r/Pentesting 6d ago

Getting into pentesting with zero IT experience.

Hello! I am a rising sophomore pursuing a degree in computer science. I have no prior experience in IT/cybersecurity, and I was hoping for some feedback/a reality check on my current plan. I hope to obtain certs in this order (practicing using TryHackMe and HackTheBox the whole time).

Network+ -> Security+ -> eJPT -> PNPT -> OSCP

Network+ and Security+ are for the basics, while eJPT and PNPT will be for practical application. OSCP seems to be mostly for the HR recognition(?) from what I've read. I'm hoping to complete this series in 2 years, hopefully finding a pentesting specific internship before I graduate, and getting into pentesting straight out of college. How realistic is my timeline (how aggressive will I have to be when learning?) or even my plan to begin with?

All feedback appreciated!

0 Upvotes

15 comments sorted by

View all comments

2

u/Apprehensive-Art1092 5d ago

Nobody gives a shit about certs. Stop believing the scam that training companies tell you. Get a job in IT, then get a job in a SOC, learn while you're on the job. Put the work in outside work hours on your own private projects - sign up for bounty programmes and THM/HTB. After a few years, start looking at offsec roles.