Skip to main content
Offensive security

Offensive Security (Pentest / Red Team)

Hands-on offensive work. High ceiling, high effort, slow start. OSCP/PNPT biased. CISSP is NOT the path.

Last reviewed May 2026Reviewed by a practitioner working in junior pentester or appsec engineer hiringUpdated quarterly against live job listings
The verdict

High ceiling, slow start, and almost nobody's first job. Treat it as a mid-career pivot from defensive or dev work, not an entry route.

You already break things for fun, you've got a HackTheBox or TryHackMe track record, and you can describe a real engagement in your own words. OSCP and the work it takes to pass it filters reasonably well.

You're brand new to IT. The pentest market doesn't hire juniors at the rate the YouTube ecosystem implies, and you'll burn 18 months on certs before you get a callback.

Phased progression

Foundations → first role → specialisation → advanced. The realistic order, not a script.

Salary figures are POST practitioner estimates, not survey data.

  1. 01Foundations
    0–6 months

    Literacy, lab habits, the cert that opens first conversations.

    eJPT
  2. 02First paid role
    6–18 months

    Land a Junior Pentester or AppSec Engineer. Operational time, not more certs, earns the next move.

    Junior Pentester or AppSec Engineer
    £35–50k junior pentest
  3. 03Specialisation
    1.5–3 years

    Add a specialist credential aligned to the work you're already doing.

    PNPTCRTO
    £55–80k mid
  4. 04Advanced
    3+ years

    Move into adjacent roles. Long-term credentials become worth their cost.

    Red TeamerOSEP
    £85–110k senior at banks/in-house (UK)

Certification sequence

Ordered by realistic relevance, not vendor marketing.

  • CRTO
  • Burp Suite Certified Practitioner

Practical projects

What to actually build, the portfolio that opens interviews.

  • TryHackMe + HackTheBox streaks with public write-ups
  • Internal CTF write-ups on a personal blog
  • Custom Burp extension or a small C2 plugin
Red TeamerAppSec EngineerAdversary Simulation
  • ·SOC-first then pivot offensive
  • ·AppSec via developer background

Realistic expectations

What no recruiter will tell you.

Misconception

That OSCP is the finish line. It's the qualifying lap. Most juniors with OSCP and no real-world reports still don't get hired, because consultancies want people who can write up a finding without hand-holding.

Honest window

Eighteen to thirty months from a standing start to a paid offensive role is the realistic window. People who already work in AppSec or sysadmin compress that. Pure career-changers rarely do.

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

The pathway is plausible. Whether it holds for five years is a different question.

A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.