Penetration Tester Roadmap 2026

Hack systems legally to make them more secure

Penetration testers (ethical hackers) simulate real-world attacks to find vulnerabilities before malicious hackers do. You're the authorized attacker every company needs.

Key facts

  • Difficulty: Hard
  • Time to job-ready: 10-16 months to job-ready
  • Demand: Very High
  • Salary (India): ₹5-15 LPA (entry) → ₹18-50 LPA (senior)
  • Salary (Global): $65K-95K (entry) → $120K-200K+ (senior)
  • Growth: Outstanding — cybercrime is growing, and every company needs security testing. Massive talent shortage.

Skills you need

  • Networking
  • Linux
  • Web Security
  • Scripting
  • Exploit Development
  • Social Engineering
  • Report Writing

Step-by-step roadmap

Phase 1: Fundamentals (2-3 months)

  • Networking — TCP/IP, DNS, HTTP, subnetting, Wireshark
  • Linux — Kali Linux, command line, scripting
  • Programming — Python and Bash for scripting, automation

Resources: TryHackMe, HackTheBox, Linux basics

Projects: Network scanner in Python, Bash automation scripts, Kali lab setup

Phase 2: Web Application Security (3-4 months)

  • OWASP Top 10 — XSS, SQL injection, CSRF, SSRF, etc.
  • Burp Suite — Proxy, scanner, intruder, repeater
  • API Security — Authentication flaws, IDOR, rate limiting

Resources: PortSwigger Web Security Academy, OWASP docs, Bug Bounty guides

Projects: Web app pentest, API security assessment, Vulnerability report

Phase 3: Infrastructure Testing (3-4 months)

  • Network Pentesting — Nmap, Metasploit, privilege escalation
  • Active Directory — AD attacks, Kerberos, lateral movement
  • Cloud Security — AWS/Azure security misconfigurations

Resources: Offensive Security, PentesterLab, Cloud security courses

Projects: Network pentest lab, AD attack chain, Cloud security audit

Phase 4: Advanced Topics (2-3 months)

  • Exploit Development — Buffer overflows, shellcode, binary exploitation
  • Mobile Pentesting — Android/iOS security testing
  • Red Teaming — Full adversary simulation, C2 frameworks

Resources: Exploit Development guides, MOBSF, Red Team guides

Projects: Custom exploit, Mobile app assessment, Red team exercise

Phase 5: Certification & Job Prep (2-3 months)

  • OSCP/CEH — Industry-recognized certifications
  • Bug Bounties — HackerOne, Bugcrowd, responsible disclosure
  • Report Writing — Professional pentest reports

Resources: Offensive Security, HackerOne, Report templates

Projects: OSCP exam prep, Bug bounty submissions, Professional reports

Reality check

It's not like the movies — most pentesting is methodical, repetitive testing. Report writing takes as much time as hacking. Legal boundaries are strict. But finding a critical vulnerability is an incredible rush.

What a Penetration Tester actually does day to day

Penetration testers (ethical hackers) simulate real-world attacks to find vulnerabilities before malicious hackers do. You're the authorized attacker every company needs. In practice the week looks less like continuous coding and more like a mix of building, reviewing, debugging and deciding. A typical day includes a short stand-up, two to four hours of focused build time, code review for teammates, and at least one conversation about scope or trade-offs. The people who progress fastest in this role are the ones who treat those conversations as part of the job rather than as an interruption to it.

  • Morning: triage anything that broke overnight, then take the highest-leverage task rather than the easiest one.
  • Core hours: deep work on the current increment — Networking, Linux and Web Security are the tools you will touch most.
  • Reviews: reading other people's changes is the fastest way to learn a codebase and the fastest way to build trust.
  • Documentation: a short written note about why a decision was made saves hours for the next person, often you in three months.
  • Learning: the field moves; an hour a week on fundamentals beats a weekend binge every quarter.

Is Penetration Tester the right fit for you?

This path suits you if several of the following are true. It is worth being honest here — switching after six months costs far more than choosing carefully now.

  • You love the thrill of breaking into systems
  • You have a curious, puzzle-solving mindset
  • You want to be the 'good guy' hacker
  • You enjoy understanding systems deeply

Penetration Tester salary in 2026

Compensation for penetration testers reflects scope more than years served. Outstanding — cybercrime is growing, and every company needs security testing. Massive talent shortage. The bands below are annual gross figures; product companies pay above them, services and agency employers below.

Penetration Tester salary bands, 2026
LevelExperienceIndiaGlobal (USD)What the role owns
Entry / junior0–2 years₹5-15 LPA (entry)$65K-95K (entry)Well-scoped tasks with close review
Mid-level3–5 yearsBetween the entry and senior bandsBetween the entry and senior bandsOwns features end to end, mentors juniors
Senior6+ years₹18-50 LPA (senior)$120K-200K+ (senior)Owns systems, sets technical direction
Lead / staff9+ yearsAbove the senior band, plus equity at product companiesAbove the senior band, plus equityLeverage through other engineers and architecture

Three factors move you up these bands faster than time does: specialising in one high-demand area rather than staying general, owning a system end to end so you can describe impact in numbers, and changing employer at the right moment — external moves still outpace internal raises in most markets. Use the salary predictor to check the band for your specific city and experience level.

The complete Penetration Tester skill map

You need 7 core competencies to be credible in interviews for this role. The table maps each one to why employers care and how it gets tested, so you can prioritise instead of trying to learn everything at once.

Core Penetration Tester skills and how they are assessed
SkillWhy it mattersHow interviewers test itTime to proficiency
NetworkingWhat separates a mid-level candidate from a junior oneTake-home review and follow-up questions2–3 months
LinuxAppears in the majority of job descriptions for this roleTake-home review and follow-up questions3–5 months
Web SecurityWhat separates a mid-level candidate from a junior oneTake-home review and follow-up questions2–3 months
ScriptingFoundation that every later topic depends onWhiteboard or design discussion2–3 months
Exploit DevelopmentThe difference between shipping and shipping something maintainableDebugging a broken example2–4 weeks
Social EngineeringFoundation that every later topic depends onDebugging a broken example3–5 months
Report WritingFoundation that every later topic depends onTake-home review and follow-up questions2–4 weeks

Week-by-week Penetration Tester learning plan

The roadmap phases above tell you what to learn. This plan tells you when, assuming 15–20 hours a week of focused study. Slipping a week is normal; skipping the build column is not — the projects are what make the learning stick and what fills your portfolio.

Week-by-week Penetration Tester study plan (15–20 hours a week)
TimelinePhaseWhat to learnWhat to build that week
Weeks 1–2Phase 1: FundamentalsNetworking — TCP/IP, DNS, HTTP, subnetting, WiresharkNetwork scanner in Python
Weeks 3–4Phase 1: FundamentalsLinux — Kali Linux, command line, scriptingBash automation scripts
Weeks 5–6Phase 1: FundamentalsProgramming — Python and Bash for scripting, automationKali lab setup
Weeks 7–8Phase 2: Web Application SecurityOWASP Top 10 — XSS, SQL injection, CSRF, SSRF, etc.Web app pentest
Weeks 9–10Phase 2: Web Application SecurityBurp Suite — Proxy, scanner, intruder, repeaterAPI security assessment
Weeks 11–12Phase 2: Web Application SecurityAPI Security — Authentication flaws, IDOR, rate limitingVulnerability report
Weeks 13–14Phase 3: Infrastructure TestingNetwork Pentesting — Nmap, Metasploit, privilege escalationNetwork pentest lab
Weeks 15–16Phase 3: Infrastructure TestingActive Directory — AD attacks, Kerberos, lateral movementAD attack chain
Weeks 17–18Phase 3: Infrastructure TestingCloud Security — AWS/Azure security misconfigurationsCloud security audit
Weeks 19–20Phase 4: Advanced TopicsExploit Development — Buffer overflows, shellcode, binary exploitationCustom exploit
Weeks 21–22Phase 4: Advanced TopicsMobile Pentesting — Android/iOS security testingMobile app assessment
Weeks 23–24Phase 4: Advanced TopicsRed Teaming — Full adversary simulation, C2 frameworksRed team exercise
Weeks 25–26Phase 5: Certification & Job PrepOSCP/CEH — Industry-recognized certificationsOSCP exam prep
Weeks 27–28Phase 5: Certification & Job PrepBug Bounties — HackerOne, Bugcrowd, responsible disclosureBug bounty submissions
Weeks 29–30Phase 5: Certification & Job PrepReport Writing — Professional pentest reportsProfessional reports

Portfolio projects that get interviews

Recruiters skim portfolios in under a minute, so two strong projects beat six weak ones. Each project below should be deployed, documented with a short README explaining the problem and the trade-offs, and something you can talk through for ten minutes without notes.

  1. Network scanner in Python
  2. Bash automation scripts
  3. Kali lab setup
  4. Web app pentest
  5. API security assessment
  6. Vulnerability report
  7. Network pentest lab
  8. AD attack chain
  9. Cloud security audit
  10. Custom exploit

Make at least one project unmistakably yours — solve a problem you actually have, use real data, and write up what broke. Interviewers ask far better questions about original work than about a cloned tutorial app, and those questions are the ones you will answer best.

Free resources worth using

  • TryHackMe
  • HackTheBox
  • Linux basics
  • PortSwigger Web Security Academy
  • OWASP docs
  • Bug Bounty guides
  • Offensive Security
  • PentesterLab
  • Cloud security courses
  • Exploit Development guides
  • MOBSF
  • Red Team guides
  • HackerOne
  • Report templates

Pick one primary resource and one reference. Rotating between five courses feels productive and teaches very little; finishing one and building alongside it teaches a lot. Official documentation should become your default reference within the first two months.

Penetration Tester interview preparation

Interview loops for this role typically run four to six stages. Expect a recruiter screen, a technical screen on fundamentals, a practical exercise or take-home, a deep-dive on your own projects, and a hiring-manager conversation about ownership and collaboration.

RoundWhat is testedPreparation that works
ScreeningMotivation, communication, salary alignmentA 90-second summary of your work and a researched range
Technical fundamentalsNetworking, Linux and Web SecurityDaily reps for four weeks, explained out loud
Practical exerciseCode quality, tests, judgement about scopeTimebox it and document what you deliberately left out
Project deep-diveWhether you actually built what your CV claimsBe able to justify every architectural choice you made
Hiring managerOwnership, conflict, how you handle being wrongSix STAR stories including one genuine failure
  • Exploit Development: compare two approaches within exploit development and justify your default choice.
  • Social Engineering: explain how you would debug a problem involving social engineering in production.
  • Report Writing: compare two approaches within report writing and justify your default choice.
  • Networking: describe how networking fits into the systems you have built.
  • Linux: compare two approaches within linux and justify your default choice.
  • Web Security: explain how you would debug a problem involving web security in production.
  • Scripting: describe how scripting fits into the systems you have built.

Career progression and where this path leads

StageTypical yearsScopeCommon next step
Junior0–2Well-defined tasks, close reviewOwn a full feature without supervision
Mid-level3–5Features end to end, some mentoringOwn a service or subsystem
Senior6–9Systems, technical direction, cross-team workStaff engineer or engineering manager
Lead / staff / manager10+Organisational leverage, architecture, hiringPrincipal engineer, head of engineering, or founder

Lateral moves are common and healthy from this role. Penetration Tester experience transfers well into adjacent specialisations, product engineering, and technical leadership. Use compare careers to see how the salary, difficulty and demand of two paths stack up before committing.

Mistakes that slow people down

  1. Collecting tutorials instead of finishing projects. Completion is the skill being trained.
  2. Learning adjacent tools before the core ones. Get Networking and Linux solid first.
  3. Building only what the tutorial shows. The learning happens when something breaks and nobody has written the fix down.
  4. Waiting until you feel ready to apply. Interview practice is a skill and it is trained by interviewing.
  5. No public trail. A deployed link and a written case study is worth more than a private repository.
  6. Ignoring fundamentals because the stack is modern. Complexity, data modelling and debugging are still what interviews test.

Penetration Tester — frequently asked questions

How long does it take to become a penetration tester?

10-16 months to job-ready for someone starting from scratch and studying 15–20 hours a week. People coming from an adjacent technical role usually move faster because they already understand how teams ship software.

Is Penetration Tester a good career in 2026?

Demand is rated very high. Outstanding — cybercrime is growing, and every company needs security testing. Massive talent shortage.

Do I need a degree to become a penetration tester?

No, though it still helps for visa-sponsored roles and large enterprises. What replaces it is evidence: deployed projects, a public code history, and the ability to explain your decisions clearly.

How hard is it really?

Difficulty is hard — roughly 4 out of 10. It's not like the movies — most pentesting is methodical, repetitive testing. Report writing takes as much time as hacking. Legal boundaries are strict. But finding a critical vulnerability is an incredible rush.

What should I learn first?

Start with Fundamentals — specifically Networking, Linux and Programming. Everything later in the roadmap assumes this foundation.

Can I switch to Penetration Tester from a non-technical background?

Yes, and thousands do each year. The realistic timeline is 10-16 months (entry) → 4-6 years (expert), the main risk is quitting in month four, and the strongest mitigation is a public build streak plus one person who expects progress from you weekly.

Will AI replace penetration testers?

AI has changed the work rather than removed it. Code generation raised the floor, and the value moved toward design, debugging, evaluating correctness and understanding systems — the parts current models handle least reliably.

All roadmaps · Is this career right for me? · Compare with other careers