Skip to main content
RoleCybersecurity

Pentester

Scope, recon, exploit, write the report nobody reads. Repeat next engagement.

POST verdict

Far harder to break into than the marketing suggests, and the day-to-day is less glamorous than the highlight reels. Worth it only if the craft genuinely pulls you.

Domain
Cybersecurity
Entry
£32–52k
Senior
£95–135k
Pick this if
  • You've already got writeups, CTF solves or HTB ranks that prove the hands work
  • You'll happily write a 40-page report for every fortnight of testing
  • You can sit with not knowing the answer for days at a time
  • You enjoy reading other people's code more than writing your own
Skip this if
  • Your only credential is a cert and a LinkedIn headline
  • You want offensive work without the consultancy travel or scoping calls
  • You don't like being wrong in writing, in front of clients, every quarter
  • Your reports get used as templates by the rest of the team
  • You find things that aren't on the checklist
  • Clients ask for you by name on the rebook
  • You're shipping tooling or research between engagements, not just consuming both
The bit you're probably underestimating

The pay-to-skill ratio is worse than people think. Senior pentesters in the UK earn less than mid-level cloud engineers, and the ladder above mid is narrow: principal, lead, or out into red team and research. Consultancy life is also harder on home routine than it looks from outside, with travel, late report nights and an endless retest queue. If you're in it for the craft, the salary is fine. If you're in it for the salary, almost every other security path pays better.

Hover any chip for the calibrated meaning. Ratings are directional, not absolute.

Moderate as IC; senior pentest / red team lead requires reputation.

  • +Sysadmin
  • +Developer
  • +Self-taught HTB grinders
  • That OSCP unlocks the role, labs and writeups matter more.
  • Red Team
  • AppSec
  • Detection (purple)

Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

You've read about the role. The harder question is whether it's the right one for you.

A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.