Penetration Tester Roadmap 2026
Hack systems legally to make them more secure
Penetration testers (ethical hackers) simulate real-world attacks to find vulnerabilities before malicious hackers do. You're the authorized attacker every company needs.
Key facts
- Difficulty: Hard
- Time to job-ready: 10-16 months to job-ready
- Demand: Very High
- Salary (India): ₹5-15 LPA (entry) → ₹18-50 LPA (senior)
- Salary (Global): $65K-95K (entry) → $120K-200K+ (senior)
- Growth: Outstanding — cybercrime is growing, and every company needs security testing. Massive talent shortage.
Skills you need
- Networking
- Linux
- Web Security
- Scripting
- Exploit Development
- Social Engineering
- Report Writing
Step-by-step roadmap
Phase 1: Fundamentals (2-3 months)
- Networking — TCP/IP, DNS, HTTP, subnetting, Wireshark
- Linux — Kali Linux, command line, scripting
- Programming — Python and Bash for scripting, automation
Resources: TryHackMe, HackTheBox, Linux basics
Projects: Network scanner in Python, Bash automation scripts, Kali lab setup
Phase 2: Web Application Security (3-4 months)
- OWASP Top 10 — XSS, SQL injection, CSRF, SSRF, etc.
- Burp Suite — Proxy, scanner, intruder, repeater
- API Security — Authentication flaws, IDOR, rate limiting
Resources: PortSwigger Web Security Academy, OWASP docs, Bug Bounty guides
Projects: Web app pentest, API security assessment, Vulnerability report
Phase 3: Infrastructure Testing (3-4 months)
- Network Pentesting — Nmap, Metasploit, privilege escalation
- Active Directory — AD attacks, Kerberos, lateral movement
- Cloud Security — AWS/Azure security misconfigurations
Resources: Offensive Security, PentesterLab, Cloud security courses
Projects: Network pentest lab, AD attack chain, Cloud security audit
Phase 4: Advanced Topics (2-3 months)
- Exploit Development — Buffer overflows, shellcode, binary exploitation
- Mobile Pentesting — Android/iOS security testing
- Red Teaming — Full adversary simulation, C2 frameworks
Resources: Exploit Development guides, MOBSF, Red Team guides
Projects: Custom exploit, Mobile app assessment, Red team exercise
Phase 5: Certification & Job Prep (2-3 months)
- OSCP/CEH — Industry-recognized certifications
- Bug Bounties — HackerOne, Bugcrowd, responsible disclosure
- Report Writing — Professional pentest reports
Resources: Offensive Security, HackerOne, Report templates
Projects: OSCP exam prep, Bug bounty submissions, Professional reports
Reality check
It's not like the movies — most pentesting is methodical, repetitive testing. Report writing takes as much time as hacking. Legal boundaries are strict. But finding a critical vulnerability is an incredible rush.
What a Penetration Tester actually does day to day
Penetration testers (ethical hackers) simulate real-world attacks to find vulnerabilities before malicious hackers do. You're the authorized attacker every company needs. In practice the week looks less like continuous coding and more like a mix of building, reviewing, debugging and deciding. A typical day includes a short stand-up, two to four hours of focused build time, code review for teammates, and at least one conversation about scope or trade-offs. The people who progress fastest in this role are the ones who treat those conversations as part of the job rather than as an interruption to it.
- Morning: triage anything that broke overnight, then take the highest-leverage task rather than the easiest one.
- Core hours: deep work on the current increment — Networking, Linux and Web Security are the tools you will touch most.
- Reviews: reading other people's changes is the fastest way to learn a codebase and the fastest way to build trust.
- Documentation: a short written note about why a decision was made saves hours for the next person, often you in three months.
- Learning: the field moves; an hour a week on fundamentals beats a weekend binge every quarter.
Is Penetration Tester the right fit for you?
This path suits you if several of the following are true. It is worth being honest here — switching after six months costs far more than choosing carefully now.
- You love the thrill of breaking into systems
- You have a curious, puzzle-solving mindset
- You want to be the 'good guy' hacker
- You enjoy understanding systems deeply
Penetration Tester salary in 2026
Compensation for penetration testers reflects scope more than years served. Outstanding — cybercrime is growing, and every company needs security testing. Massive talent shortage. The bands below are annual gross figures; product companies pay above them, services and agency employers below.
| Level | Experience | India | Global (USD) | What the role owns |
|---|---|---|---|---|
| Entry / junior | 0–2 years | ₹5-15 LPA (entry) | $65K-95K (entry) | Well-scoped tasks with close review |
| Mid-level | 3–5 years | Between the entry and senior bands | Between the entry and senior bands | Owns features end to end, mentors juniors |
| Senior | 6+ years | ₹18-50 LPA (senior) | $120K-200K+ (senior) | Owns systems, sets technical direction |
| Lead / staff | 9+ years | Above the senior band, plus equity at product companies | Above the senior band, plus equity | Leverage through other engineers and architecture |
Three factors move you up these bands faster than time does: specialising in one high-demand area rather than staying general, owning a system end to end so you can describe impact in numbers, and changing employer at the right moment — external moves still outpace internal raises in most markets. Use the salary predictor to check the band for your specific city and experience level.
The complete Penetration Tester skill map
You need 7 core competencies to be credible in interviews for this role. The table maps each one to why employers care and how it gets tested, so you can prioritise instead of trying to learn everything at once.
| Skill | Why it matters | How interviewers test it | Time to proficiency |
|---|---|---|---|
| Networking | What separates a mid-level candidate from a junior one | Take-home review and follow-up questions | 2–3 months |
| Linux | Appears in the majority of job descriptions for this role | Take-home review and follow-up questions | 3–5 months |
| Web Security | What separates a mid-level candidate from a junior one | Take-home review and follow-up questions | 2–3 months |
| Scripting | Foundation that every later topic depends on | Whiteboard or design discussion | 2–3 months |
| Exploit Development | The difference between shipping and shipping something maintainable | Debugging a broken example | 2–4 weeks |
| Social Engineering | Foundation that every later topic depends on | Debugging a broken example | 3–5 months |
| Report Writing | Foundation that every later topic depends on | Take-home review and follow-up questions | 2–4 weeks |
Week-by-week Penetration Tester learning plan
The roadmap phases above tell you what to learn. This plan tells you when, assuming 15–20 hours a week of focused study. Slipping a week is normal; skipping the build column is not — the projects are what make the learning stick and what fills your portfolio.
| Timeline | Phase | What to learn | What to build that week |
|---|---|---|---|
| Weeks 1–2 | Phase 1: Fundamentals | Networking — TCP/IP, DNS, HTTP, subnetting, Wireshark | Network scanner in Python |
| Weeks 3–4 | Phase 1: Fundamentals | Linux — Kali Linux, command line, scripting | Bash automation scripts |
| Weeks 5–6 | Phase 1: Fundamentals | Programming — Python and Bash for scripting, automation | Kali lab setup |
| Weeks 7–8 | Phase 2: Web Application Security | OWASP Top 10 — XSS, SQL injection, CSRF, SSRF, etc. | Web app pentest |
| Weeks 9–10 | Phase 2: Web Application Security | Burp Suite — Proxy, scanner, intruder, repeater | API security assessment |
| Weeks 11–12 | Phase 2: Web Application Security | API Security — Authentication flaws, IDOR, rate limiting | Vulnerability report |
| Weeks 13–14 | Phase 3: Infrastructure Testing | Network Pentesting — Nmap, Metasploit, privilege escalation | Network pentest lab |
| Weeks 15–16 | Phase 3: Infrastructure Testing | Active Directory — AD attacks, Kerberos, lateral movement | AD attack chain |
| Weeks 17–18 | Phase 3: Infrastructure Testing | Cloud Security — AWS/Azure security misconfigurations | Cloud security audit |
| Weeks 19–20 | Phase 4: Advanced Topics | Exploit Development — Buffer overflows, shellcode, binary exploitation | Custom exploit |
| Weeks 21–22 | Phase 4: Advanced Topics | Mobile Pentesting — Android/iOS security testing | Mobile app assessment |
| Weeks 23–24 | Phase 4: Advanced Topics | Red Teaming — Full adversary simulation, C2 frameworks | Red team exercise |
| Weeks 25–26 | Phase 5: Certification & Job Prep | OSCP/CEH — Industry-recognized certifications | OSCP exam prep |
| Weeks 27–28 | Phase 5: Certification & Job Prep | Bug Bounties — HackerOne, Bugcrowd, responsible disclosure | Bug bounty submissions |
| Weeks 29–30 | Phase 5: Certification & Job Prep | Report Writing — Professional pentest reports | Professional reports |
Portfolio projects that get interviews
Recruiters skim portfolios in under a minute, so two strong projects beat six weak ones. Each project below should be deployed, documented with a short README explaining the problem and the trade-offs, and something you can talk through for ten minutes without notes.
- Network scanner in Python
- Bash automation scripts
- Kali lab setup
- Web app pentest
- API security assessment
- Vulnerability report
- Network pentest lab
- AD attack chain
- Cloud security audit
- Custom exploit
Make at least one project unmistakably yours — solve a problem you actually have, use real data, and write up what broke. Interviewers ask far better questions about original work than about a cloned tutorial app, and those questions are the ones you will answer best.
Free resources worth using
- TryHackMe
- HackTheBox
- Linux basics
- PortSwigger Web Security Academy
- OWASP docs
- Bug Bounty guides
- Offensive Security
- PentesterLab
- Cloud security courses
- Exploit Development guides
- MOBSF
- Red Team guides
- HackerOne
- Report templates
Pick one primary resource and one reference. Rotating between five courses feels productive and teaches very little; finishing one and building alongside it teaches a lot. Official documentation should become your default reference within the first two months.
Penetration Tester interview preparation
Interview loops for this role typically run four to six stages. Expect a recruiter screen, a technical screen on fundamentals, a practical exercise or take-home, a deep-dive on your own projects, and a hiring-manager conversation about ownership and collaboration.
| Round | What is tested | Preparation that works |
|---|---|---|
| Screening | Motivation, communication, salary alignment | A 90-second summary of your work and a researched range |
| Technical fundamentals | Networking, Linux and Web Security | Daily reps for four weeks, explained out loud |
| Practical exercise | Code quality, tests, judgement about scope | Timebox it and document what you deliberately left out |
| Project deep-dive | Whether you actually built what your CV claims | Be able to justify every architectural choice you made |
| Hiring manager | Ownership, conflict, how you handle being wrong | Six STAR stories including one genuine failure |
- Exploit Development: compare two approaches within exploit development and justify your default choice.
- Social Engineering: explain how you would debug a problem involving social engineering in production.
- Report Writing: compare two approaches within report writing and justify your default choice.
- Networking: describe how networking fits into the systems you have built.
- Linux: compare two approaches within linux and justify your default choice.
- Web Security: explain how you would debug a problem involving web security in production.
- Scripting: describe how scripting fits into the systems you have built.
Career progression and where this path leads
| Stage | Typical years | Scope | Common next step |
|---|---|---|---|
| Junior | 0–2 | Well-defined tasks, close review | Own a full feature without supervision |
| Mid-level | 3–5 | Features end to end, some mentoring | Own a service or subsystem |
| Senior | 6–9 | Systems, technical direction, cross-team work | Staff engineer or engineering manager |
| Lead / staff / manager | 10+ | Organisational leverage, architecture, hiring | Principal engineer, head of engineering, or founder |
Lateral moves are common and healthy from this role. Penetration Tester experience transfers well into adjacent specialisations, product engineering, and technical leadership. Use compare careers to see how the salary, difficulty and demand of two paths stack up before committing.
Mistakes that slow people down
- Collecting tutorials instead of finishing projects. Completion is the skill being trained.
- Learning adjacent tools before the core ones. Get Networking and Linux solid first.
- Building only what the tutorial shows. The learning happens when something breaks and nobody has written the fix down.
- Waiting until you feel ready to apply. Interview practice is a skill and it is trained by interviewing.
- No public trail. A deployed link and a written case study is worth more than a private repository.
- Ignoring fundamentals because the stack is modern. Complexity, data modelling and debugging are still what interviews test.
Penetration Tester — frequently asked questions
How long does it take to become a penetration tester?
10-16 months to job-ready for someone starting from scratch and studying 15–20 hours a week. People coming from an adjacent technical role usually move faster because they already understand how teams ship software.
Is Penetration Tester a good career in 2026?
Demand is rated very high. Outstanding — cybercrime is growing, and every company needs security testing. Massive talent shortage.
Do I need a degree to become a penetration tester?
No, though it still helps for visa-sponsored roles and large enterprises. What replaces it is evidence: deployed projects, a public code history, and the ability to explain your decisions clearly.
How hard is it really?
Difficulty is hard — roughly 4 out of 10. It's not like the movies — most pentesting is methodical, repetitive testing. Report writing takes as much time as hacking. Legal boundaries are strict. But finding a critical vulnerability is an incredible rush.
What should I learn first?
Start with Fundamentals — specifically Networking, Linux and Programming. Everything later in the roadmap assumes this foundation.
Can I switch to Penetration Tester from a non-technical background?
Yes, and thousands do each year. The realistic timeline is 10-16 months (entry) → 4-6 years (expert), the main risk is quitting in month four, and the strongest mitigation is a public build streak plus one person who expects progress from you weekly.
Will AI replace penetration testers?
AI has changed the work rather than removed it. Code generation raised the floor, and the value moved toward design, debugging, evaluating correctness and understanding systems — the parts current models handle least reliably.