Penetration testing has the most portfolio-driven hiring process in cybersecurity — and a CV without supporting evidence (GitHub repositories, CVE disclosures, bug bounty acknowledgements, CTF rankings) is at a structural disadvantage regardless of how well it is written. The reason is simple: pentesting is a technical skill that is easy to claim and hard to fake, and hiring managers know it. OSCP remains the single most powerful filter credential in this market — not because it proves elite skill, but because it proves that you can compromise a real machine under exam conditions with no hints. A CV with OSCP gets read differently from the first line. Beyond certification, the evidence that matters is engagement scope (how many tests, what type, at what target complexity), any original research (CVE disclosures, bug bounty findings, tool development), and report quality — because for consultancy pentesting roles, clear and actionable reports are the primary commercial deliverable. This guide covers how to structure a penetration tester CV, which keywords ATS systems filter on, and how to write bullets that prove offensive security capability rather than just claiming it.

What Penetration Tester Job Descriptions Require in 2026

Pentesting JDs split clearly between consultancy roles (where you test multiple client environments per month and deliver reports) and in-house roles (where you test your own organisation's systems, typically as part of a red team or offensive security function). Both require similar technical skills but weight different competencies:

Consultancy pentesting (CREST-accredited firms, Big 4 advisory, boutique security firms): Primary deliverable is the written report. Commercial awareness, client communication, and on-time delivery matter as much as technical skill. CREST qualifications (CRT, CCT) are required for many UK government and financial services contracts. Volume of tests and breadth of test types are key signals.

In-house / red team (large enterprises, tech companies, financial institutions): More time per engagement, deeper access to internal systems, and closer collaboration with blue team. Red team operations (multi-week adversary simulation) are the senior-end of this track. Purple team experience (working with defenders to improve detection) is increasingly valued.

Requirements across both tracks:

  • Scoped engagement experience — web application testing (OWASP Top 10, business logic flaws, API security), network infrastructure testing (internal and external), and Active Directory / Windows environment testing. Cloud penetration testing (AWS, Azure, GCP) is growing rapidly in JDs.
  • Core tooling — Burp Suite (web), Nmap, Metasploit, Nessus/OpenVAS (network scanning), BloodHound (AD reconnaissance), and Cobalt Strike or Havoc for red team engagements. JDs name the specific tools; your CV should match.
  • Methodology — OWASP Testing Guide, PTES (Penetration Testing Execution Standard), NIST SP 800-115, and MITRE ATT&CK for red team operations. Methodology literacy signals professionalism above script-kiddie tooling.
  • Report writing — clear, structured, client-ready reports with executive summaries, technical findings, evidence, and prioritised remediation recommendations. This is non-negotiable for consultancy roles.
  • OSCP or equivalent — Offensive Security Certified Professional (OSCP) for most roles; GPEN (GIAC Penetration Tester) or CREST CRT for consultancy/government contexts; GWAPT for web-specific roles.

Penetration tester salaries in 2026: £40K–£70K UK (junior to mid-level consultancy); £65K–£100K for senior and lead. In-house senior red team roles: £75K–£110K. US: $80K–$130K; senior/red team $120K–$175K.

ATS Keywords for a Penetration Tester Resume

Pentesting ATS filtering is certification-first and tool-specific. "OSCP" as a standalone string is one of the highest-signal keywords in offensive security hiring.

Essential ATS terms for a penetration tester resume:

  • Title variants: Penetration Tester, Pen Tester, Ethical Hacker, Red Team Analyst, Offensive Security Engineer, Security Consultant, Vulnerability Researcher
  • Certifications: OSCP, OSCE, OSEP, CEH, GPEN, GWAPT, GXPN, CREST CRT, CREST CCT, CompTIA PenTest+
  • Web application: web application penetration testing, OWASP Top 10, Burp Suite, API security testing, XSS, SQL injection, IDOR, SSRF, business logic vulnerabilities
  • Network and infrastructure: network penetration testing, Nmap, Metasploit, Nessus, OpenVAS, internal testing, external testing, firewall bypass
  • Active Directory / Windows: Active Directory attacks, BloodHound, SharpHound, Kerberoasting, Pass-the-Hash, lateral movement, privilege escalation, Cobalt Strike, PowerShell Empire
  • Red team: red team, adversary simulation, C2 framework, persistence, evasion, MITRE ATT&CK, TTP, purple team
  • Cloud pentesting: AWS penetration testing, Azure security testing, cloud misconfiguration, IAM abuse
  • Research: CVE, bug bounty, HackerOne, Bugcrowd, responsible disclosure, CTF, TryHackMe, HackTheBox, exploit development
  • Long-tail phrases: penetration tester resume examples, how to write a pen tester resume, OSCP resume, ethical hacker cv, red team resume, cybersecurity offensive security resume

Placement: OSCP (or equivalent) in the headline — it is the first thing every pentesting hiring manager looks for. Your primary test type (web app, network, red team) in the headline alongside it. GitHub link in your header if you have public security tools, PoCs, or writeups — interviewers will check it.

Penetration Tester CV Structure and Bullets That Prove Offensive Capability

Section order:

  1. Headline — "Penetration Tester | OSCP · Web App & Network · Burp Suite · MITRE ATT&CK · Active Directory"
  2. Certifications — OSCP first, then others; in-progress OSCP worth listing with expected date
  3. Skills — Testing Domains / Core Tools / AD & Windows / Cloud / Methodology & Frameworks
  4. Experience — 4–5 bullets per role; engagement count, test types, critical findings, and report delivery are the evidence
  5. Research & Portfolio — CVE disclosures, bug bounty programme names and findings, CTF competition rankings, HackTheBox/TryHackMe completion; this section is unique to pentesting and can be decisive
  6. Education — CS or information security degree; bottom

One to two pages. GitHub or personal site link in the header. The Research & Portfolio section replaces the education emphasis that other IT roles rely on — original findings are more persuasive than any degree.

Three elements make a pentesting bullet convincing: the engagement scope (test type, environment complexity, target count), the key technical finding or action, and the outcome (vulnerability severity, client impact, report delivered). Three examples:

  • Conducted 40+ web application penetration tests over 12 months for clients in financial services, healthcare, and e-commerce — identified 8 critical vulnerabilities including 2 SQL injection flaws enabling full unauthenticated database extraction; all reports delivered within 5 business days of testing completion with executive summary and CVSS-scored remediation roadmap
  • Led a 2-week red team engagement simulating an advanced persistent threat actor — achieved domain administrator compromise via spear phishing, lateral movement through Kerberoasting, and simulated data exfiltration without triggering SOC detection; delivered 38-page debrief with all TTPs mapped to MITRE ATT&CK and a prioritised detection improvement roadmap for the blue team
  • Discovered and responsibly disclosed a critical authentication bypass vulnerability in a widely-used open-source library (CVSS 9.1) — coordinated 90-day disclosure timeline with the vendor, patch released and deployed to 14,000+ installations before public disclosure; acknowledged in vendor security advisory

Pentesting interviews for consultancy roles include a technical challenge (a small CTF-style box or code review) and a communication test (explain this finding to a non-technical client). For in-house roles, the interview tests depth on specific attack techniques and blue team awareness. Your CVE disclosures and bug bounty entries are often discussed in detail — be prepared to walk through your methodology.

Three Penetration Tester CV Mistakes That Lose the Interview

OSCP absent from the headline when you hold it. The OSCP is not just a certification — it is a signal that changes how the hiring manager reads everything that follows. It proves you can identify vulnerabilities, develop exploits, and compromise machines in a real, unguided environment. An OSCP buried in a certifications list at the bottom of the page loses most of its value. Put it in the headline. If you are studying for it, note it: "OSCP — expected Q4 2026" still signals serious intent and is better than silence.

Engagement scope without findings. "Conducted penetration tests for multiple clients" is the weakest possible pentesting bullet. It says nothing about what types of tests, what environments, how many engagements, or most importantly — what you found. Findings are the output of a penetration test; they are the evidence that technical work was done. "Identified 3 critical vulnerabilities including an unauthenticated remote code execution flaw" is concrete. The absence of findings from a pentesting CV reads as either junior experience with no significant discoveries, or an inability to describe the work — neither is a positive signal.

No portfolio or research section. Pentesting is unique among IT disciplines in that original research — CVE disclosures, bug bounty findings, CTF wins, open-source tool development — carries more weight than most formal credentials. A CV with a CREST certification and no evidence of independent security research will be outcompeted by a CV with strong bug bounty acknowledgements and HackTheBox Pro Hacker status. If you have any public security work — a writeup, a disclosed vulnerability, a tool on GitHub, a CTF podium finish — it belongs on your CV. Create a Research & Portfolio section above Education and list it there.


If you are applying to penetration tester or red team roles and want your CV rebuilt around the specific OSCP, CREST, and engagement requirements in a target job description, Resumegpt generates your penetration tester CV from your work history in under 60 seconds — offensive credentials surfaced, portfolio signals integrated, ATS-optimised, and exported as a PDF ready to submit.