Author Topic: Anyone working in the penetration testing industry?  (Read 553 times)

0 Members and 1 Guest are viewing this topic.

Offline gentlemanscratch

  • /dev/null
  • *
  • Posts: 7
  • Cookies: 1
    • View Profile
Anyone working in the penetration testing industry?
« on: October 26, 2015, 04:19:06 am »
So I'm graduating soon and so far (as far as I can tell) the thing I want to do is work for a computer security company which outsources pen tests. I imagine a few people on EZ work in the area. For any of you that do and want to take the time to answer a few of my questions, that would be sweet.

1) How did you get your foot in the door? (Did you specifically look for a pen testing job, did someone come to you, etc?)
2) Were there any specific qualifications your employers looked for? (Degree in some area, published papers, code, etc?)
3) What's the pay like?
4) Do you enjoy your job?
5) What exactly is your position and what do your specific duties entail?
6) Do you work for a company or do you do freelance work?

Those are all the relevant questions I can think of for now, feel free to not answer any questions you don't feel comfortable answering for any reason. I'll post more if I think of any.

Offline Mordred

  • Knight
  • **
  • Posts: 360
  • Cookies: 135
  • Nvllivs in Verba
    • View Profile
Re: Anyone working in the penetration testing industry?
« Reply #1 on: October 27, 2015, 01:43:28 pm »
Hey gentlemanscratch and welcome to EZ first of all! (Nice nickname btw  ;D).

I sort of fit in your profile, with the exception of not working for a company which outsources penetration testing, but rather I work for a software development company and conduct penetration testing on internal products before they hit the market.

Now on to the questions (answers in italics):

1) How did you get your foot in the door? (Did you specifically look for a pen testing job, did someone come to you, etc?)
After doing a Bachelor of Engineering (I.T. specialization) and in parallel studying relevant sub-fields of the Security domain I set up my LinkedIn profile in such a way that it would come up as a hit for headhunters/recruiters looking to hire in the Sec industry (I wasn't fixed on pen-testing at the time and was interested in working in basically any field of Sec - RE, Malware Analysis, AV development, Pen Testing, Red Team, Blue Team, etc.). Apart from that I also looked at what skills are required at entry level for the jobs I was interested in, focused hard on broadening my knowledge in that particular field as fast as possible and applied to those particular companies as well.
In the end I got my previous job by applying (I didn't like it much) and got my current job (which I love) by getting recruited.


2) Were there any specific qualifications your employers looked for? (Degree in some area, published papers, code, etc?)
Degree in I.T. or related. Everything else was interview-based. No requirements for certifications, papers or code although they can be useful. But because I did not have any hard proof of my knowledge I had to undergo a more rigorous technical interview (like a multiple-choice exam combined with a couple of hypothetical case studies).

3) What's the pay like?
In my country it's great. Entry level pay is somewhere in the vicinity of 4-5 times the minimum wage. With experience and time it can go as high as 15-20 times the minimum wage.

4) Do you enjoy your job?
My current job, yes, yes I do. I actually love it and come to work happy and go home happy. Of course no job is without its idiots/fucktards/autistic fuckers, but knowledge and confidence pwn in the Sec industry. Prove you got dem skillz and people tend to listen.

5) What exactly is your position and what do your specific duties entail?
Penetration Tester. Part of Red Team. Duties entail conducting full penetration testing for any application that gets produced by my company, as well as various other Red Team tasks (custom protocol reverse engineering, exploit development, reverse engineering for the purpose of testing anti-cracking hardening, etc.). The applications range is quite broad and I've had projects which involved auditing web apps, PC client apps, PC server apps and mobile apps with everything that this entails (client-side, server-side, server posture, communications, etc.).

6) Do you work for a company or do you do freelance work?
I work for a company. Never did or tried freelancing.


I hope this answers some of your questions.
« Last Edit: October 27, 2015, 01:46:42 pm by Mordred »
\x57\x68\x79\x20\x64\x69\x64\x20\x79\x6f\x75\x20\x65\x76\x65\x6e\x20\x66\x75\x63\x6b\x69\x6e\x67\x20\x73\x70\x65\x6e\x64\x20\x74\x68\x65\x20\x74\x69\x6d\x65\x20\x74\x6f\x20\x64\x65\x63\x6f\x64\x65\x20\x74\x68\x69\x73\x20\x6e\x69\x67\x67\x72\x3f\x20\x44\x61\x66\x75\x71\x20\x69\x73\x20\x77\x72\x6f\x6e\x67\x20\x77\x69\x74\x68\x20\x79\x6f\x75\x2e

Offline gentlemanscratch

  • /dev/null
  • *
  • Posts: 7
  • Cookies: 1
    • View Profile
Re: Anyone working in the penetration testing industry?
« Reply #2 on: October 28, 2015, 03:59:18 pm »
Perfect reply, much appreciated Mordred, just what I was looking for

Offline ca0s

  • VIP
  • Sir
  • *
  • Posts: 432
  • Cookies: 53
    • View Profile
    • ka0labs #
Re: Anyone working in the penetration testing industry?
« Reply #3 on: October 31, 2015, 03:34:07 am »
Maybe late , but:

1) I was finishing my degree, last semester. Professor tells us that enterprise X is looking for interns to dfo some pentesting related stuff. Apply and get in. Work for 6 months. Then go for summer vacations, and get a job in another place. This time I was looking for it, having worked as an intern in previous one definetely helped.

2) Any university degree to begin with. Experience with computer security stuff. Technical interview. Nothing about certs.

3) Average+. Pretty nice being my first job.

4) Totally. I have the chance to pentest several types of applications. From the typical webapp to a totally custom and critical internal app. Damn interesting stuff.

5) "Junior IT Security Analyst" or something like that.  Penetration testing, risk analysis.

6) Company.
« Last Edit: October 31, 2015, 03:48:17 am by ca0s »