Penetration Tester Resume Examples & Writing Guide
A penetration tester resume is read for three things: what you have actually tested (web, internal network, cloud, mobile, wireless, social engineering), the certifications that prove hands-on skill, and whether you can write a report a client will pay for. Numbers of engagements and critical findings beat any list of tools.
Penetration tester resume example (consultant, 5 years)
This sample is a consultant at a security testing firm who runs web application and internal network engagements. Names and companies are invented. Internal red teamers and application security engineers should keep the structure and change the engagement types; there is a section for people breaking in below.
Devin Oyelaran
Senior Penetration Tester
Denver, CO (remote) · (303) 555-0181 · devin.oyelaran@email.com · github.com/doyelaran · OSCP · GWAPT
Summary
Penetration tester with 5 years and about 130 engagements across web applications, internal and external networks, cloud and Active Directory. Leads 2 to 3 person teams on assessments for financial services and healthcare clients, and writes the report that goes to the board. OSCP and GWAPT certified. Two published CVEs in commercial software.
Experience
Senior Penetration Tester · Security consultancy, 60 staff, financial services and healthcare clients
May 2023 – Present
- Lead 40 to 50 engagements a year: web and API testing, internal and external network penetration tests, Active Directory assessments and cloud configuration reviews in AWS and Azure.
- Achieved domain administrator on 22 of 31 internal engagements in the last two years, most often through Active Directory certificate services misconfiguration, Kerberoasting or coerced authentication with relaying.
- Found and reported 34 critical and 96 high severity issues, including an authentication bypass in a client's customer portal that exposed roughly 400,000 account records.
- Write the full report on every engagement: executive summary, risk-rated findings with reproduction steps, screenshots and remediation guidance, delivered within 5 business days of test close on 96% of jobs.
- Run the retest cycle and the findings walkthrough call with client engineering teams, averaging 78% of critical findings closed within 30 days.
- Built the team's internal testing methodology on the OWASP Web Security Testing Guide and PTES, plus a reporting template that cut average report writing time by about 4 hours per engagement.
- Published 2 CVEs in commercial network appliances through coordinated disclosure, and mentor 2 junior testers through their first solo engagements.
Penetration Tester · Managed security provider, mid-market clients
Aug 2021 – Apr 2023
- Delivered 60+ engagements over 20 months, mostly external network, web application and PCI DSS scoped tests for retail and payments clients.
- Performed phishing and pretexting campaigns against 4,000+ users, with credential capture rates from 4% to 19% and a debrief that fed the client's awareness program.
- Reduced false positives in the team's external scanning workflow by writing 30 custom Nuclei templates for client-specific technology.
- Wrote and presented findings to non-technical stakeholders on 25 engagements, including three board-level presentations.
Security Analyst, SOC Tier 2 · Managed security provider
Jun 2019 – Jul 2021
- Investigated 40 to 60 alerts a shift across EDR, firewall and email gateway sources, escalating confirmed incidents with a timeline and indicators.
- Built 22 detection rules that closed gaps found in purple team exercises, mapped to MITRE ATT&CK techniques.
- Moved to the offensive team after passing OSCP and completing 8 internal red team shadow engagements.
Education
Bachelor of Science, Information Technology
Front Range State University, 2019
Certifications
- OSCP (Offensive Security Certified Professional), 2021
- GWAPT (GIAC Web Application Penetration Tester), 2023
- Burp Suite Certified Practitioner, PortSwigger, 2022
- CompTIA Security+, 2019
- 2 published CVEs through coordinated disclosure
Skills
What a practice lead reads for
The hiring manager is usually a practice lead or principal consultant who has done the job. They can tell from four lines whether you have tested anything real.
- Engagement types and count. Web, API, mobile, internal, external, cloud, wireless, social engineering, red team, physical. Give the mix and the number a year. "Performed penetration testing" tells a practice lead nothing.
- Depth signals. Attack paths you achieved, privilege escalation techniques, chained findings, custom exploits or scripts written. This is what distinguishes testing from running a scanner and formatting the output.
- Certifications, and specifically the hands-on ones. OSCP is the standard entry signal because it is a 24-hour practical exam. GIAC's GPEN and GWAPT, the PortSwigger Burp Suite Certified Practitioner, PNPT, CRTO and the Offensive Security follow-ons all carry weight. CEH is recognized but does not prove hands-on skill on its own.
- Report writing and client communication. This is half the job and the most common reason a technically strong candidate is turned down. Say how many reports you write, your turnaround, and whether you present to executives.
- Scoping and legal awareness. Rules of engagement, authorization letters, testing windows, out-of-scope handling and what you do when you find something you were not authorized to touch. Consultancies ask about this in every interview.
“Show me an attack path, not a tool list. And tell me who reads your reports. This firm has hired brilliant testers who could not write a finding a client could act on, and that costs more than a missed vulnerability.”
Penetration tester resume summary examples
Penetration tester with 5 years and about 130 engagements across web, internal network, Active Directory and cloud. Leads small teams on financial services and healthcare assessments and writes the board-level report. OSCP and GWAPT certified, 2 published CVEs.
Application security tester with 6 years focused on web and API assessment for SaaS products. Tests authentication, authorization and business logic beyond the OWASP Top 10, writes Burp extensions for client-specific flows, and has reported 40 critical findings including 3 authentication bypasses. Burp Suite Certified Practitioner.
Red team operator with 4 years running full-scope adversary simulation: initial access through phishing and exposed services, lateral movement, persistence and exfiltration, mapped to MITRE ATT&CK. Builds custom loaders and evades EDR in a lab before every engagement. CRTO and OSEP certified.
Security engineer with 7 years, the last 3 running the internal offensive testing program for a 9,000-person company. Tests 30 applications a year before release, runs quarterly internal network assessments, and works with development teams on remediation rather than handing over a PDF. OSCP certified.
Security analyst with 2 years in a SOC and an OSCP earned in 2025. Completed 120 Hack The Box and 40 TryHackMe machines, wrote 15 public writeups, holds 3 accepted bug bounty submissions and built a home Active Directory lab with 6 hosts. Seeking a junior penetration testing role.
Start with an example, finish in minutes.
No sign-up to start. Download works. One-time $12 for a clean PDF, no subscription.
Bullets for a penetration testing resume
Show the technique, the scale and the consequence. Vague findings language is the fastest way to look like someone who ran a scan.
| Weak | Strong |
|---|---|
| Performed penetration tests on client systems. | Led 40 to 50 engagements a year across web, API, internal and external network, Active Directory and cloud for financial services and healthcare clients. |
| Identified vulnerabilities in web applications. | Found an authentication bypass in a customer portal that exposed roughly 400,000 account records, chained from a session fixation flaw and a missing authorization check. |
| Used tools such as Nmap and Burp Suite. | Wrote 30 custom Nuclei templates and 4 Burp extensions for client-specific technology, cutting false positives on the external scanning workflow by about half. |
| Tested internal networks. | Reached domain administrator on 22 of 31 internal engagements, most often through Active Directory certificate services misconfiguration, Kerberoasting or coerced authentication with relaying. |
| Wrote reports for clients. | Wrote the full report on every engagement with risk-rated findings, reproduction steps and remediation guidance, delivered within 5 business days of test close on 96% of jobs. |
| Conducted phishing campaigns. | Ran phishing and pretexting campaigns against 4,000+ users with credential capture rates from 4% to 19%, and delivered the debrief that shaped the client's awareness program. |
| Helped clients fix issues. | Ran remediation walkthrough calls with client engineering teams and retests, closing 78% of critical findings within 30 days. |
| Contributed to the security community. | Published 2 CVEs in commercial network appliances through coordinated disclosure and released a tool for parsing certificate templates, now used internally by the team. |
| Mentored junior staff. | Mentored 2 junior testers through their first solo engagements, reviewing every finding and report before delivery. |
Certifications that matter, and how to order them
This field weighs practical, exam-in-a-lab certifications far above multiple-choice ones. List the hands-on ones first and put the year on each.
- OSCP from OffSec. A 24-hour practical exam plus a report, and still the most common baseline requirement in job postings. The follow-ons (OSEP for evasion, OSWE for web exploitation, OSED for exploit development) each signal a specialty.
- GIAC certifications: GPEN for network penetration testing, GWAPT for web applications, GXPN for advanced exploitation, GCPN for cloud. Expensive, respected, and common in government and large enterprise environments.
- Burp Suite Certified Practitioner from PortSwigger. Practical, inexpensive and taken seriously for web testing roles.
- CRTO from Zero-Point Security for red team operations, and PNPT from TCM Security, which includes a report and a debrief call and is well regarded for entry level.
- CEH from EC-Council. Widely recognized by HR filters and required for some government contracts, but on its own it does not tell a practice lead you can test. Pair it with something practical.
- CISSP is a management-leaning certification. It helps for senior and consulting roles and for contract requirements, not for proving hands-on ability.
- In the UK, CREST certifications and CHECK status are the equivalent gatekeepers, and many British postings require them specifically.
- Bug bounty results, CVEs, conference talks and public tools count as credentials here. Put them in their own short block with links.
Penetration tester resume for a fresher or career changer
Junior penetration testing roles are competitive because a lot of people want them and few companies want to train. The resume has to prove you can already do the work without a job title saying so.
- 1Get one practical certification. OSCP is the strongest signal; PNPT and the Burp Suite Certified Practitioner are cheaper and still count. A certificate of completion from a course is not the same thing and practice leads know the difference.
- 2Build a lab and describe it as infrastructure: a domain controller, two workstations, a Linux server, a vulnerable web app, an EDR trial. Say what you attacked and what you learned about detection.
- 3Show practice platform volume with a link: Hack The Box, TryHackMe, PortSwigger Web Security Academy, proving grounds. Machine counts and rank are legitimate evidence at this level.
- 4Write. Public writeups are the closest thing to a work sample for a job whose main deliverable is a written report. Five good writeups beat fifty half-finished boxes.
- 5Try bug bounty, and report honestly. "3 accepted submissions, 1 duplicate, $450 total" is credible; "bug bounty hunter" with nothing behind it is not.
- 6Use adjacent experience properly. Help desk, sysadmin, network engineering, development and SOC work are all real advantages, because testers who understand how systems are actually built find more. Rewrite those jobs around what you learned about attack surface.
- 7Apply to consultancies as well as product companies. Consultancies hire and train juniors far more often, and the volume of engagements will teach you faster.
Built a 6-host Active Directory lab with a domain controller, two workstations and a Linux web server, then practiced Kerberoasting, certificate template abuse and NTLM relay while watching detections fire in a free EDR trial.
Completed 120 Hack The Box machines and the full PortSwigger Web Security Academy, and published 15 writeups covering web exploitation and privilege escalation.
3 accepted bug bounty submissions across two public programs, including a stored cross-site scripting issue in an authenticated admin panel, with $450 in total payouts.
Administered 200 Windows endpoints and a small Active Directory domain, which is where the group policy and service account weaknesses now tested for became familiar.
Format, GitHub and applying
- One page under 10 years, two after. Practice leads read quickly and value density over design.
- Order: header with certifications and GitHub link, summary, experience, skills grouped, certifications and community work, education. Freshers move labs, platforms and writeups above experience.
- Plain, single column, selectable text. Cyber resumes with heavy design get mangled by applicant tracking systems, and many security teams still hire through corporate HR portals.
- Group the skills: engagement types, then tools, then languages, then frameworks. Do not list 60 tools; list the ones you would be comfortable being asked about in an interview.
- Link a GitHub or a blog as plain text, and make sure what is there is finished. An empty profile is worse than none.
- Never include client names, real findings, screenshots or anything under a non-disclosure agreement. Describe sectors and sizes instead.
- Mention clearance if you hold one, since a lot of US testing work is government adjacent, and say whether you can travel and how often. Consulting roles often expect 20 to 40 percent travel.
- Mirror the posting's words when true: penetration testing, red team, web application, API, Active Directory, cloud, OWASP, MITRE ATT&CK, PCI DSS, report writing, remediation.
- PDF named Firstname-Lastname-Penetration-Tester-Resume.pdf. Outside the US the same document is a CV, and UK postings will often ask for CREST or CHECK status rather than OSCP.
Frequently asked questions
How do I write a penetration tester resume?
Lead with engagement types and counts, then attack paths you achieved rather than tools you opened. Put OSCP or your practical certifications in the header, add report turnaround and client communication, and group your skills. Never name clients or include real findings. One page under ten years.
What skills should a penetration tester list on a resume?
Engagement types first (web, API, internal and external network, Active Directory, cloud, mobile, wireless, social engineering), then tools you can defend in an interview, then Python or PowerShell for tooling, then frameworks: OWASP WSTG, MITRE ATT&CK, PTES, NIST SP 800-115 and any compliance context such as PCI DSS.
Do I need OSCP to get a penetration testing job?
Not always, but it is the most commonly requested certification and the clearest signal for a first role because the exam is a 24-hour practical test. PNPT and the Burp Suite Certified Practitioner are cheaper alternatives that still show hands-on ability. CEH passes HR filters but does not prove testing skill on its own.
How do I write a penetration tester resume as a fresher?
Prove the work without the job title: one practical certification, a described home lab, machine counts and writeups from Hack The Box or the Web Security Academy, honest bug bounty results, and any help desk, sysadmin or development work rewritten around attack surface. Apply to consultancies, which hire juniors most often.
Can I put client engagements on my resume?
Only in anonymized form. Describe the sector and size, such as a regional bank with 40 branches or a healthcare SaaS with 400,000 users, and never include client names, real findings, screenshots or anything covered by a non-disclosure agreement. Interviewers treat a breach of this as a judgment failure.
What is the difference between a penetration tester and a red teamer on a resume?
A penetration test finds as many issues as possible within a defined scope and time box; a red team engagement simulates a specific adversary against the whole organization including detection and response. If you have done red team work, say so explicitly and mention evasion, persistence and how the blue team responded.
Should I list bug bounties and CVEs on a penetration testing resume?
Yes, in their own short block with links, and report them honestly. Published CVEs, accepted submissions with payouts, conference talks and public tools all function as credentials in this field. Vague claims of bug bounty hunting with nothing behind them work against you.
Ready to write yours?
The builder suggests a summary from your own experience, then checks it against the job posting.
How this page was made: a first draft was written with AI assistance from cvplex's example library, then edited and fact-checked by the cvplex Careers Team. Examples are fictional composites; numbers are illustrative. Report an error via the editorial policy page.