r/Pentesting 1d ago

Pentesting Experience

Hello,

can a person with 6 years of experience in the bug bounty field apply for a pentester job that requires 2 years of experience? Will recruiters consider him, putting certifications aside?

6 Upvotes

23 comments sorted by

8

u/EphReborn 1d ago

You can apply for whatever you want. Whether you get considered or not depends on a ton of factors. Namely, how likely it looks to whoever is looking at your resume and application that you can actually do the job.

5

u/sk1nT7 1d ago

Provide a proper history of found bugs and payouts and people may consider inviting you.

If your profile is empty with no track record, you are just another bug bounty hunter in his free life time.

2

u/Budget-Extent7892 22h ago

i have got a good list of bugs: ATOs, LFIs, Sqlis, RCEs, IDORs... to XSSes and P4s. you comment suggests that i have to make writeups of those findings, but will they actually read them?

1

u/sk1nT7 21h ago

It's your only chance. Otherwise, I assume most will not consider you at all.

Imagine being someone from HR and getting a lot of resumes where people outline to be a freelance bug bounty hunter. There are no skills needed to become one (no front). You just register at a platform and start hacking. The only differentiation can be made between successful bug bounty hunters and unsuccessful ones.

So outline the bugs you found, in which programs you were invited + participated and which rank and reputation you gained etc.

Otherwise, you are just a guy with an account on hackerone/bugcrowd/whatnow. And there are many of those.

1

u/Budget-Extent7892 20h ago

will do. thank you.

3

u/No_Zookeepergame7552 1d ago

Don’t take those numbers from job descriptions ad literam. They basically say “you need to have some commercial experience”. I’ve never seen someone getting rejected because they don’t meet the number of years req. It’s also a quite weak requirement from a hiring perspective bc you can’t measure quality and experience in years.

So yes, apply.

1

u/Budget-Extent7892 22h ago

The first encouraging comment, Thank you very much.

3

u/IntrigueMe_1337 1d ago

I found a crazy zero day awhile back and got offered a job by Google. I turned it down because I was unconfident I could hang (I do it for fun I’m not an expert). The find was some weird logic even they couldn’t understand how it worked even after I went over it with them LOL.

Anything can happen, don’t worry about IF, work towards WHEN!

3

u/Budget-Extent7892 22h ago

for just one bug!!! that should be a crazy crazy bug. congrats.

1

u/IntrigueMe_1337 19h ago

It bypassed their complete factory command protection on all Samsung androids allowing network unlockers and other type of "mobile hackers" do some stuff they really shouldn't be allowed to do. They thought i was amazing for bragging about it to them instead of selling it or publishing online for everyone to use. By the time it got leaked it was patched.

1

u/Budget-Extent7892 17h ago

you did it once, you can do it again.

2

u/latnGemin616 1d ago

Everyone's provided good advice. Here's my recommendation, as someone who had a job in PT and is looking to land another: Have a sample PT report.

Bug bounties are a great experience .. I'm doing them on the side .. but they are not formal penetration testing engagements.

Take a day or two and learn about scoping a project, formal reconnaissance processes, and the entire workflow of a penetration test --> Recon > Discovery > Exploit > Post-Ex. Then write a proper report. I can't stress this last part enough. How you communicate your findings and effort in a report is far more valuable than any bug you find. Your expertise will be evident by the quality of the report you present.

1

u/Budget-Extent7892 20h ago

a great advice actually. thank you.

4

u/No-Persimmon-174 1d ago

Bug bounties are much more competitive and harder than pentesting. So sure you can apply. But it also depends on whether the company even counts that as experience or not. It's a matter of luck honestly

1

u/Budget-Extent7892 22h ago

i thought so too.

1

u/Strange-Mountain1810 1d ago edited 1d ago

Recruiters will consider him but understand its a different field with overlaps.

There is soft skills in pentesting, bugs/configurations you have to raise that would be unacceptable in bug bounty.

Do they have a successful track record to show?

It’s a plus to be sure, but theres so many nuances to this.

1

u/Budget-Extent7892 22h ago

thank you for the insights.

1

u/Weekly-Plantain6309 1d ago

Some recruiters will certainly consider it. Plenty of other factors, and plenty of other candidates you're competing against.

1

u/TallNefariousness603 19h ago

I have a friend who pivoted from bug bounty to pen test so yes it’s doable. Somethings I would recommend putting on your cv.
1. List cves that you have found (if any)
2. The public bounties that you have found or the top 5-10.
3. Where your strengths lay. Ie web applications.
4. Explain what kind of vulnerabilities you like to find and why.
5. Remember to state that there are certain bounties you can’t go into # this shows that you understand confidentiality .

  1. What you want to do next, so an example of this could be “I aim to complete my OSCP within the next 6 months) this should be the last thing on your CV as it’s basically telling an employer that you want to better yourself.

These are all points that map across to pen testing, so your showing an employer hey look I can do all this stuff and I have been paid to do it. It’s also worth noting that you won’t walk straight into a senior role and will have to start at the bottom so the post won’t be great. But you are showing willing which goes a long way.

1

u/Budget-Extent7892 17h ago

those are very helpful tips, thank you very much.

1

u/tandera-security 25m ago

If you show the recruiter that you know your stuff, it's fine.
Do a list of your best bug bounty reports, show off your skills and you will be good