Ethical Hacker / Penetration Tester
Get paid to break into systems — legally.
What does a Ethical Hacker / Penetration Tester do?
Ethical hackers are hired to attack systems before the bad guys can — finding vulnerabilities in networks, apps, and infrastructure, then writing up exactly how they did it. You work with a mix of scripting, deep technical knowledge, and creative thinking to find weaknesses others miss. This path takes time to get into but pays off significantly. Good fit if you enjoy deep technical problems and want to specialise in something most people never attempt.
Who it fits
People who enjoy puzzles, think like attackers, and get a kick out of finding the flaw nobody else noticed.
Suits hands-on learners who thrive on puzzles and are comfortable with trial and error.
Skills you need
Tools you will use
Starter projects
Good projects to practise and add to a portfolio.
- Complete a beginner room on TryHackMe
- Set up a home lab with a vulnerable VM and attack it
- Write a Python port scanner from scratch
- Capture the Flag (CTF) writeup on a public challenge
// ROADMAP
Ethical Hacker / Penetration Tester career roadmap
Estimated time: 12–18 months
Badges show what each resource is. Only items marked certification lead to a professional credential — everything else is learning material.
Networking Fundamentals
6–8 weeksEverything in security starts with networking. TCP/IP, DNS, HTTP/S, ports, protocols. You need to understand how data moves across a network before you can attack or defend one.
Linux & Scripting
4–6 weeksKali Linux is the standard pentesting OS. Get fluent with the Linux command line, learn Bash scripting, and write basic Python scripts for automating reconnaissance tasks.
TryHackMe & Structured Learning
8–12 weeksTryHackMe has guided paths specifically for ethical hacking. Work through the Pre-Security and Jr Penetration Tester paths in order — they are genuinely well-designed for beginners.
Web Application Hacking
6–8 weeksWeb applications are the most common target. Learn the OWASP Top 10, practise on PortSwigger Web Security Academy, and learn to use Burp Suite for intercepting and modifying HTTP traffic.
CTF Practice & Certification
12–16 weeksCTF competitions build your skills faster than anything else. Start with picoCTF (beginner-friendly), progress to Hack The Box. Pursue CEH first, then OSCP when you are ready.
// START LEARNING
Ethical Hacker / Penetration Tester learning resources
Videos first — they're the fastest way to get moving — then reading, hands-on practice and courses. Only resources badged professional certification award a formal credential.
The Hacker's Roadmap: Getting Started in Cybersecurity
NetworkChuck · 25 minutes
A current orientation to the certifications, practical skills and experience needed to enter cybersecurity.
Learning resource. This does not award a professional certification.
Networking Basics
Cisco Skills for All
A free foundational course covering network devices, protocols, addressing and basic troubleshooting.
Certificate availability depends on the course provider.
Linux Journey
LabEx
Short progressive lessons on the command line, permissions, processes, networking and system administration.
Certificate availability depends on the course provider.
OWASP Top 10
OWASP
The industry-standard awareness guide to the most important web application security risks.
Learning resource. This does not award a professional certification.
Introduction to Cyber Security
TryHackMe
Guided browser-based labs introducing offensive security, defensive security, networking and web concepts.
Learning resource. This does not award a professional certification.
Web Security Academy
PortSwigger
Free learning paths and realistic labs for web vulnerabilities, testing methodology and exploitation.
Learning resource. This does not award a professional certification.
// PRACTISE
Gain Ethical Hacker / Penetration Tester work experience
Build practical evidence before your first role. Provider terms and eligibility can change.
GitHub · Good first issues
open-source · REMOTE
Find newcomer-labelled issues and build evidence of collaboration in public repositories.
PortSwigger Web Security Academy · Web security practice labs
hands-on-lab · REMOTE
Solve realistic web-vulnerability labs and document methodology and results as practical security evidence.
pwn.college · Program security challenges
hands-on-lab · REMOTE
Complete structured binary exploitation and reverse-engineering challenges in an online practice environment.
// FIND WORK
Find Ethical Hacker / Penetration Tester jobs
Start with “Penetration Tester”. Platforms without stable public search URLs open with this suggested phrase.
LinkedIn Jobs
Broad professional job search with keyword, location, experience-level and remote filters.
Wellfound
Startup and technology roles with company and compensation context.
Dice
Specialist technology roles across engineering, data, security and infrastructure.
Built In
Technology and startup job discovery, including remote and city-focused listings.
UK visa and international opportunities
Sponsorship depends on the employer, vacancy and current immigration rules. Use the linked official guidance and verify every role before applying.
Going independent
Ethical hacking is one of the most viable specialist paths for independent work. Bug bounty hunting alone can be a full-time income at sufficient skill level.
Bug Bounty Hunting
Medium effortFind and report vulnerabilities in companies that run public bug bounty programmes through platforms like HackerOne and Bugcrowd.
Examples
- Web application vulnerability reports on HackerOne
- Mobile app security reports on Bugcrowd
- Specific disclosure reports on company VDPs
Getting started
- 1. Complete TryHackMe and Hack The Box paths first
- 2. Start with less competitive programmes on HackerOne
- 3. Focus on a specific class of vulnerability to build expertise fast
- 4. Keep a private report of every vulnerability you find, even if duplicated
Freelance Penetration Testing
Medium effortConduct formal penetration tests for businesses on a contract basis.
Examples
- Web application penetration tests
- Network security assessments for SMEs
- Social engineering and phishing exercises
- Cloud security assessments
Getting started
- 1. Get CREST CRT or OSCP certification
- 2. Build a professional scope-of-work and report template
- 3. Subcontract through established pen test firms initially
- 4. Approach solicitors, accountants, and healthcare providers for compliance-driven work
Communities & tools
// EARNING POTENTIAL
Earning potential
2025Ethical hackers with OSCP and real-world experience are in high demand. Bug bounty income can supplement salary significantly at the right skill level.
Freelance rates
Day rate
£350–£1k
Hourly rate
£45–£125
What affects salary
- OSCP certification is the strongest differentiator in this field
- SC and DV security clearance adds premium in government and defence contracts
- Bug bounty payouts can be substantial — top researchers earn six figures from bounties alone
- Web application pentesting is the most in-demand specialism
- Writeup quality and CTF history are reviewed during hiring at the best firms
🌍 US ethical hackers at financial institutions earn $120k–$180k. Remote pentesting is possible but some roles require on-site presence.
Based on: Glassdoor UK · LinkedIn Salary · CyberSeek · ec-council Salary Guide. All figures approximate.
// RESOURCES
Free resources to get started
Recommended starting points — no payment required.
- Lab
- Lab
- Lab
- Course
- Lab
Paid courses worth considering
These are not required — free resources above can get you far.
- Course
- Professional certification
Browse all resources
Resource directory.
Free and paid resources across every tech career path — searchable and filterable.
Not sure this fits?
Take the assessment.
Answer a few short questions and get your top matches — with reasons why they fit you.
Wondering if you are ready for this path? Analyse your CV →
Related careers
Compare paths that share skills, tools or ways of working.


