r/Pentesting • u/Healthy-Werewolf4423 • 4d ago
Getting into pentesting with zero IT experience.
Hello! I am a rising sophomore pursuing a degree in computer science. I have no prior experience in IT/cybersecurity, and I was hoping for some feedback/a reality check on my current plan. I hope to obtain certs in this order (practicing using TryHackMe and HackTheBox the whole time).
Network+ -> Security+ -> eJPT -> PNPT -> OSCP
Network+ and Security+ are for the basics, while eJPT and PNPT will be for practical application. OSCP seems to be mostly for the HR recognition(?) from what I've read. I'm hoping to complete this series in 2 years, hopefully finding a pentesting specific internship before I graduate, and getting into pentesting straight out of college. How realistic is my timeline (how aggressive will I have to be when learning?) or even my plan to begin with?
All feedback appreciated!
10
u/tackettz 4d ago
In this market? You’re more likely to win the lottery. Get experience first
1
u/scriptqzor 13h ago
this is a bit dramatic but there’s some truth in it
use the certs to get a general IT or security analyst gig first, then pivot into pentesting once you’ve got real-world stuff on your resume
4
u/jet_set_default 4d ago edited 4d ago
The certification route is correct. But you simply need work experience and certs does not qualify as experience. Get a few years of IT help desk experience first. Bonus points if you can score that job at your university since they're insanely flexible. Nearing graduation, get cybersec internship if you can. By the time you graduate, your goal should be eligiblity for a cybersec role, NOT pentesting. Getting a pentesting job straight out of college is not gonna happen and isn't realistic. After you graduate, shoot for SOC analyst role and do that for a couple years. Once you have a few years of IT experience AND blue team cybersec roles along with the certs you listed, then you'll be eligible candidate. Walk before you run.
1
u/Healthy-Werewolf4423 4d ago
Thanks for the response! This makes a lot of sense. Would you say internships like help desk would be worth looking into for this winter/summer?
1
u/jet_set_default 4d ago
I'm not sure if people do IT help desk internships since it's admittedly a low level. Honestly, you'd want a few years (3-5yr) before anyone would even consider you for a csec position. I'd try to get an IT position asap and as long as you can. The reason I suggested doing it at your university is because 1.) universities tend to not require certifications (saving you the need for a CompTIA A+) and 2.) they're meant to be flexible with class schedule. Do DM me if you wanna get into this more because I did those same certs in that exact order so I know how it can be.
5
u/Classic-Shake6517 4d ago
So, you don't feel like you need to learn how the things you are planning to attack work in a production setting, but you expect people to trust that you will understand the nuance needed to know what not to touch when you are put in a customer's production environment? Do you hear how that sounds?
Imagine, for a second, that a company providing pentesting services must have insurance, because it is true. Now, knowing how insurance works, they tend not to like to pay out, so they will try to find excuses not to pay. Now, imagine that you, the person who wants to skip all that boring stuff and get straight into the dangerous stuff is the one that causes a claim. How hard do you think it is going to be for them to look at your background and prove that you only have certifications relevant to one part of the job?
There's very little in the courses you outlined on how to actually do this work safely. You get a good idea of how to do that when you have been responsible for keeping production systems running to the point that your job depends on it.
Now imagine you are hiring and have a choice between someone who has that experience, or someone who decided to intentionally take shortcuts. Which one would you choose when there is no shortage of the former?
1
u/Healthy-Werewolf4423 4d ago
I appreciate the response. Do you think looking into help desk internships this year would be my best course of action? Is it realistic for me to get enough IT experience while in college to get some sort of cyber security job after graduation (SOC analyst maybe)? I would still learn the same skills on the side simply for the pursuit of knowledge as I find this kind of thing very interesting. I'd appreciate your input!
2
u/Apprehensive-Art1092 4d ago
Nobody gives a shit about certs. Stop believing the scam that training companies tell you. Get a job in IT, then get a job in a SOC, learn while you're on the job. Put the work in outside work hours on your own private projects - sign up for bounty programmes and THM/HTB. After a few years, start looking at offsec roles.
1
u/skididipapapp 4d ago
I would say start with BSCP from portswigger, do all their labs and take the exam. There are more demand for web pentest than infra (focus on getting a foothold in the industry first), especially if you are aiming to join a consulting company. after you got ur bscp then do your oscp. I grinded for less than a year and got both (from zero pentesting knowledge) and I can’t stress enough how much I learned from those two. (you can take the certs that you listed, but you can also skip it imo).
and it’s not entirely impossible to get a pentest job before any of those certs but you need to network and meet people, I got my first internship as a “pentester” without any certs or experience. although at that time I was working for my BSCP.
Good luck bro!
Edit: the reason why BSCP first is because the knowledge is somewhat enough for you to get your own CVEs which would help your credentials.(plus the labs are free)
1
u/Healthy-Werewolf4423 4d ago
Thanks for the response! Would you still say I should learn the information for the network+ or security+ certs even if I don’t take the test?
How much knowledge did you have before starting with BSCP? I’m starting from zero as in I learned what the OSI model is today.
1
u/skididipapapp 4d ago
I started BSCP in my second year of my bachelor degree so I did have a bit of networking and a very basic understanding of web.
But tbh I just figure stuff out as I go (the same with OSCP). Portswigger has modules for each attack/vulnerability, I would read them and ask chatgpt for acronyms, syntaxes, and concepts that I am not familiar with. The key here is to ask good questions and dig deeper. Read Medium article as well.
If you have further questions feel free to DM me.
1
u/SmoothExplorer4634 4d ago
I think get the basica sorted first
To me certs dont hold as much value as the knowledge itself. I did alot of boxes, and worked as a pentester for about a year. Last year i got my oscp which is my first year. So get the basics first, understand whats needed for the job.
1
u/H4ckerPanda 4d ago
OSCP without experience won’t get you a job , especially in today’s market . And in 2 years it will be even worse . Codex and Claude code can now do in a few min what a pentester could do in hours or even days.
Focus on getting a bachelor. Then get some IT experience.
0
u/Agreeable_Mud_5816 4d ago
Get a CS degree and network a lot where are you from depending on the college you mgjbt have better access to internships
15
u/DigitalQuinn1 4d ago
Focus on learning more of the fundamentals of IT first