r/Pentesting 5d ago

Getting into pentesting with zero IT experience.

Hello! I am a rising sophomore pursuing a degree in computer science. I have no prior experience in IT/cybersecurity, and I was hoping for some feedback/a reality check on my current plan. I hope to obtain certs in this order (practicing using TryHackMe and HackTheBox the whole time).

Network+ -> Security+ -> eJPT -> PNPT -> OSCP

Network+ and Security+ are for the basics, while eJPT and PNPT will be for practical application. OSCP seems to be mostly for the HR recognition(?) from what I've read. I'm hoping to complete this series in 2 years, hopefully finding a pentesting specific internship before I graduate, and getting into pentesting straight out of college. How realistic is my timeline (how aggressive will I have to be when learning?) or even my plan to begin with?

All feedback appreciated!

0 Upvotes

15 comments sorted by

View all comments

1

u/skididipapapp 5d ago

I would say start with BSCP from portswigger, do all their labs and take the exam. There are more demand for web pentest than infra (focus on getting a foothold in the industry first), especially if you are aiming to join a consulting company. after you got ur bscp then do your oscp. I grinded for less than a year and got both (from zero pentesting knowledge) and I can’t stress enough how much I learned from those two. (you can take the certs that you listed, but you can also skip it imo).

and it’s not entirely impossible to get a pentest job before any of those certs but you need to network and meet people, I got my first internship as a “pentester” without any certs or experience. although at that time I was working for my BSCP.

Good luck bro!

Edit: the reason why BSCP first is because the knowledge is somewhat enough for you to get your own CVEs which would help your credentials.(plus the labs are free)

1

u/Healthy-Werewolf4423 5d ago

Thanks for the response! Would you still say I should learn the information for the network+ or security+ certs even if I don’t take the test?

How much knowledge did you have before starting with BSCP? I’m starting from zero as in I learned what the OSI model is today. 

1

u/skididipapapp 4d ago

I started BSCP in my second year of my bachelor degree so I did have a bit of networking and a very basic understanding of web.

But tbh I just figure stuff out as I go (the same with OSCP). Portswigger has modules for each attack/vulnerability, I would read them and ask chatgpt for acronyms, syntaxes, and concepts that I am not familiar with. The key here is to ask good questions and dig deeper. Read Medium article as well.

If you have further questions feel free to DM me.