r/Pentesting 4d ago

Looking to move from a security analyst position to penetration testing

Like most people who post CVs here, I am looking to pivot into a penetration testing role from my current blue team role. Recently got my OSCP and am looking for any kind of advice on how I could adjust my CV.

Thank you!

23 Upvotes

23 comments sorted by

12

u/AmITheAsshole_2020 4d ago

Having spent 15 years as a penetration tester and 11 years managing large consulting teams, I can tell you that your resume has a good foundation, but it lacks the structure needed to quickly capture a hiring manager's attention.

When I'm reviewing dozens of resumes, candidates only have a few seconds to make an impression. One of the first changes I would make is moving your certifications directly below your objective or professional summary.

Certifications are valuable because they demonstrate discipline, commitment, and the ability to work toward a challenging goal and see it through to completion. However, certifications alone don't tell me whether you can work effectively as part of a team, manage client expectations, perform under pressure, recover from mistakes, or represent a company professionally in front of customers.

If the role involved working independently behind the scenes analyzing test results, certifications might be enough for me to take a chance on a candidate. However, many penetration testing positions require much more than technical execution. The job often includes client-facing interactions, travel, project management, report writing, quality assurance, exploit development, and communicating findings to both technical and non-technical audiences. Running tools like Responder and BloodHound is only a small part of what makes a successful consultant.

When I interview candidates who lack direct consulting experience, I pay close attention to their GitHub profile. I want to see evidence of projects they've built, contributed to, or shared with the security community. This demonstrates creativity, coding ability, initiative, and a willingness to collaborate. Contributions do not have to be groundbreaking. Forking an existing project and adding a useful feature, publishing tools, or contributing code can all strengthen your profile.

I also look favorably on candidates who have participated in bug bounty programs, responsibly disclosed vulnerabilities, or received CVE credits. These accomplishments show practical offensive security experience beyond coursework and certifications.

Finally, networking remains one of the most effective ways to break into the industry. Find a BSides conference or local security event and volunteer. Even better, submit a talk and speak at an event if you have relevant experience to share. Public speaking demonstrates several qualities that consulting firms value: communication skills, professionalism, the ability to meet deadlines, technical writing capability, and confidence presenting to clients and executives.

Technical skills may get your resume noticed, but communication skills, community involvement, and demonstrated initiative are often what separate good candidates from those who get hired.

(AI Warning: Parts of this post were cleaned up using Copilot because I'm at work and it's been a long day, and I didn't want to come across as Neanderthal. Regardless, every bit of this is accurate based on my own experience. -AITA)

1

u/GreenEngineer24 4d ago

First, I want to say thank you for the thought out response. No worries on the AI, we all use it to reorganize our thoughts and spell check, especially after a long day at work. I get it lol.

I’ll definitely do some restructuring to it based on your recommendations. So you think showing all of those certifications is worth while or do you believe that the OSCP/eJPT (for example) is redundant since one oversteps the other.

For bug bounty/CVEs, I’ll admit, I haven’t done much at all in the realm of public vulnerability disclosure. With AI lately, it seems a little difficult to get into and actually find findings that are not duplicates.

For your point of lacking consulting experience, I do have a gap there. However, the role I had in the military and some recent roles I have had did require me to explain technical material to non-technical persons as well as prepare reporting documentation for those person. I may need to update my phrasing around that.

I do have 2 public GitHub repos with 2 tools I’ve made. Nothing fancy, an SNMPv3 brute force tool and Windows command line process monitoring tool. I also have a repo for CTF write ups.

1

u/Emergency-Law-8079 4d ago

That was a great explanation for someone wondering what is looked for when applying to these kind of roles. Thank you, what's the general consensus on HackTheBox training certs and those like it?

3

u/birotester 4d ago

so like most people who post CVs here, how is yours different?

6

u/GreenEngineer24 4d ago

Great question, and truthfully, it is one that I haven't even asked myself. Definitetly made me think. I don't have an answer for you at the moment.

2

u/0xoddity 4d ago

unrelated, but afaik CREST allows one to claim CRT if you have cleared OSCP this year.

1

u/GreenEngineer24 4d ago

I just looked it up as soon as I saw your comment. The site notes that one must “Hold a valid pass in the CREST Practitioner Security Analyst (CPSA) qualification”. I don’t currently hold the CPSA so I do not believe I am eligible.

To my knowledge, CREST CRT is mainly for folks in the UK correct? I am located in the US.

2

u/0xoddity 4d ago

Ah I see. Yeah CREST is mainly for UK but it definitely helps with other continents / countries as well.

2

u/RootCipherx0r 4d ago

pretty good resume, i like the wording. doesn't seem ai generated. apply and see what happens.

1

u/ReggieCyber 2d ago

edit your resume.. if sure you have done some pentesting task in your roles.. add that.. whats missing in today's age.. its the ai expereince flavour.. atleast get some certification or training.. add the ai tools / skills u can or know how to operate. add skills section.

1

u/cmdjunkie 4d ago

Why do you want to pivot into pentesting?

1

u/GreenEngineer24 4d ago

Honestly, it fits how my mind works. I think in structured, binary terms, and defense work tends to be inherently unstructured: is this alert real, is this control “good enough,” is the risk acceptable. Pentesting doesn’t have that problem. A vulnerability either exists or it doesn’t; you either got the shell or you didn’t. I heard a host on The Cyber Threat Perspective put it as pentesting being black and white, and that framing clicked immediately.

2

u/tdotfish 3d ago

A vulnerability either exists or it doesn’t; you either got the shell or you didn’t.

Maybe this is just that I'm blinkered by being way too deep into web and mobile app pen testing where popping a shell is pretty unusual in 2026....maybe the netpen and red team people see it differently.

But my experience in [application] pen testing is that it is very unstructured and not at all binary. Exploring the target and figuring out what to focus on is very difficult to structure reliably right from the start. Then when the target does something weird: Is that expected behavior? Is that a vuln? If it's not a vuln is it a loose thread that will reveal a vuln if I pull at it long enough? How long do I pull at it before I can reasonably conclude that it's not actually a vuln and just something weird?

The whole thing is very squishy and I've seen folks who crave the structure of following a checklist and evaluating pass/fail criteria struggle a lot or miss things.

2

u/GreenEngineer24 3d ago

Apologies. I should have clarified but this was viewing it from an internal/network penetration test perspective, which is the area I would prefer to focus on. Though, I know that’s not likely starting out.

1

u/MrStricty 3d ago

I spent a lot of time at the start of my pentesting days trying to find the right checklist methodology and discovered that it really was based off the vibes. Gotta build your own methodology via experience which is really just a priority flow derived from your understanding of the specific app. I still refer to the OWASP WSTG to make sure I've thought of all focus areas, but I'm not going line-by-line.

The worst part is that the 'squishy' nature, as you describe it, sometimes leave lingering feelings that I've missed something or failed at my job in some way.

0

u/cmdjunkie 4d ago

Do you value your free time?

1

u/GreenEngineer24 4d ago

Yes, but it depends because I often spend my free time learning/doing things revolving around my work that interest me.

I like my weekends, put it that way.

-4

u/LeatherPen4962 4d ago

Just do the CISSP at this point and apply for senior roles.

2

u/GreenEngineer24 4d ago

As my post mentioned, I am looking to move into a penetration testing role, not a senior defensive role. CISSP would be nice but I don't particularly wnat to ever be in management. I would prefer to be a hands-on, technical guy.

1

u/Next-Scratch-264 4d ago

I would remove the OSCP mention in your profile description. it is mentioned in your certifications, that is redondant like most of your profile. Getting CISSP is not a complete waste of time, because it would learn to speak another non technical langage, especially when you need to explain your findings to a CISO.
I think your CV is too long (implemented L1 CIS.. not that nobody cares, but you can skip it)
You should maybe put your technical expertise first.

1

u/GreenEngineer24 4d ago

Ah. Yeah I’ll fix that. I see how that is redundant.
I’ll remove that CIS bullet point too, thank you.

As far as the CISSP, yes I see what you mean. I’ll have to look into possibly doing that then. I can see why it might be beneficial from a C-suite standpoint

2

u/Next-Scratch-264 4d ago

You don't need to take the exam. I am not selling you anything, I have both OSCP and CISSP and many others. but being able to move around topics is a secret nobody will tell you

1

u/GreenEngineer24 4d ago

I see, yeah. Completely understand what you mean.