Offensive Security (Pentest / Red Team)
Hands-on offensive work. High ceiling, high effort, slow start. OSCP/PNPT biased. CISSP is NOT the path.
High ceiling, slow start, and almost nobody's first job. Treat it as a mid-career pivot from defensive or dev work, not an entry route.
You already break things for fun, you've got a HackTheBox or TryHackMe track record, and you can describe a real engagement in your own words. OSCP and the work it takes to pass it filters reasonably well.
You're brand new to IT. The pentest market doesn't hire juniors at the rate the YouTube ecosystem implies, and you'll burn 18 months on certs before you get a callback.
Phased progression
Foundations → first role → specialisation → advanced. The realistic order, not a script.
- 010–6 monthsFoundations
Literacy, lab habits, the cert that opens first conversations.
eJPT - 026–18 monthsFirst paid role
Land a Junior Pentester or AppSec Engineer. Operational time, not more certs, earns the next move.
Junior Pentester or AppSec Engineer£35–50k junior pentest - 031.5–3 yearsSpecialisation
Add a specialist credential aligned to the work you're already doing.
PNPTCRTO£55–80k mid - 043+ yearsAdvanced
Move into adjacent roles. Long-term credentials become worth their cost.
Red TeamerOSEP£85–110k senior at banks/in-house (UK)
- 01Foundations0–6 months
Literacy, lab habits, the cert that opens first conversations.
eJPT - 02First paid role6–18 months
Land a Junior Pentester or AppSec Engineer. Operational time, not more certs, earns the next move.
Junior Pentester or AppSec Engineer£35–50k junior pentest - 03Specialisation1.5–3 years
Add a specialist credential aligned to the work you're already doing.
PNPTCRTO£55–80k mid - 04Advanced3+ years
Move into adjacent roles. Long-term credentials become worth their cost.
Red TeamerOSEP£85–110k senior at banks/in-house (UK)
Certification sequence
Ordered by realistic relevance, not vendor marketing.
Practical projects
What to actually build, the portfolio that opens interviews.
- TryHackMe + HackTheBox streaks with public write-ups
- Internal CTF write-ups on a personal blog
- Custom Burp extension or a small C2 plugin
- ·SOC-first then pivot offensive
- ·AppSec via developer background
Realistic expectations
What no recruiter will tell you.
That OSCP is the finish line. It's the qualifying lap. Most juniors with OSCP and no real-world reports still don't get hired, because consultancies want people who can write up a finding without hand-holding.
Eighteen to thirty months from a standing start to a paid offensive role is the realistic window. People who already work in AppSec or sysadmin compress that. Pure career-changers rarely do.
The next step
The pathway is plausible. Whether it holds for five years is a different question.
A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.
A route shows what people usually do. A Career Verdict judges whether it's realistic for you.
A Career Verdict includes
Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.