Careerhelp

Penetration Tester

You break into computer systems on purpose, with written permission, and then explain exactly how you did it.

Typical pay
$129,180a year
Time to qualify
1 to 4 yearsafter high school
Demand
Very high
Licence needed
Noanyone can do it

Click through it

Start
Download the one-pagerPDF

Pay, the path, pros and cons and the facts on one printable page. Good for a wall or a guidance counsellor.

Or jump to a part

  1. 1.MoneyWhat you earn and what it costs to get there.5 screens
  2. 2.EducationThe exact path from high school to qualified.5 screens
  3. 3.OptionalThings you don't need, but that help.3 screens
  4. 4.ExtrasDay to day, pros and cons, where you'd work.4 screens
  5. 5.FactoidsThings people don't tell you.4 screens

Or read the whole thing here

Money

What you earn and what it costs to get there.

What penetration testers make

Typical

$129,180

Junior tester

$75,090

Senior or red team lead

$199,850

The federal survey has no separate line for penetration testers. It counts them inside Information Security Analysts, where the national median is $129,180 a year and the bottom tenth start near $75,090. Consulting firms that bill testers by the day tend to pay above that median.

Your first tester job

$75,000 to $95,000

Junior on a consulting team, usually after a help desk or analyst job

Very few people get hired straight into offensive work. Most start in information technology support or on a defensive security team, then move across once they have a certification and some proof they can do it.

The top tenth

About $199,850 a year

Senior testers, red team leads and specialists

Above that sit people who specialize: cloud, hardware, industrial control systems, or breaking mobile apps. Independent consultants and top bug bounty hunters can beat it, with no salary and no benefits.

What it costs to get there

Community college cybersecurity degree
Roughly $4,000 to $8,000 a year in in-state tuition
Bachelor's degree, in-state public
About $11,000 to $15,000 a year in tuition
Offensive Security Certified Professional (OSCP)
$1,749 for the course bundle with one exam attempt, or $1,699 for the exam alone
A week-long training course with a vendor
Around $8,780 for the SANS Institute (a private security training company) course that leads to the GIAC Penetration Tester (GPEN) certification
Roughly, all in
$500 to $46,000

Tuition, fees, exams and kit. Not rent, food or travel

Almost all of the skill here can be built for free using practice labs, capture the flag events, deliberately vulnerable machines and the free federal training catalog, so the low end is one entry level certification exam fee and nothing else. The high end is a four year bachelor's degree in cybersecurity at an in state public university plus the Offensive Security Certified Professional certification, which is about one thousand seven hundred dollars for the exam alone. A week long vendor course can add close to nine thousand dollars on its own, and employers frequently pay for that one once you are already hired. The cheap door is harder to walk through than the price suggests, because self taught candidates have to prove themselves through public write ups and lab rankings that a degree holder does not need.

You can get most of the skill for free. Practice labs, capture the flag events and deliberately vulnerable machines cost nothing, and the federal government publishes a free training catalog. The money goes on the certification that makes a hiring manager take you seriously.

What comes with the job

  • Remote work

    Most testing is done over a network, so this is one of the most remote-friendly technical jobs there is.

  • Employer-paid certifications

    Good firms budget for a course and exam every year, which is thousands of dollars of training.

  • Conference travel

    Security conferences are a real part of the culture, and employers often pay.

  • Clearance premium

    Government and defense work pays extra for a security clearance, and the clearance follows you.

Education

The exact path from high school to qualified.

The path

Nobody licenses this. You get hired on evidence that you can actually do it.

  1. 1

    High school

    Grades 11 and 12

    Learn to program a little, build a home lab out of old machines or free virtual ones, and start breaking things you own.

  2. 2

    Degree or certification, or both

    0 to 4 years

    A two-year or four-year cybersecurity or computer science degree is the common route. Self-taught people get in too, but they need a certification to prove it.

  3. 3

    A first technical job

    1 to 3 years

    Help desk, systems administration, network support or a security operations center. You need to understand how systems are built before you can break them.

  4. 4

    Get a hands-on certification

    3 to 12 months of study

    The Offensive Security Certified Professional (OSCP) exam is 24 hours of proctored practical hacking. The CompTIA PenTest+ exam runs 165 minutes with up to 90 questions.

  5. 5

    Junior penetration tester

    First role

    Join a consulting firm or an in-house red team. You learn the report writing and the client side on the job.

High school courses that help

  • Computer science

    Any programming. Python and scripting turn up constantly in this work.

  • Math

    Logic and discrete math underpin cryptography and how you reason about systems.

  • English

    Half this job is writing a report a manager can act on. Testers who cannot write stay junior.

  • Networking or information technology courses

    If your school offers them, they teach the plumbing you will attack.

Time and money, at a glance

Years after high school
1 to 4 before a first security job
License required
No, but written permission from the client is legally essential
Total tuition
$0 if self-taught, up to about $60,000 for a four-year in-state degree
Paid while training?
Usually yes, because most people learn in an earlier technology job

No license, but a very real law

There is no state or federal license for penetration testing, and anyone can call themselves one. What is not optional is authorization. Accessing a computer system without permission is a federal crime in the United States, and the only thing separating this career from that crime is a signed scope document saying what you may test, when and how. Professional engagements start with that paperwork every single time, and a tester who goes outside the agreed scope is the one holding the risk.

Where people learn it

  • Community colleges

    Two-year cybersecurity degrees at in-state tuition, often with an internship attached.

  • Universities

    Computer science or cybersecurity degrees, and many campuses run a competitive hacking team.

  • Free federal resources

    The National Initiative for Cybersecurity Careers and Studies, run by the Cybersecurity and Infrastructure Security Agency (CISA), publishes a training catalog and career pathway tools.

  • Practice platforms

    Online labs full of deliberately vulnerable machines. This is where almost everyone actually learns the craft.

Optional

Things you don't need, but that help.

Certifications that get you hired

  • Offensive Security Certified Professional (OSCP)

    A 24-hour practical exam where you have to compromise real machines. It is the one hiring managers respect most.

  • CompTIA PenTest+

    Covers planning, reconnaissance, exploitation and reporting. Easier to reach than the practical exams and useful for a first job.

  • GIAC Penetration Tester (GPEN)

    From the SANS Institute (a private security training company). Expensive, common in government and defense work.

  • Cloud security certifications

    Most targets now live in cloud accounts, and testers who understand cloud identity are in short supply.

Nice-to-haves

  • A public portfolio

    Write-ups of practice boxes, a tool you built, a talk you gave. This substitutes for experience you do not have yet.

  • Programming beyond scripting

    Reading source code lets you find bugs nobody has found yet, instead of running other people's tools.

  • Capture the flag competitions

    Team hacking events. Good practice, and recruiters watch the scoreboards.

  • A clean record

    Client work and clearances involve background checks. Illegal hacking as a teenager closes doors permanently.

Bug bounties as a side path

Many companies pay outsiders for reported vulnerabilities through public bug bounty programs. It is a legal way to practice on real systems within rules the company publishes, and a way to build a name before anyone will hire you. Be clear-eyed about the money: most reports earn nothing, a few earn a few hundred dollars, and the people making a living at it are a small elite. Treat it as a portfolio and training, not income.

Extras

Day to day, pros and cons, where you'd work.

A typical week

An engagement usually runs one or two weeks. Day one is scoping and reconnaissance: mapping what the client actually has exposed. Then scanning, finding a way in, escalating from a normal account to an administrator, and moving sideways through the network to see how far you get. You keep notes and screenshots of everything, because the deliverable is a written report ranking each finding and telling the client how to fix it. Then you present it to people who may not want to hear it.

The honest trade-offs

The good

  • Strong pay, with a median of $129,180 and a bright federal outlook
  • No license and no mandatory degree, so the door is open to self-taught people
  • Heavily remote friendly
  • The work is genuinely a puzzle, and it changes constantly

The hard parts

  • Almost nobody gets hired into it directly, so expect a few years elsewhere first
  • Report writing and client meetings are most of the job, not the hacking
  • You have to keep learning forever or you are obsolete in 3 years
  • Deadlines are fixed and some engagements find nothing, which is still your problem to explain

Work life

Typical hours
40 to 50 a week, with occasional overnight testing windows
Remote work
Very common
Physical demand
Low
Unionized
No

Factoids

Things people don't tell you.

The best known exam lasts 24 hours

The Offensive Security Certified Professional exam gives you a day inside a private network to compromise machines, watched by a proctor, then time afterwards to write the report. Plenty of people fail it more than once.

The paperwork is the difference

The same actions are either a paid engagement or a federal crime. The only thing that changes is a signed authorization naming what you are allowed to touch.

Physical testing is part of it

Some engagements include getting into the building: tailgating through a door, cloning a badge, or leaving a device plugged in under a desk. Testers carry a signed letter in case security detains them.

The government gives the training away

The Cybersecurity and Infrastructure Security Agency publishes a free catalog of cybersecurity training and career pathway tools, aimed at beginners as well as working professionals.

Where these numbers come from

Last checked September 2026. Pay figures are typical full-time annual amounts in United States dollars, based on Bureau of Labor Statistics wage data and published pay scales. They vary by state, employer and experience. Tuition is for in-state students at public schools unless the card says otherwise.