Ethical Hacker / Penetration Tester

Get paid to break into systems — legally.

advanced Remote friendly

What does a Ethical Hacker / Penetration Tester do?

Ethical hackers are hired to attack systems before the bad guys can — finding vulnerabilities in networks, apps, and infrastructure, then writing up exactly how they did it. You work with a mix of scripting, deep technical knowledge, and creative thinking to find weaknesses others miss. This path takes time to get into but pays off significantly. Good fit if you enjoy deep technical problems and want to specialise in something most people never attempt.

Who it fits

People who enjoy puzzles, think like attackers, and get a kick out of finding the flaw nobody else noticed.

Suits hands-on learners who thrive on puzzles and are comfortable with trial and error.

Skills you need

Network securityVulnerability assessmentSocial engineeringScriptingReport writing

Tools you will use

Kali LinuxMetasploitBurp SuiteNmapWireshark

Starter projects

Good projects to practise and add to a portfolio.

  • Complete a beginner room on TryHackMe
  • Set up a home lab with a vulnerable VM and attack it
  • Write a Python port scanner from scratch
  • Capture the Flag (CTF) writeup on a public challenge

// ROADMAP

Ethical Hacker / Penetration Tester career roadmap

Estimated time: 12–18 months

Badges show what each resource is. Only items marked certification lead to a professional credential — everything else is learning material.

1

Networking Fundamentals

6–8 weeks

Everything in security starts with networking. TCP/IP, DNS, HTTP/S, ports, protocols. You need to understand how data moves across a network before you can attack or defend one.

2

Linux & Scripting

4–6 weeks

Kali Linux is the standard pentesting OS. Get fluent with the Linux command line, learn Bash scripting, and write basic Python scripts for automating reconnaissance tasks.

3

TryHackMe & Structured Learning

8–12 weeks

TryHackMe has guided paths specifically for ethical hacking. Work through the Pre-Security and Jr Penetration Tester paths in order — they are genuinely well-designed for beginners.

4

Web Application Hacking

6–8 weeks

Web applications are the most common target. Learn the OWASP Top 10, practise on PortSwigger Web Security Academy, and learn to use Burp Suite for intercepting and modifying HTTP traffic.

5

CTF Practice & Certification

12–16 weeks

CTF competitions build your skills faster than anything else. Start with picoCTF (beginner-friendly), progress to Hack The Box. Pursue CEH first, then OSCP when you are ready.

// START LEARNING

Ethical Hacker / Penetration Tester learning resources

Videos first — they're the fastest way to get moving — then reading, hands-on practice and courses. Only resources badged professional certification award a formal credential.

VideoFree

The Hacker's Roadmap: Getting Started in Cybersecurity

NetworkChuck · 25 minutes

A current orientation to the certifications, practical skills and experience needed to enter cybersecurity.

Learning resource. This does not award a professional certification.

CourseFree

Networking Basics

Cisco Skills for All

A free foundational course covering network devices, protocols, addressing and basic troubleshooting.

Certificate availability depends on the course provider.

CourseFree

Linux Journey

LabEx

Short progressive lessons on the command line, permissions, processes, networking and system administration.

Certificate availability depends on the course provider.

ReadingFree

OWASP Top 10

OWASP

The industry-standard awareness guide to the most important web application security risks.

Learning resource. This does not award a professional certification.

LabFree

Introduction to Cyber Security

TryHackMe

Guided browser-based labs introducing offensive security, defensive security, networking and web concepts.

Learning resource. This does not award a professional certification.

LabFree

Web Security Academy

PortSwigger

Free learning paths and realistic labs for web vulnerabilities, testing methodology and exploitation.

Learning resource. This does not award a professional certification.

Browse all learning resources →

// PRACTISE

Gain Ethical Hacker / Penetration Tester work experience

Build practical evidence before your first role. Provider terms and eligibility can change.

GitHub · Good first issues

open-source · REMOTE

Free to participate

Find newcomer-labelled issues and build evidence of collaboration in public repositories.

PortSwigger Web Security Academy · Web security practice labs

hands-on-lab · REMOTE

Free to participate

Solve realistic web-vulnerability labs and document methodology and results as practical security evidence.

pwn.college · Program security challenges

hands-on-lab · REMOTE

Free to participate

Complete structured binary exploitation and reverse-engineering challenges in an online practice environment.

Explore all experience options →

// FIND WORK

Find Ethical Hacker / Penetration Tester jobs

Start with “Penetration Tester”. Platforms without stable public search URLs open with this suggested phrase.

LinkedIn Jobs

Free with optional premium

Broad professional job search with keyword, location, experience-level and remote filters.

Wellfound

Free for job seekers

Startup and technology roles with company and compensation context.

Dice

Free for job seekers

Specialist technology roles across engineering, data, security and infrastructure.

Built In

Free for job seekers

Technology and startup job discovery, including remote and city-focused listings.

Compare all job platforms →

UK visa and international opportunities

Sponsorship depends on the employer, vacancy and current immigration rules. Use the linked official guidance and verify every role before applying.

Going independent

Ethical hacking is one of the most viable specialist paths for independent work. Bug bounty hunting alone can be a full-time income at sufficient skill level.

Bug Bounty Hunting

Medium effort
⏱ 3–12 months to first income£1,000–£50,000+ per month (variable)

Find and report vulnerabilities in companies that run public bug bounty programmes through platforms like HackerOne and Bugcrowd.

Examples

  • Web application vulnerability reports on HackerOne
  • Mobile app security reports on Bugcrowd
  • Specific disclosure reports on company VDPs

Getting started

  1. 1. Complete TryHackMe and Hack The Box paths first
  2. 2. Start with less competitive programmes on HackerOne
  3. 3. Focus on a specific class of vulnerability to build expertise fast
  4. 4. Keep a private report of every vulnerability you find, even if duplicated

Freelance Penetration Testing

Medium effort
⏱ 3–8 months to first income£350–£1,000 per day

Conduct formal penetration tests for businesses on a contract basis.

Examples

  • Web application penetration tests
  • Network security assessments for SMEs
  • Social engineering and phishing exercises
  • Cloud security assessments

Getting started

  1. 1. Get CREST CRT or OSCP certification
  2. 2. Build a professional scope-of-work and report template
  3. 3. Subcontract through established pen test firms initially
  4. 4. Approach solicitors, accountants, and healthcare providers for compliance-driven work

Communities & tools

Bugcrowd DiscordHackerOne Communityr/netsecDC4420 London DEF CON chapterBurp SuiteMetasploitKali LinuxHackerOneBugcrowdCobalt Strike

// EARNING POTENTIAL

Earning potential

2025

Ethical hackers with OSCP and real-world experience are in high demand. Bug bounty income can supplement salary significantly at the right skill level.

junior£30k–£45k
mid£50k–£72k
senior£75k–£105k
lead£100k–£140k

Freelance rates

Day rate

£350–£1k

Hourly rate

£45–£125

What affects salary

  • OSCP certification is the strongest differentiator in this field
  • SC and DV security clearance adds premium in government and defence contracts
  • Bug bounty payouts can be substantial — top researchers earn six figures from bounties alone
  • Web application pentesting is the most in-demand specialism
  • Writeup quality and CTF history are reviewed during hiring at the best firms

🌍 US ethical hackers at financial institutions earn $120k–$180k. Remote pentesting is possible but some roles require on-site presence.

Based on: Glassdoor UK · LinkedIn Salary · CyberSeek · ec-council Salary Guide. All figures approximate.

// RESOURCES

Free resources to get started

Recommended starting points — no payment required.

  • Lab
  • Lab
  • Lab
  • Course
  • Lab

Paid courses worth considering

These are not required — free resources above can get you far.

  • Course
  • Professional certification

Browse all resources

Resource directory.

Free and paid resources across every tech career path — searchable and filterable.

Browse resources →

Not sure this fits?

Take the assessment.

Answer a few short questions and get your top matches — with reasons why they fit you.

Start assessment

Wondering if you are ready for this path? Analyse your CV →

Compare paths that share skills, tools or ways of working.

Help us improve your experience

We use analytics to understand how people use Skill to Life and improve the product. We do not use analytics to identify you. You can accept or reject optional cookies — the site works either way.

Privacy policy