Education · 1 of 5
The path
Nobody licenses this. You get hired on evidence that you can actually do it.
- 1
High school
Grades 11 and 12
Learn to program a little, build a home lab out of old machines or free virtual ones, and start breaking things you own.
- 2
Degree or certification, or both
0 to 4 years
A two-year or four-year cybersecurity or computer science degree is the common route. Self-taught people get in too, but they need a certification to prove it.
- 3
A first technical job
1 to 3 years
Help desk, systems administration, network support or a security operations center. You need to understand how systems are built before you can break them.
- 4
Get a hands-on certification
3 to 12 months of study
The Offensive Security Certified Professional (OSCP) exam is 24 hours of proctored practical hacking. The CompTIA PenTest+ exam runs 165 minutes with up to 90 questions.
- 5
Junior penetration tester
First role
Join a consulting firm or an in-house red team. You learn the report writing and the client side on the job.