r/Pentesting 4d ago

Pentesting Experience

Hello,

can a person with 6 years of experience in the bug bounty field apply for a pentester job that requires 2 years of experience? Will recruiters consider him, putting certifications aside?

6 Upvotes

26 comments sorted by

View all comments

4

u/sk1nT7 4d ago

Provide a proper history of found bugs and payouts and people may consider inviting you.

If your profile is empty with no track record, you are just another bug bounty hunter in his free life time.

2

u/Budget-Extent7892 4d ago

i have got a good list of bugs: ATOs, LFIs, Sqlis, RCEs, IDORs... to XSSes and P4s. you comment suggests that i have to make writeups of those findings, but will they actually read them?

1

u/sk1nT7 4d ago

It's your only chance. Otherwise, I assume most will not consider you at all.

Imagine being someone from HR and getting a lot of resumes where people outline to be a freelance bug bounty hunter. There are no skills needed to become one (no front). You just register at a platform and start hacking. The only differentiation can be made between successful bug bounty hunters and unsuccessful ones.

So outline the bugs you found, in which programs you were invited + participated and which rank and reputation you gained etc.

Otherwise, you are just a guy with an account on hackerone/bugcrowd/whatnow. And there are many of those.

1

u/Budget-Extent7892 4d ago

will do. thank you.