Penetration Tester Roadmap: Zero to Job-Ready in 2026
9 min read · 2026-10-08
No single certification or degree makes you a penetration tester. The job is a stack of skills: networking and operating system fundamentals, fluency in Linux and a scripting language, the ability to find and exploit flaws in web apps, systems, and Active Directory, and the discipline to write a report a client can act on. Build the stack in order and you become hireable.
This roadmap covers six phases over roughly nine to twelve months, from subnetting to your first paid engagement. Each phase lists what to study, what to build, and a milestone you can verify. It also covers practice labs, which certifications actually carry weight, how to measure progress, and how to get past the resume screen with no professional security experience.
The roadmap at a glance
Goal: Go from zero technical background to a job-ready penetration tester with verified lab reps, a hands-on certification, and a public portfolio. Duration: 9 to 12 months
Networking and OS Basics (Weeks 1-6)
Understand how packets move and how operating systems are configured, so later exploitation makes sense instead of being memorized.
- Learn the TCP/IP model, subnetting, DNS, HTTP, and common ports cold.
- Practice subnetting by hand until you can size a network in your head.
- Install a hypervisor and build isolated Windows and Linux virtual machines.
- Study Windows internals: users, groups, services, registry, and event logs.
- Map the OSI model to real tools like Wireshark, tcpdump, and Nmap.
- Work through one structured networking course instead of random videos.
Milestone: You can explain what happens between typing a URL and a page loading, and you can build a two-VM isolated lab from scratch.
Linux, Scripting, and Tooling (Weeks 7-12)
Become dangerous on the command line and automate the repetitive parts of reconnaissance and enumeration.
- Live in Linux daily: permissions, processes, systemd, package management, and bash.
- Learn Python well enough to write a scanner and parse its output.
- Master Nmap, Netcat, curl, and Wireshark as everyday tools, not novelties.
- Build a home lab with Kali plus intentionally vulnerable machines such as Metasploitable.
- Practice file transfer, bind shells, and reverse shells inside your own lab.
- Learn Git and keep your scripts and notes in a public repository.
Milestone: You have a public repo with two working scripts, and you can navigate any Linux box without a graphical interface.
Web Application Attacks (Months 4-5)
Learn how web applications break and how to find those flaws manually before reaching for automation.
- Work through the OWASP Top 10 and the OWASP Web Security Testing Guide systematically.
- Complete PortSwigger Web Security Academy labs on SQL injection, XSS, SSRF, and access control.
- Learn Burp Suite until interception, repeater, and intruder feel automatic.
- Exploit each vulnerability by hand first, then compare your result with sqlmap.
- Stand up a deliberately vulnerable app and document how you would break it.
- Read disclosed bug bounty reports to see how researchers chain small bugs.
Milestone: You can find and exploit SQL injection, XSS, IDOR, and SSRF in a lab app without a tool doing the thinking for you.
Systems and Active Directory (Months 6-7)
Move from single-host exploits to enterprise networks and the attack paths that matter on real internal engagements.
- Learn Windows privilege escalation: service misconfigurations, tokens, and weak permissions.
- Learn Linux privilege escalation: SUID binaries, cron jobs, capabilities, and sudo rules.
- Build an Active Directory lab with a domain controller and two member machines.
- Practice Kerberoasting, AS-REP roasting, and lateral movement with Impacket and BloodHound.
- Study MITRE ATT&CK and PTES so your work follows a repeatable methodology.
- Add a command-and-control framework such as Sliver to your lab workflow.
Milestone: You can go from one low-privilege foothold to domain admin in your own AD lab and explain every step out loud.
Reporting and Certification (Months 8-9)
Prove your skills with a hands-on certification and produce a report that reads like professional client work.
- Write a full report for one lab machine: findings, evidence, impact, and remediation.
- Practice on Hack The Box, Proving Grounds, or TryHackMe on a fixed schedule.
- Commit to one hands-on exam path: OSCP, OSCP+, PNPT, eJPT, or HTB CPTS.
- Study the exam format so exam day is spent hacking, not learning the interface.
- Rewrite your report after peer feedback until the executive summary stands alone.
Milestone: A pass on a hands-on certification plus two polished sample reports in your portfolio.
Job Hunt and Portfolio (Months 10-12)
Turn lab work into interviews and convert your first offer.
- Publish a portfolio site with lab writeups, scripts, and redacted sample reports.
- Build a one-page resume that leads with labs, certifications, and a GitHub link.
- Apply to SOC, IT support, and junior pentest roles as legitimate entry points.
- Practice walking through a finding out loud like a client debrief.
- Network on LinkedIn and at local security meetups and conferences.
- Run mock interviews for both the technical screen and the report walkthrough.
Milestone: Interviews scheduled and at least one offer for a junior penetration testing, red team, or security role.
Choosing a Specialization Without Locking Yourself In
Most entry-level penetration testing jobs are generalist, so your first year should be broad. Web application testing has the most openings and the clearest practice path through PortSwigger Academy and bug bounty programs. Internal network and Active Directory testing dominates corporate engagements and rewards deep Windows knowledge. Cloud security testing is growing and usually expects you to already understand AWS or Azure identity and networking. Red teaming, which focuses on stealth and detection evasion, is normally a later move.
Pick based on what you can practice today, not on salary rumors. If you have a web development background, lean web. If you come from IT support or systems administration, lean network and Active Directory — your Windows instincts are an advantage most beginners lack. Whatever you choose, keep the fundamentals sharp, because interviewers probe networking and Linux regardless of specialty.
- Web application: OWASP Top 10, Burp Suite, PortSwigger Academy, bug bounty programs.
- Network and Active Directory: Nmap, Impacket, BloodHound, Responder, internal labs.
- Cloud: IAM misconfigurations, metadata services, CloudGoat-style scenarios.
- Red team: command-and-control frameworks, evasion, MITRE ATT&CK; usually requires prior experience.
Where to Practice: Labs and Ranges
Reading about exploitation does nothing on its own. You need repetitions against machines you are allowed to break. TryHackMe is the friendliest on-ramp and has structured learning paths. Hack The Box and OffSec Proving Grounds offer harder, more realistic boxes. PortSwigger Web Security Academy is free and remains the best web-specific lab environment. For Active Directory, build your own domain with Windows Server evaluation images rather than relying only on pre-made boxes.
A local lab is still worth the disk space. A hypervisor, Kali, and a handful of vulnerable VMs let you practice shells, privilege escalation, and snapshot rollbacks without waiting on someone else's infrastructure. Keep every session in a note-taking tool, and turn your best sessions into public writeups. The writeups are what hiring managers actually read.
- TryHackMe for guided paths and beginner-friendly boxes.
- Hack The Box and Proving Grounds for exam-style, unguided practice.
- PortSwigger Academy for web vulnerabilities with in-browser labs.
- Self-built Active Directory domain for Kerberos and lateral movement.
- flaws.cloud and CloudGoat for cloud misconfiguration practice.
Certifications: Order and Signal
If you have no technical background, start with vendor-neutral fundamentals: CompTIA Network+ and Security+ give you vocabulary and get past some automated filters. Then move to something hands-on. eJPT and PNPT are common starting points, while OSCP, OSCP+, and HTB CPTS carry more weight because the exams are practical and timed. For web specialists, the Burp Suite Certified Practitioner exam is a credible signal that you can find real bugs.
Hands-on exams matter more than multiple choice. A hiring manager reads OSCP, PNPT, or CPTS as evidence you can operate under pressure with incomplete information. The trap is collecting credentials instead of skills; every multiple-choice exam you skip frees weeks for lab time that actually changes what you can do.
- Fundamentals first: Network+ and Security+ for vocabulary and filters.
- Entry hands-on: eJPT, PNPT, or HTB CPTS.
- Stronger signal: OSCP or OSCP+ for generalist pentest roles.
- Specialist: Burp Suite Certified Practitioner for web, CRTP for Active Directory.
How to Measure Progress Without a Job Title
Job titles lag behind skill, so track verifiable outputs instead. Count machines you finished without a walkthrough, vulnerabilities you found manually, and reports you wrote. Track how long enumeration takes you on a typical box and whether you are getting faster at ruling things out, which is most of the job.
Two habits accelerate everything: teach and get reviewed. Explain a technique in a blog post or to a study partner; if you cannot explain it simply, you do not own it yet. Then ask someone more experienced to critique a report or a writeup. Feedback on your documentation improves faster than feedback on your tool usage.
- Number of boxes rooted with no walkthrough and no hints.
- Number of vulnerabilities reproduced manually before running a tool.
- Time spent on enumeration versus exploitation per machine.
- Reports written, reviewed, and rewritten.
- Public writeups published and read by strangers.
If You're Switching Careers or Have No Degree
Degrees help with some large employers and government roles that require specific credentials, but they are not the deciding factor in most private-sector hiring. What gets interviews is demonstrable skill: a hands-on certification, public writeups, and the ability to explain a finding clearly to a non-technical audience. Help desk, sysadmin, and software development experience all transfer directly.
If you are coming from outside IT, take the on-ramp seriously. A support or SOC role is not a detour; it puts you inside a security team, gives you a paycheck, and exposes you to the tools and ticketing systems that pentest teams use. Meanwhile, bug bounties, internal security projects, and local meetups build the network that produces referrals.
- Translate existing work into security language on your resume.
- Use SOC or IT support roles as paid, legitimate entry points.
- Attend local security meetups and conferences; referrals beat applications.
- Contribute to open-source security tooling to build a public track record.
Common mistakes to avoid
- Collecting certifications instead of lab hours — pick one hands-on exam and spend the rest of your time exploiting machines.
- Skipping networking and Linux fundamentals, which leaves you memorizing exploits you cannot adapt or explain.
- Running tools without reading the output — reproduce every finding manually at least once so you understand the cause.
- Never writing anything up — treat every machine you finish as a client report with findings, impact, and remediation.
- Avoiding Active Directory because it looks intimidating, even though it appears in most corporate internal tests.
- Applying only to roles titled penetration tester — SOC, IT support, and sysadmin jobs are legitimate on-ramps.
Frequently asked questions
How long does it take to become a penetration tester?
From zero, plan on roughly nine to twelve months of consistent study to reach entry-level readiness, and longer if you study part time. Career switchers with IT or development experience often move faster. The timeline depends far more on hours per week and how many machines you actually exploit than on which course you buy. Hands-on reps, not reading, are the bottleneck.
Do I need a degree to become a penetration tester?
No, though it helps with some large employers and government work that requires specific credentials. What gets you hired is demonstrable skill: a hands-on certification, public writeups, and the ability to explain a finding clearly. Many testers enter from IT support, systems administration, or software development. Without a degree, compensate with portfolio depth, referrals, and strong communication.
Which certification should I get first?
If you have no technical background, start with vendor-neutral fundamentals such as CompTIA Network+ and Security+. Then move to a hands-on certification. eJPT and PNPT are common starting points, while OSCP, OSCP+, and HTB CPTS carry a stronger signal for generalist roles. Avoid stacking multiple-choice certificates; each one you skip frees weeks for lab time.
Is penetration testing hard?
It is hard in a specific way: the field is broad before it is deep, and progress is uneven. You will spend long stretches on enumeration that leads nowhere before something clicks. The people who succeed treat it as a craft, keep disciplined notes, read tool output carefully, and finish machines instead of jumping to a new one when they get frustrated.
Can I learn penetration testing without a home lab?
Mostly yes. Cloud ranges like TryHackMe and Hack The Box cover the majority of practice you need, and PortSwigger Academy runs entirely in a browser. A small local lab is still worth setting up: a hypervisor, Kali, and a couple of vulnerable VMs let you practice shell handling, Active Directory, and privilege escalation with full control and no queue.