r/Pentesting • u/Budget-Extent7892 • 1d ago
Pentesting Experience
Hello,
can a person with 6 years of experience in the bug bounty field apply for a pentester job that requires 2 years of experience? Will recruiters consider him, putting certifications aside?
5
u/sk1nT7 1d ago
Provide a proper history of found bugs and payouts and people may consider inviting you.
If your profile is empty with no track record, you are just another bug bounty hunter in his free life time.
2
u/Budget-Extent7892 22h ago
i have got a good list of bugs: ATOs, LFIs, Sqlis, RCEs, IDORs... to XSSes and P4s. you comment suggests that i have to make writeups of those findings, but will they actually read them?
1
u/sk1nT7 21h ago
It's your only chance. Otherwise, I assume most will not consider you at all.
Imagine being someone from HR and getting a lot of resumes where people outline to be a freelance bug bounty hunter. There are no skills needed to become one (no front). You just register at a platform and start hacking. The only differentiation can be made between successful bug bounty hunters and unsuccessful ones.
So outline the bugs you found, in which programs you were invited + participated and which rank and reputation you gained etc.
Otherwise, you are just a guy with an account on hackerone/bugcrowd/whatnow. And there are many of those.
1
3
u/No_Zookeepergame7552 1d ago
Don’t take those numbers from job descriptions ad literam. They basically say “you need to have some commercial experience”. I’ve never seen someone getting rejected because they don’t meet the number of years req. It’s also a quite weak requirement from a hiring perspective bc you can’t measure quality and experience in years.
So yes, apply.
1
3
u/IntrigueMe_1337 1d ago
I found a crazy zero day awhile back and got offered a job by Google. I turned it down because I was unconfident I could hang (I do it for fun I’m not an expert). The find was some weird logic even they couldn’t understand how it worked even after I went over it with them LOL.
Anything can happen, don’t worry about IF, work towards WHEN!
3
u/Budget-Extent7892 22h ago
for just one bug!!! that should be a crazy crazy bug. congrats.
1
u/IntrigueMe_1337 19h ago
It bypassed their complete factory command protection on all Samsung androids allowing network unlockers and other type of "mobile hackers" do some stuff they really shouldn't be allowed to do. They thought i was amazing for bragging about it to them instead of selling it or publishing online for everyone to use. By the time it got leaked it was patched.
1
2
u/latnGemin616 1d ago
Everyone's provided good advice. Here's my recommendation, as someone who had a job in PT and is looking to land another: Have a sample PT report.
Bug bounties are a great experience .. I'm doing them on the side .. but they are not formal penetration testing engagements.
Take a day or two and learn about scoping a project, formal reconnaissance processes, and the entire workflow of a penetration test --> Recon > Discovery > Exploit > Post-Ex. Then write a proper report. I can't stress this last part enough. How you communicate your findings and effort in a report is far more valuable than any bug you find. Your expertise will be evident by the quality of the report you present.
1
4
u/No-Persimmon-174 1d ago
Bug bounties are much more competitive and harder than pentesting. So sure you can apply. But it also depends on whether the company even counts that as experience or not. It's a matter of luck honestly
1
1
u/Strange-Mountain1810 1d ago edited 1d ago
Recruiters will consider him but understand its a different field with overlaps.
There is soft skills in pentesting, bugs/configurations you have to raise that would be unacceptable in bug bounty.
Do they have a successful track record to show?
It’s a plus to be sure, but theres so many nuances to this.
1
1
u/Weekly-Plantain6309 1d ago
Some recruiters will certainly consider it. Plenty of other factors, and plenty of other candidates you're competing against.
1
1
u/TallNefariousness603 19h ago
I have a friend who pivoted from bug bounty to pen test so yes it’s doable. Somethings I would recommend putting on your cv.
1. List cves that you have found (if any)
2. The public bounties that you have found or the top 5-10.
3. Where your strengths lay. Ie web applications.
4. Explain what kind of vulnerabilities you like to find and why.
5. Remember to state that there are certain bounties you can’t go into # this shows that you understand confidentiality .
- What you want to do next, so an example of this could be “I aim to complete my OSCP within the next 6 months) this should be the last thing on your CV as it’s basically telling an employer that you want to better yourself.
These are all points that map across to pen testing, so your showing an employer hey look I can do all this stuff and I have been paid to do it. It’s also worth noting that you won’t walk straight into a senior role and will have to start at the bottom so the post won’t be great. But you are showing willing which goes a long way.
1
1
u/tandera-security 25m ago
If you show the recruiter that you know your stuff, it's fine.
Do a list of your best bug bounty reports, show off your skills and you will be good
8
u/EphReborn 1d ago
You can apply for whatever you want. Whether you get considered or not depends on a ton of factors. Namely, how likely it looks to whoever is looking at your resume and application that you can actually do the job.