A Penetration Tester (ethical hacker) simulates real attacks to find and prove security weaknesses before criminals do.
Role overview
Penetration Testers assess networks, applications and systems, exploit weaknesses safely, and report findings with clear remediation. It demands strong networking and security fundamentals plus relentless curiosity.
Typical responsibilities
- Plan and scope authorised security tests.
- Enumerate, exploit and document vulnerabilities safely.
- Assess networks, web apps and systems against real threats.
- Write clear reports with prioritised remediation.
Required technical skills
- Networking (OSI, ports, protocols)
- Security fundamentals & common attacks
- Web and system enumeration
- Cryptography & authentication weaknesses
- Linux & scripting
Required soft skills
- Relentless curiosity
- Ethics and discretion
- Clear technical report writing
- Persistence and creativity
- Client communication
Recommended learning paths (vendor-neutral)
Understand a core concept
The Cyber Kill Chain
The seven stages of an intrusion — and where you can break it.
Tap or hover a part to learn more.
Research the target.
The attacker gathers information — emails, technologies, employees, exposed services — via OSINT and scanning. Defence: minimise public exposure, monitor for scanning.
Check your understanding
1. Blocking a malicious email attachment disrupts which stage?
2. Egress filtering and DNS monitoring most directly disrupt which stage?
Concepts to master — your readiness map
Work through these interactive Academy guides, marking each complete to build your Job Readiness Score for this role:
- CompTIA Security+ (overview)
- Threats, Attacks & Vulnerabilities
- The OSI Model
- Firewalls
- Cryptography & PKI
Recommended certifications
- CompTIA Security+
- CompTIA Network+
- CompTIA PenTest+ / OSCP — on the Academy roadmap
Technical interview preparation
- Walk me through the phases of a penetration test.
- How does the cyber kill chain map to an engagement?
- How would you approach testing a web application?
Behavioural interview preparation
- Describe reporting a serious finding responsibly.
- Tell me about persisting on a hard problem until you solved it.
Career progression
Junior Penetration Tester → Penetration Tester → Senior / Red Team, with PenTest+, OSCP and specialisation (web, cloud, red team).
Typical UK salary
Typically £30,000–£45,000 starting in the UK, rising to £55,000–£80,000+ for senior and red-team roles.
Prepare with Missiora
- AI Interview™ — run a scored mock interview for this exact role.
- Career Coach™ — get a personalised path from where you are to this role.
- Career Passport™ — evidence your skills and earn shareable achievements as your readiness grows.
