How to become a penetration tester in 2026
Want to become a penetration tester but don't know where to start? A realistic roadmap: skills, certifications, portfolio and your first job — no fluff.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 19 July 2026
- READING TIME
- 12 min read
- TOPIC
- Careers and Certifications
“How do I become a hacker?” is a question countless people type into search, and the answers online are either shrouded in mystery or trying to sell a course for thousands. The truth is less dramatic and more encouraging: you can become a penetration tester (a legal, ethical hacker who tests security under contract) methodically, in a reasonable amount of time, and without any innate talent. This article is an honest roadmap: which skills you need, in what order to build them, which certifications actually matter, and what breaking into the market looks like in 2026.
Hacker or pentester? Let’s define terms
In everyday language “hacker” sounds like someone who breaks into systems. In professional practice that person is a penetration tester or offensive security specialist: they do exactly what an attacker does, but legally, under contract and within an agreed scope, and they hand the result over in a report so the company can patch. The difference isn’t in the techniques — it’s in authorisation and ethics. That distinction is the foundation of the whole profession and the first thing any employer will check.
Step 1: IT fundamentals (there’s no skipping this)
You can’t test the security of something you don’t understand. Before you think about “hacking”, you need a solid base:
- Operating systems — Linux above all (daily driver) and Windows (because that’s where most corporate targets live). The terminal has to stop being scary.
- Networking — the TCP/IP model, ports, DNS, HTTP, SMB. You need to understand how traffic flows before you try to abuse it.
- Basic scripting — Bash and a little Python, enough to automate the boring parts and modify other people’s tools.
This is the least “flashy” stage and therefore the most commonly skipped — and it’s exactly the missing fundamentals that trip up most self-taught learners. If you’re starting completely from zero, you can work through these fundamentals in order in BreachRoad Academy (more on that below).
Step 2: learn to think like an attacker
Techniques change; the mindset stays. It’s the habit of questioning assumptions (“what happens if I type something nobody expects here?”), systematic enumeration and patience. A good pentester isn’t the person who knows the most tricks — it’s the person who methodically checks everything in order and doesn’t give up when the first path fails.
At this stage you also meet the most common vulnerability classes — best viewed through the lens of the OWASP Top 10 for web applications, because web apps are the most common target for first engagements.
Step 3: practice, practice, practice
You learn security with your hands. Watching courses gives the illusion of progress; real progress comes from solving machines and breaking deliberately vulnerable apps on legal practice platforms. The starting rule: do machines yourself, without peeking at the solution, and only read the walkthrough afterwards to compare approaches.
The real internet is also a good, safe range — within the law. You can, for example, X-ray your own domain’s security with our free scanner and learn to read the result: headers, HTTPS, email configuration, file exposure. It shows what an “attack surface” looks like from the outside.
Step 4: certifications that actually count
A certificate won’t replace skills, but in hiring it opens doors — because it signals to an employer that you can do something in practice, not just read about it. The ones that matter early:
- OSCP — the gold standard entry ticket, a hands-on 24-hour exam. Demanding, but the most recognised. We cover how to prepare in a separate guide: How to prepare for OSCP from scratch.
- PNPT — a more “realistic” exam with a full attack chain and a report, highly regarded.
- eJPT / CPTS — gentler entry points, good as a first step before OSCP.
If you’re torn between them, our OSCP vs PNPT vs CPTS comparison helps. The order varies, but the principle is one: skills first, the certificate as their proof, not the other way around.
Step 5: build a visible portfolio
Employers want to see evidence, not declarations. A beginner pentester’s portfolio is usually:
- Public notes and write-ups from solved machines (respecting each platform’s rules).
- Your own blog or GitHub with simple scripts, technique notes, learning logs.
- CTF participation — great on a CV and genuinely educational.
- A professional profile (e.g. LinkedIn) that shows consistent growth.
It doesn’t have to be impressive from day one. It has to show a trajectory — that week by week, you know more.
Step 6: your first job (and realistic expectations)
You rarely walk in “off the street” straight into a pentester role. Common paths in:
- Junior pentester / security analyst — if you have OSCP and a portfolio.
- An adjacent role — sysadmin, helpdesk, developer, SOC — and a move into offensive security from there. Experience from “the other side” is priceless.
- Internships and bug bounty programs — legal, paid vulnerability hunting, great for building a name.
Let’s be honest: the first months are learning on the job and a good dose of humility. But the profession is in demand, well paid (we cover the ranges in a separate post: how much a pentester earns in Poland) and gives you something rare — real impact and constant learning.
How long it takes and what it costs
- Time: from zero to employable is usually 12 to 24 months of regular work. With an IT background — less.
- Money: you can start learning for free (material, legal platforms, our Academy). The real cost is mostly the certifications, once you’re ready to sit them.
The biggest “cost” is consistency. Calm daily work beats sprints.
Start with an ordered path — BreachRoad Academy
The biggest trap for self-taught learners is chaos: hundreds of tabs, random tutorials and no idea what comes after what. That’s why we built BreachRoad Academy — a free knowledge path into the profession, released one module at a time.
The “Pentester Path” takes you from zero: from a model for working safely with Kali Linux through terminal, system, and networking foundations to adversarial thinking, written cases, remediation, and detection. Every module ends with an automatically graded knowledge check, XP, and ranks; nothing needs to be downloaded or run.
Everything is free right now — you create an account, track your progress and come back whenever you want. It’s the simplest way to turn “I want to become a hacker” into a concrete, step-by-step plan you actually complete.
👉 Start the Pentester Path in BreachRoad Academy — free, at your own pace.
Summary
To become a pentester you don’t need talent or an expensive bootcamp — you need order and persistence. Build IT fundamentals, learn to think like an attacker, practise heavily on legal platforms, prove your skills with a certificate (OSCP leading the way), show a portfolio, and enter the market accepting that the start is learning. If you want to begin today with a ready plan instead of chaos, create a free BreachRoad Academy account.
Thinking about switching careers into cybersecurity? Get in touch — we’ll point you to a starting line for your situation.


