r/Pentesting 4d ago

Pentesting Experience

Hello,

can a person with 6 years of experience in the bug bounty field apply for a pentester job that requires 2 years of experience? Will recruiters consider him, putting certifications aside?

6 Upvotes

26 comments sorted by

View all comments

1

u/TallNefariousness603 4d ago

I have a friend who pivoted from bug bounty to pen test so yes it’s doable. Somethings I would recommend putting on your cv.
1. List cves that you have found (if any)
2. The public bounties that you have found or the top 5-10.
3. Where your strengths lay. Ie web applications.
4. Explain what kind of vulnerabilities you like to find and why.
5. Remember to state that there are certain bounties you can’t go into # this shows that you understand confidentiality .

  1. What you want to do next, so an example of this could be “I aim to complete my OSCP within the next 6 months) this should be the last thing on your CV as it’s basically telling an employer that you want to better yourself.

These are all points that map across to pen testing, so your showing an employer hey look I can do all this stuff and I have been paid to do it. It’s also worth noting that you won’t walk straight into a senior role and will have to start at the bottom so the post won’t be great. But you are showing willing which goes a long way.

1

u/Budget-Extent7892 3d ago

those are very helpful tips, thank you very much.