Do you need certs/a degree to get a pentesting job?

tl;dw; No, we don't think so, but they don't hurt.


I get not everyone wants to sit through a 20minute video so the main points we hit besides just the title question:

  • Certs are becoming more valuable and more asked for as time goes on
  • Certs are generally not necessary outside of some specific regulatory reasons
    • ex, CISSP and CEH
  • OSCP teaches methodology but is very much an entry level cert
  • Degrees are not necessary
    • Requirement is that you have the skill
    • They provide a foundation that you might struggle to build later

That said, its a general discussion between three of us who have worked across several parts of the industry. We discuss the impact formal qualifications have when trying to break into the offensive side of the security industry and is not something that can just be summed up in a few points.

  • Droogie: More than 10 years as a security consultant
  • Myself (zi): Magician -> Software Engineer -> Security Consultant -> Vulnerability Researcher
  • Specter: An independent researcher, mostly known for his work on the PS4
/r/cybersecurity Thread Link - youtu.be