3 ms·
First you need to work for established infosec companies. They get pentest projects every day, easily. You can't be like them day 1. So when you work through th
by SecConsult 11y ago
First you need to work for established infosec companies. They get pentest projects every day, easily. You can't be like them day 1. So when you work through those companies and do pentest for a client, show yourself. In our team, maybe 10 people were working with me on pentest projects, but if you ask clients now after years, they probably ONLY remember my name, because they know and understand who did what. So after years and years of good reputation, it's super easy to expand your client base, do for yourself, ask for top $, reject offers might be a dream salary for some. But just like everything else, you start slowly and gradually "level-up"