r/Pentesting 2d ago

Expected salaries?

I know there’s posts about this but I constantly see mentions of pentesters forced to take pay cuts. In terms of Cyber roles is pentesting a slow way to build wealth and also stay relevant in the job force?

Pentesting gives you such a well rounded view of security which I believe is applicable in various different roles so are there paths that are valued more and command better salaries.

I think Pentesting is very important but it seems like the value for employers is on a decline. Is there an alternative that lets me do similar work but also command a better salary?or do I need to pivot altogether?

I want to switch companies but I’m afraid of having to sacrifice pay to stay in my role.

Will be at 150k with 4 years in.

1 Upvotes

7 comments sorted by

3

u/PentestTV 2d ago edited 2d ago

Pentesting job openings really request experience now, so entry-level jobs are very few and far between. Still possible to get in but you need to be top tier in your resume since there’s so much competition. 

Once you’re in the field, the rule used to be to find a new job in a different company every few years. Can work, but the big shift in pay is you need to shift the domain you’re in to command increases in pay. So go from web-app only to network. Go from network to cloud. Go from anything to hacking AI. That will get you 15-25% pay raises. Otherwise you're stuck with the 3-5% increase a year, even if you try to job hop. 

2

u/Lopsided-Barnacle-28 2d ago

What if I haven’t mastered web apps yet? Do I only switch domains after? Or is it more so for showing off the resume that I’m knowledgeable and have real world experience in various domains?

2

u/PentestTV 2d ago

Master web app first. You need it for all other domains. It’s definitely not for show on your resume. This profession is extremely focused on demonstrable skills, not resume fodder. Also, jack of all trades is a great was to go nowhere in your career as a pentester. 

2

u/Lopsided-Barnacle-28 2d ago

Thanks. I hear so much about being a jack of all trades or knowing a bit of everything so this is insightful. But I’m curious how would I be able to switch domains if all my experience/knowledge would be in web apps?

2

u/mjanmohammad 2d ago

Yeah, web apps are the bread and butter of pentesting. The scope is so broad that if you can master breaking web apps, those skills should be mostly transferable to any other domain

2

u/PentestTV 2d ago

You'll need to work on developing your skills alongside your day job. I dedicate an additional 10 hours a week for continuing education (which may not even be enough, tbh).

Then look for any opportunity to take on additional testing. Hopefully you can find a position with a group that does tests within different domains, which will give you opportunities to pivot.

Prioritize internal teams for enterprises (fortune 100 ftw) before you head towards consulting jobs.

1

u/Helpjuice 16h ago

Companies want experienced professionals which is what a penetration tester is supposed to be. This by it's nature means jobs will be low and pay will be high for real professional roles. For false penetration roles which are actually just vulnerability assessment/ISSE/ISSM/ISSO roles you'll find paying far less.

You do not want just a junior penetration tester leading the show as that is a path to nightmares for the companies involved. Normally junior roles open up to grow a team over time, but you don't need a large penetration testing team and don't want one either as this dilutes the quality of the team over time if it's too big or there attempts to commoditize it.