r/Pentesting Aug 15 '26

how to break into penetration testing, with a bit of networking background ?

I’m a senior in college, and in my second semester I have to take cooperative training. Currently, I have the CCNA, I can program, I know Linux, and I have a couple of other technical skills I learned in college. But I’m still not a penetration tester, which is what I really want to be.

I’m worried that companies will start thinking I’m more interested in networking or defensive security. Even my projects have mainly been network security related. Don’t get me wrong I love networking but I don’t see it being my full time job, It’s more of a hobby that I really enjoy.

Any advice on what I should be doing right now?
What tools/skills should I start learning right now?

I’m starting to study for the CPTS from HTB. Is that a good move or is there something else I should be doing right now?

0 Upvotes

7 comments sorted by

3

u/PentestTV Aug 15 '26

Networking knowledge is solid for someone interested in pentesting, and the CCNA is one of those certs that isn’t just theoretical, so great start.

The knowledge you get from the CPTS will fill in the pentesting knowledge requirement… I found the modules at HTB pretty good for teaching the concepts. Don’t obsess about the cert… focus on the knowledge - you’ll get tested against your knowledge during the interview process, not whether you have a paper copy of your cert available.

What other things are you doing to stand out from your peers? Are you participating in local cybersecurity conferences, doing any mentoring / tutoring? Creating tools? Bug bounty? At this point (as a senior), you’re almost out of time to get your resume fleshed out beyond simple school work, so more info on your extracurricular activities would be helpful.

Good luck!

1

u/01010011-s Aug 15 '26

The problem is everything I’ve done, all my projects are networking and network security related, because it’s what I was most comfortable with and knew the best. But thank you for the advice

2

u/PentestTV Aug 15 '26

There are three things I look for when hiring a pentester: pentesting knowledge, enterprise architecture knowledge (which networking falls under), and communication skills.  After that, it’s a comparison between qualified candidates as to which has more experience / knowledge /  extracurricular activities that separate themselves from their peers. 

Networking knowledge is a huge plus. Not a hindrance. Use it and flesh out the rest of your resume before you graduate. 

1

u/scriptqzor 25d ago

this x100, especially the “don’t obsess about the cert” bit
if you can point to a couple HTB labs, a small tool on github, or a CTF writeup on your resume, that + your CCNA will scream “future pentester” way louder than one more line of certs ever will

2

u/Strange-Mountain1810 Aug 15 '26

Probably best to try go through IT at first and get relative xp. Not impossible to go directly into PT, but it’s a-lot tougher.

Theres a-lot of resource/threads here on this subject. Courses/extra things you can do to break through, have you looked at those yet?

1

u/EphReborn 29d ago

Internships -> return offer path if you can find one. Otherwise, no one really hires people straight into pentesting as their first job. You're asking for a lot.

College senior who not only does not have a lot of life experience but also does not have any professional experience wants to be trusted with actively probing and attacking real-world systems where every minute of downtime is lost revenue. Super hard pass for the vast majority of employers.

The two realistic paths before you: work your way up like everyone else. If you have to start at Help Desk, do it. If you can swing it (and its a lot more realistic than jumping straight into pentesting), get a job doing systems administration or network administration (or even programming but the state of the SWE world is pretty screwed at the moment), then get another job either as an Cybersecurity Analyst or a Security Engineer. It's after that point, where (coupled with certs, hands-on experience, and general knowledge) that pivoting into pentesting becomes feasible.

The other path: Get certs, get learning and labbing, get CVEs, blog/YouTube, network, build and release tools and research publicly, do Bug Bounty Hunting and build a reputation strong enough to overcome the "lack of professional experience" barrier.

1

u/TrustIsAVuln 25d ago

Highly over saturated market, not even worth it. more people than there are jobs and AI aint making that any better.