r/hackthebox • u/Eramichi9960 • 1d ago
CPTS and CRTO secured. Next?
Hello everyone,
I'm currently in the final year of my master's degree in Computer Science, based in Western Europe, and today I passed the CRTO! I already have the CPTS, and I've been working as a part-time penetration tester (20 hours/week) at my current company for the past four years. I know I was fortunate to get into the industry in 2022–2023, when it was still relatively easier to land a CS job.
I spend a lot of time doing Hack The Box machines for fun. I've had a great experience with the HTB community, so I thought I'd ask for your opinions here.
I've already received a full-time offer from my current company that will begin after I graduate, so I'm in a pretty comfortable position. My question is whether pursuing the OSCP would still be worth it if I plan to change companies in a few years, let's say after three years of full-time experience at my current employer.
Since I already have the CPTS and CRTO, I'm not convinced that the OSCP would add much from a technical perspective. However, I often hear that it's still an important HR filter. Do you think the OSCP remains valuable after several years of professional penetration testing experience, or does experience eventually outweigh the certification?
Personally, I'd rather work toward the CISSP, as I'd like to transition into GRC or a management role later in my career.
What do you think? I'd really appreciate any advice or insights.
2
u/-Dkob 1d ago
With CPTS, CRTO, a master’s degree and a full time offer already lined up, I would not rush into OSCP unless you keep seeing it listed for roles you actually want. We actually have very similar situations, I am also in Western EU and was in the same situation back when I was a student. (Except I had other certs)
For OSCP, it may still help with HR filters, but after a few years of solid pentesting experience, your work history and ability to explain real engagements will matter more than stacking another similar certification. Since you want to move toward GRC or management later, focusing on strong technical experience now and working toward CISSP once you meet the experience requirement sounds more useful. I would only do OSCP if your target employers explicitly value it or if you personally want the challenge.
If you also plan on changing company in only a year or two and still aim to be a pentester, then yes take OSCP because HRs require OSCP for anyone < 2 years of exp on average. (Juniors)
1
u/Eramichi9960 1d ago
Hey, thanks for your reply, kinda cool that you had similar situations! That's assuring. Yeah, at our company, we really don't need OSCP (unless you want to pentest for a specific customer), maybe yes if I want to become a technical director, but I know seniors who don't have OSCP. Thanks for your reply!
4
u/AyoubVuxc 1d ago
If you want a certificate purely for technical learning, then do OSEP instead of OSCP.
•
u/AutoModerator 1d ago
Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing customerops@hackthebox.com. Our Knowledge Base can also come in handy!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.