Education · 1 of 5

The path

Nobody licenses this. You get hired on evidence that you can actually do it.

  1. 1

    High school

    Grades 11 and 12

    Learn to program a little, build a home lab out of old machines or free virtual ones, and start breaking things you own.

  2. 2

    Degree or certification, or both

    0 to 4 years

    A two-year or four-year cybersecurity or computer science degree is the common route. Self-taught people get in too, but they need a certification to prove it.

  3. 3

    A first technical job

    1 to 3 years

    Help desk, systems administration, network support or a security operations center. You need to understand how systems are built before you can break them.

  4. 4

    Get a hands-on certification

    3 to 12 months of study

    The Offensive Security Certified Professional (OSCP) exam is 24 hours of proctored practical hacking. The CompTIA PenTest+ exam runs 165 minutes with up to 90 questions.

  5. 5

    Junior penetration tester

    First role

    Join a consulting firm or an in-house red team. You learn the report writing and the client side on the job.