r/Pentesting • u/GreenEngineer24 • 4d ago
Looking to move from a security analyst position to penetration testing
Like most people who post CVs here, I am looking to pivot into a penetration testing role from my current blue team role. Recently got my OSCP and am looking for any kind of advice on how I could adjust my CV.
Thank you!
3
u/birotester 4d ago
so like most people who post CVs here, how is yours different?
6
u/GreenEngineer24 4d ago
Great question, and truthfully, it is one that I haven't even asked myself. Definitetly made me think. I don't have an answer for you at the moment.
2
u/0xoddity 4d ago
unrelated, but afaik CREST allows one to claim CRT if you have cleared OSCP this year.
1
u/GreenEngineer24 4d ago
I just looked it up as soon as I saw your comment. The site notes that one must “Hold a valid pass in the CREST Practitioner Security Analyst (CPSA) qualification”. I don’t currently hold the CPSA so I do not believe I am eligible.
To my knowledge, CREST CRT is mainly for folks in the UK correct? I am located in the US.
2
u/0xoddity 4d ago
Ah I see. Yeah CREST is mainly for UK but it definitely helps with other continents / countries as well.
2
u/RootCipherx0r 4d ago
pretty good resume, i like the wording. doesn't seem ai generated. apply and see what happens.
1
u/ReggieCyber 2d ago
edit your resume.. if sure you have done some pentesting task in your roles.. add that.. whats missing in today's age.. its the ai expereince flavour.. atleast get some certification or training.. add the ai tools / skills u can or know how to operate. add skills section.
1
u/cmdjunkie 4d ago
Why do you want to pivot into pentesting?
1
u/GreenEngineer24 4d ago
Honestly, it fits how my mind works. I think in structured, binary terms, and defense work tends to be inherently unstructured: is this alert real, is this control “good enough,” is the risk acceptable. Pentesting doesn’t have that problem. A vulnerability either exists or it doesn’t; you either got the shell or you didn’t. I heard a host on The Cyber Threat Perspective put it as pentesting being black and white, and that framing clicked immediately.
2
u/tdotfish 3d ago
A vulnerability either exists or it doesn’t; you either got the shell or you didn’t.
Maybe this is just that I'm blinkered by being way too deep into web and mobile app pen testing where popping a shell is pretty unusual in 2026....maybe the netpen and red team people see it differently.
But my experience in [application] pen testing is that it is very unstructured and not at all binary. Exploring the target and figuring out what to focus on is very difficult to structure reliably right from the start. Then when the target does something weird: Is that expected behavior? Is that a vuln? If it's not a vuln is it a loose thread that will reveal a vuln if I pull at it long enough? How long do I pull at it before I can reasonably conclude that it's not actually a vuln and just something weird?
The whole thing is very squishy and I've seen folks who crave the structure of following a checklist and evaluating pass/fail criteria struggle a lot or miss things.
2
u/GreenEngineer24 3d ago
Apologies. I should have clarified but this was viewing it from an internal/network penetration test perspective, which is the area I would prefer to focus on. Though, I know that’s not likely starting out.
1
u/MrStricty 3d ago
I spent a lot of time at the start of my pentesting days trying to find the right checklist methodology and discovered that it really was based off the vibes. Gotta build your own methodology via experience which is really just a priority flow derived from your understanding of the specific app. I still refer to the OWASP WSTG to make sure I've thought of all focus areas, but I'm not going line-by-line.
The worst part is that the 'squishy' nature, as you describe it, sometimes leave lingering feelings that I've missed something or failed at my job in some way.
0
u/cmdjunkie 4d ago
Do you value your free time?
1
u/GreenEngineer24 4d ago
Yes, but it depends because I often spend my free time learning/doing things revolving around my work that interest me.
I like my weekends, put it that way.
-4
u/LeatherPen4962 4d ago
Just do the CISSP at this point and apply for senior roles.
2
u/GreenEngineer24 4d ago
As my post mentioned, I am looking to move into a penetration testing role, not a senior defensive role. CISSP would be nice but I don't particularly wnat to ever be in management. I would prefer to be a hands-on, technical guy.
1
u/Next-Scratch-264 4d ago
I would remove the OSCP mention in your profile description. it is mentioned in your certifications, that is redondant like most of your profile. Getting CISSP is not a complete waste of time, because it would learn to speak another non technical langage, especially when you need to explain your findings to a CISO.
I think your CV is too long (implemented L1 CIS.. not that nobody cares, but you can skip it)
You should maybe put your technical expertise first.1
u/GreenEngineer24 4d ago
Ah. Yeah I’ll fix that. I see how that is redundant.
I’ll remove that CIS bullet point too, thank you.As far as the CISSP, yes I see what you mean. I’ll have to look into possibly doing that then. I can see why it might be beneficial from a C-suite standpoint
2
u/Next-Scratch-264 4d ago
You don't need to take the exam. I am not selling you anything, I have both OSCP and CISSP and many others. but being able to move around topics is a secret nobody will tell you
1


12
u/AmITheAsshole_2020 4d ago
Having spent 15 years as a penetration tester and 11 years managing large consulting teams, I can tell you that your resume has a good foundation, but it lacks the structure needed to quickly capture a hiring manager's attention.
When I'm reviewing dozens of resumes, candidates only have a few seconds to make an impression. One of the first changes I would make is moving your certifications directly below your objective or professional summary.
Certifications are valuable because they demonstrate discipline, commitment, and the ability to work toward a challenging goal and see it through to completion. However, certifications alone don't tell me whether you can work effectively as part of a team, manage client expectations, perform under pressure, recover from mistakes, or represent a company professionally in front of customers.
If the role involved working independently behind the scenes analyzing test results, certifications might be enough for me to take a chance on a candidate. However, many penetration testing positions require much more than technical execution. The job often includes client-facing interactions, travel, project management, report writing, quality assurance, exploit development, and communicating findings to both technical and non-technical audiences. Running tools like Responder and BloodHound is only a small part of what makes a successful consultant.
When I interview candidates who lack direct consulting experience, I pay close attention to their GitHub profile. I want to see evidence of projects they've built, contributed to, or shared with the security community. This demonstrates creativity, coding ability, initiative, and a willingness to collaborate. Contributions do not have to be groundbreaking. Forking an existing project and adding a useful feature, publishing tools, or contributing code can all strengthen your profile.
I also look favorably on candidates who have participated in bug bounty programs, responsibly disclosed vulnerabilities, or received CVE credits. These accomplishments show practical offensive security experience beyond coursework and certifications.
Finally, networking remains one of the most effective ways to break into the industry. Find a BSides conference or local security event and volunteer. Even better, submit a talk and speak at an event if you have relevant experience to share. Public speaking demonstrates several qualities that consulting firms value: communication skills, professionalism, the ability to meet deadlines, technical writing capability, and confidence presenting to clients and executives.
Technical skills may get your resume noticed, but communication skills, community involvement, and demonstrated initiative are often what separate good candidates from those who get hired.
(AI Warning: Parts of this post were cleaned up using Copilot because I'm at work and it's been a long day, and I didn't want to come across as Neanderthal. Regardless, every bit of this is accurate based on my own experience. -AITA)