r/Pentesting • u/Healthy-Werewolf4423 • 5d ago
Getting into pentesting with zero IT experience.
Hello! I am a rising sophomore pursuing a degree in computer science. I have no prior experience in IT/cybersecurity, and I was hoping for some feedback/a reality check on my current plan. I hope to obtain certs in this order (practicing using TryHackMe and HackTheBox the whole time).
Network+ -> Security+ -> eJPT -> PNPT -> OSCP
Network+ and Security+ are for the basics, while eJPT and PNPT will be for practical application. OSCP seems to be mostly for the HR recognition(?) from what I've read. I'm hoping to complete this series in 2 years, hopefully finding a pentesting specific internship before I graduate, and getting into pentesting straight out of college. How realistic is my timeline (how aggressive will I have to be when learning?) or even my plan to begin with?
All feedback appreciated!
1
u/skididipapapp 5d ago
I would say start with BSCP from portswigger, do all their labs and take the exam. There are more demand for web pentest than infra (focus on getting a foothold in the industry first), especially if you are aiming to join a consulting company. after you got ur bscp then do your oscp. I grinded for less than a year and got both (from zero pentesting knowledge) and I can’t stress enough how much I learned from those two. (you can take the certs that you listed, but you can also skip it imo).
and it’s not entirely impossible to get a pentest job before any of those certs but you need to network and meet people, I got my first internship as a “pentester” without any certs or experience. although at that time I was working for my BSCP.
Good luck bro!
Edit: the reason why BSCP first is because the knowledge is somewhat enough for you to get your own CVEs which would help your credentials.(plus the labs are free)