PurPassionDigital / Everywhere
The landscapeCybersecurity / InfoSecPenetration Tester / Ethical Hacker
Cybersecurity / InfoSec · Digital / Everywhere

Penetration Tester / Ethical Hacker

Revelation · Hidden RevealedThe pull to bring what's hidden to light
Pace
  • A steady rhythm with room to breathe
  • Short, intense, and the stakes are right now
What your week looks likeQuiet stretches, then deadline storms
How much you move around at workScreen and chair, almost all day
Whether you can work from anywhereWork from anywhere with a signal or internet connection
How quickly you receive feedback on your workGive it a few days
What you're actually working withNumbers, measurements, records — things you read on a screen / Concepts, theories, designs, stories — things you think up

Core
  • Going into unmapped territory, literal or intellectual.
  • Locating the specific point of failure in a complex system. The detective work of dysfunction.
  • Following evidence toward hidden truth.
  • Peeling back layers to find what's underneath.
Also present
  • Breaking something into its real components.
  • Creating the record that allows others to understand later.
  • Applying systematic problem-solving to make things work reliably.
  • Verifying whether something is true or works as claimed.

The penetration tester is the authorised attacker. An organisation hires them to find the holes in its defences before a real attacker does. The pen tester's job is to think like an adversary — to probe networks, applications, and systems methodically, looking for the misconfiguration, the unpatched vulnerability, the weak credential, the logic flaw that would give an attacker a foothold. The primary pull is Revelation — the vulnerabilities exist already but are hidden behind complexity, oversight, and misconfiguration; the work is bringing them to light before someone with worse intent does. The structured exploration of unknown target environments is the Discovery dimension that makes the reveal possible; the satisfaction lives in the moment of finding what nobody else has found.

The daily texture is a blend of methodical enumeration and creative problem-solving. A penetration test is not random hacking; it follows a structured methodology — reconnaissance, scanning, enumeration, exploitation, post-exploitation, reporting. Each phase builds on the last. The reconnaissance is patient and often the most important: understanding what the target environment looks like before touching it, mapping the attack surface, identifying the most likely paths. The exploitation phase — the moment of actually gaining access — is typically a small fraction of the total time. The report that follows is where the Protection gradient enters: the pen tester's findings become the roadmap for the organisation to fix its vulnerabilities.

The ethical dimension is distinctive. The penetration tester possesses skills that are functionally identical to those of a criminal hacker. The difference is authorisation, scope, and intent. The field takes this seriously — rules of engagement, scope documents, and get-out-of-jail letters are standard practice. The people drawn to this work are drawn to the intellectual challenge of breaking systems, and the ethical framework that channels that drive into protective work is not an afterthought; it is the structural condition that makes the profession possible.

🦊
There's a guide here if you want one

Kitsune can talk through anything on this page — whether it might suit you, what to do next, questions this page doesn't answer. Everything here is yours to read either way.

The popular image of hacking — fast, dramatic, cinematic — bears little resemblance to the actual work. Most of a penetration tester's time is spent on reconnaissance, documentation, and report writing. The exploitation itself is often anticlimactic — a known vulnerability with a known exploit that works because somebody forgot to patch. The glamour ratio is low.

Report writing is a larger share of the job than most entrants expect. A penetration test that finds critical vulnerabilities but produces an unclear report is a failed engagement. The ability to write clearly — to explain what was found, why it matters, and what to do about it — is as important as the technical skill that found the vulnerability in the first place.

The skills-maintenance burden is high. The threat landscape changes continuously. Tools, techniques, and vulnerabilities evolve. A penetration tester who stops learning falls behind within months. The field rewards sustained curiosity and the willingness to spend personal time on labs, CTF competitions, and research.

The entry path is skill-demonstrated rather than credential-gated. The OSCP (Offensive Security Certified Professional) is the most respected practical certification — it requires passing a hands-on exam rather than a multiple-choice test. CompTIA PenTest+ and CEH (Certified Ethical Hacker) are common stepping stones. Many pen testers enter from systems administration, network engineering, or SOC analyst roles. Bug bounty programmes and CTF (Capture the Flag) competitions provide a way to build skills and a visible track record without formal employment in the field. Computer science or cybersecurity degrees are valued but not required if practical skills are demonstrable.