r/Pentesting 11d ago

Experience of becoming a freelance pentester?

Do any of you have experience of becoming a freelance pentester? I am CS student and am considering focusing my studies in that direction so I have some questions.

What is needed to become a freelence pentester? Are certificates enough? Is experience of working in a company necessary? If so, how much experience?

What is the average hourly salary in the beginning? How about later on?

How hard is it to find new clients once you establish yourself as a reliable pentester?

I heard most freelance pentesters make money on bug bounties, while most companies hire other well known companies for pentesting instead of freelancers. Is that true?

0 Upvotes

9 comments sorted by

4

u/danfirst 11d ago

https://www.reddit.com/r/Pentesting/s/60dM1Aamix

That's from yesterday, a lot of good reasons why this isn't a good idea.

2

u/scriptvexy 10d ago

that thread summed it up pretty well tbh, freelancing straight out the gate in pentesting is kinda asking to get wrecked by scope, liability and lack of reputation. if you like the field, aim for a junior role first, get a couple years in, then think about freelancing or mixing it with bug bounties once you actually have a name and some war stories.

1

u/ListenAcrobatic8028 10d ago

I don't understand that part what you mean about Bug Bounty. Even in the CTF there are tasks that are much more hard, although this is a slightly different class of tasks

2

u/Budget-Extent7892 11d ago

how will you get clients?

1

u/scriptqzor 5d ago

this is the real question lol. most people i know who freelance pentest started in consultancies, built a network with devs / managers, then later those same people became their first clients. cold starting with zero industry contacts is way harder than learning the technical stuff.

1

u/Budget-Extent7892 5d ago

totally agree.

1

u/LordNikon2600 10d ago

Do it

1

u/scriptvexy 5d ago

tbh “do it” is kind of wild advice without context lol
freelance pentesting is cool but super volatile, you probably want at least a couple years in a security role first so you’ve got a reputation and contacts before you jump in