3 ms·
I am a professional penetration tester right now in the US. I got into the field from education, but once I got my OSCP I had multiple offers from different com
by Benichmt1 9y ago
I am a professional penetration tester right now in the US. I got into the field from education, but once I got my OSCP I had multiple offers from different companies.
There are a ton of "boutique" firms in the space right now, but there are quite a few who seemed to be popular and then died off right away.
One of the big market gaps I see is the ability to provide really good tactical feedback but also package it in a way that it provides value to the actual decision-makers at the top. There are so many pentesting firms that are extremely talented at breaking in, but are really lacking at helping to actually implement cultural and program-level changes so that it doesn't happen again. There are also firms whose idea of a penetration test is just running Metasploit/Nessus/Acunetix and then packing it up without a lot of insight.
Compliance is a huge driver right now, meaning some companies just want to check the boxes and be done with it. However, just because you are PCI compliant doesn't mean you are actually secure. It takes a special set of "soft skills" to be able to help companies truly improve their posture.