $103,000 a year full time. Testers with a strong certification and a few years of experience tend to sit at or above that median.

Starting pay

$60,000 to $75,000

Junior tester or security analyst, first 1 to 2 years

Most people start in a broader security or IT role and move into testing. Toronto, Ottawa, Montreal, Calgary and Vancouver have the most jobs. Banks and big consulting firms pay the most for juniors.

Senior and specialist pay

$130,000 to $150,000+

Senior tester, red team lead, or independent consultant

Consultants who bill by the day, and testers who specialize in hard targets like cloud, mobile apps or industrial control systems, earn the most. Bug bounty payouts can add to this but are not steady income.

What it costs to get there

College diploma in cybersecurity or networking (2 to 3 years)
$4,000 to $8,000 a year in Ontario, more in BC and Alberta
University computer science degree (4 years)
$7,000 to $12,000 a year
OSCP (Offensive Security Certified Professional) course and exam
About US$1,750 for the course, labs and one exam attempt
Entry certifications like CompTIA Security+
A few hundred US dollars per exam
Home lab
A decent computer, mostly free software
Roughly, all in
$1,500 to $51,000

Tuition, fees, exams and kit. Not rent, food or travel

The low end is teaching yourself on free practice platforms, paying for one entry level security certification exam, and building a home lab on a computer you already own. The high end is a four year computer science degree at the top of the tuition range plus a well known hands on hacking certification whose course and exam are priced in US dollars. Most employers pay for certifications once you are hired, so the expensive ones are often better left until you have the job. Nothing here is required by law, which means the money buys credibility rather than a licence.

Many employers pay for certifications once you are hired. Practice platforms with free tiers cut the cost of learning.

Benefits and perks

  • Remote work

    Most testing is done over a secure connection from wherever you are.

  • Paid training and certifications

    Common, because the field changes fast and employers need you current.

  • Health, dental and a pension plan

    Standard at banks, government and large firms. Small consultancies vary.

  • Conference travel

    Security conferences are part of the culture and many employers cover them.

Education

The exact path from high school to qualified.

The path

No licence. Employers hire on proven skill: certifications, a home lab, and practice challenges you can talk about.

  1. 1

    High school

    Grades 11 and 12

    Computer science, math and English. Start learning Linux and basic networking at home now.

  2. 2

    Diploma or degree

    2 to 4 years

    A 2-year college cybersecurity diploma (Seneca, Algonquin, and the polytechnics in Calgary, Edmonton and Vancouver) or a 4-year computer science degree. Co-op programs help a lot.

  3. 3

    First job in IT or security

    1 to 3 years

    Help desk, network technician, or security operations analyst. Most testers do 1 to 3 years here first. Practice hacking legally on training platforms in your spare time.

  4. 4

    Get certified and move into testing

    6 to 12 months of study

    The OSCP (Offensive Security Certified Professional) is the certification most employers ask for. Its exam is a 24-hour hands-on test where you break into real machines.

  5. 5

    Specialize

    Ongoing

    Web apps, cloud, mobile, hardware, or red teaming (full attack simulations). Each specialty raises your rate.

High school courses that help

  • Computer science

    Programming basics. Python is the language testers use most for tools and scripts.

  • Math

    Logic and problem solving. Cryptography is math.

  • English

    A tester's real product is a written report a manager can understand.

  • Any networking or IT elective

    How data moves between computers is the foundation of the job.

Time and money, at a glance

Years after high school
3 to 6, including a first IT job
Admission
Diploma programs take a high school diploma with math; degrees usually want mid-70s or higher
Total tuition
$10,000 to $45,000
Paid while training?
Yes, once you land the first IT job
Licence required
No, but certifications matter a lot

Not regulated, but the law is strict

Anyone can call themselves a penetration tester. What separates a professional from a criminal is written permission: a signed scope agreement that says which systems you may attack, when, and how far. Testing anything without that permission is a crime under Canada's Criminal Code, no matter your intent. Employers also run background checks, and government and bank work often needs a security clearance.

Where people study

  • Alberta

    SAIT (Southern Alberta Institute of Technology) Cyber Security diploma, 2 years. NAIT (Northern Alberta Institute of Technology) also runs security programs.

  • Ontario

    Seneca Cybersecurity and Threat Management (8-month graduate certificate after a diploma or degree), Sheridan, Algonquin, Conestoga.

  • BC

    BCIT (British Columbia Institute of Technology) Computer Systems Technology, then security courses.

  • Universities

    Any computer science degree works. Concordia, Waterloo, Carleton and UNB (University of New Brunswick) have well-known security research groups.

Optional

Things you don't need, but that help.

Certifications that raise your rate

  • OSCP (Offensive Security Certified Professional)

    The one job ads ask for. A 24-hour practical exam. Hard, and respected because it is hard.

  • CompTIA Security+

    Entry level. Proves you know the basics before you go for the OSCP.

  • Web and cloud specialties

    Advanced OffSec certifications, plus AWS (Amazon Web Services) and Azure security credentials, open higher-paying work.

  • CISSP (Certified Information Systems Security Professional)

    A management-level certification that needs 5 years of security experience. Opens the door to leading a security team.

Nice-to-haves

  • A public record of practice

    Write-ups of training challenges, a small tool on GitHub, or a bug bounty acknowledgement.

  • Capture-the-flag competitions

    Team hacking contests. Many colleges and universities have clubs that compete.

  • Security clearance eligibility

    Federal contracts need it. Canadian citizenship or permanent residence and a clean record help.

  • Scripting

    Python and Bash. Testers who can automate get more done and get promoted.

Side path: bug bounties

Companies like Shopify and many US tech firms pay outside researchers for reporting real security holes. A handful of people make a full-time living at it, but most earn occasional payouts. It is a good way to build a reputation and a portfolio while you work a regular job. The rules of each program are your permission slip, so read them closely.

Extras

Day to day, pros and cons, where you'd work.

A typical engagement

A client hires your firm to test a web app, a network or an entire company. Day one is scoping: what you may touch and what you must not. Then a week or two of testing: mapping the systems, hunting for weaknesses, chaining small flaws into a real break-in, and proving impact without causing damage. The last days are writing. The report ranks every finding by risk and tells the client's developers how to fix it. Then a new client, a new target.

The honest trade-offs

The good

  • Puzzle solving you get paid well for
  • Remote friendly and in demand worldwide
  • No licence, skill is what counts
  • Clear ladder: analyst, tester, senior, red team lead or consultant

The hard parts

  • Constant studying; the tools and attacks change every year
  • Report writing is a big part of the job and nobody warns you
  • Deadlines and billable-hour pressure at consulting firms
  • The junior market is crowded; the first security job is the hard one

Work life

Typical hours
40 a week, late nights near report deadlines or during live attack simulations
Remote work
Very common
Physical demand
Low, all screen time
Unionized
Rarely, except government jobs

Factoids

Things people don't tell you.

The exam is 24 hours long

The OSCP (Offensive Security Certified Professional) exam gives you 24 hours to break into a set of machines while a proctor watches over a video link, then another day to write the report. People book time off work to sit it.

Canada has a national cyber defence centre

The Canadian Centre for Cyber Security is part of the Communications Security Establishment, the country's signals intelligence agency. It publishes threat alerts and advice for businesses and hires security specialists in Ottawa.

Permission is the whole difference

The same actions, run against the same server, are a paid job with a signed scope letter and a criminal offence without one. Professional testers keep that letter close.

Job Bank does not have a box for you yet

Penetration testers are counted with cybersecurity analysts in Canada's job statistics, one code (NOC 21220) that covers everything from monitoring alerts to breaking in. That is why pay data for the field is a wide range.

Where these numbers come from

Last checked September 2026. Pay figures are typical full-time annual amounts in Canadian dollars, based on Government of Canada Job Bank wage data and published salary grids. They vary by province, employer and experience. Tuition is for domestic students.