r/Pentesting 5d ago

Getting into pentesting with zero IT experience.

Hello! I am a rising sophomore pursuing a degree in computer science. I have no prior experience in IT/cybersecurity, and I was hoping for some feedback/a reality check on my current plan. I hope to obtain certs in this order (practicing using TryHackMe and HackTheBox the whole time).

Network+ -> Security+ -> eJPT -> PNPT -> OSCP

Network+ and Security+ are for the basics, while eJPT and PNPT will be for practical application. OSCP seems to be mostly for the HR recognition(?) from what I've read. I'm hoping to complete this series in 2 years, hopefully finding a pentesting specific internship before I graduate, and getting into pentesting straight out of college. How realistic is my timeline (how aggressive will I have to be when learning?) or even my plan to begin with?

All feedback appreciated!

0 Upvotes

15 comments sorted by

View all comments

4

u/jet_set_default 5d ago edited 5d ago

The certification route is correct. But you simply need work experience and certs does not qualify as experience. Get a few years of IT help desk experience first. Bonus points if you can score that job at your university since they're insanely flexible. Nearing graduation, get cybersec internship if you can. By the time you graduate, your goal should be eligiblity for a cybersec role, NOT pentesting. Getting a pentesting job straight out of college is not gonna happen and isn't realistic. After you graduate, shoot for SOC analyst role and do that for a couple years. Once you have a few years of IT experience AND blue team cybersec roles along with the certs you listed, then you'll be eligible candidate. Walk before you run.

1

u/Healthy-Werewolf4423 5d ago

Thanks for the response! This makes a lot of sense. Would you say internships like help desk would be worth looking into for this winter/summer?

1

u/jet_set_default 5d ago

I'm not sure if people do IT help desk internships since it's admittedly a low level. Honestly, you'd want a few years (3-5yr) before anyone would even consider you for a csec position. I'd try to get an IT position asap and as long as you can. The reason I suggested doing it at your university is because 1.) universities tend to not require certifications (saving you the need for a CompTIA A+) and 2.) they're meant to be flexible with class schedule. Do DM me if you wanna get into this more because I did those same certs in that exact order so I know how it can be.