Penetration Tester CV Example for 2026
Updated 23 June 2026
A strong penetration tester CV shows the reader what you tested, the boundaries you worked within and what happened after you reported the findings. This guide covers the structure, evidence and wording that help authorised testing work stand up to scrutiny, without turning the CV into a list of tools or exposing sensitive client information.
Penetration Tester CV examples
Junior Penetration Tester
JuniorJunior penetration tester with hands-on experience of authorised web application, network and Active Directory testing through a graduate role, university projects and a security placement. Confident using Linux, Burp Suite, Nmap and Python to investigate weaknesses, validate findings and write clear remediation advice for technical teams.
Why it works: This example turns a short employment history into credible evidence by showing authorised testing scope, technical method, validated findings and measurable reporting outcomes.
Penetration Tester
Mid-levelPenetration Tester with four years of experience delivering owner-authorised web application, network and infrastructure assessments. Has completed 46 client engagements, validated findings before reporting and translated technical weaknesses into clear risks and practical remediation advice for technical teams and managers.
Why it works: This mid-level example connects hands-on testing with defensible engagement figures, clear reporting and practical remediation advice.
Senior Penetration Tester
SeniorSenior penetration tester with nine years of experience delivering authorised web application, infrastructure and Active Directory assessments. Leads complex client engagements from scoping and technical validation through to reporting, turning security flaws into practical remediation priorities for engineers and executives.
Why it works: Shows technical depth, engagement leadership, defensible scale and clear communication of security risk to technical and executive audiences.
How to write a penetration tester CV
Use a clean, reverse-chronological layout with plain section headings and consistent dates. Two pages will suit many applicants, but relevance matters more than squeezing or padding the document to meet an arbitrary limit. Start with your name and contact details, then add a personal statement, skills, relevant certifications, professional experience and education. Candidates without much paid experience can place a clearly labelled projects section above employment, provided each project explains its scope, method and outcome.
| Section | Include | Leave out |
|---|---|---|
| Header | Name, UK location, mobile, email and professional profile URL | Photo, date of birth and full street address |
| Personal statement | Current level, testing focus and two pieces of evidence | Generic enthusiasm and claims you cannot prove |
| Experience | Authorised scope, actions, validated findings, reporting and outcomes | Confidential targets, credentials or client details |
| Skills | Methods, environments, scripting and tools you can discuss confidently | Products you have merely tried once |
| Education and certifications | Exact award, institution or issuer, and completion date | Unfinished training presented as completed |
| Projects and extras | Relevant labs, utilities, publications or volunteering | Unexplained links and unrelated interests |
Open with evidence
Keep the personal statement to three or four lines. State your present level, the kinds of assessment you have completed and the evidence that makes your application worth reading. Useful evidence can include the number of authorised engagements completed, systems or endpoints assessed, validated findings, time taken to reach a defined test objective, reports delivered or a script you wrote. Figures must come from records you can defend. A junior applicant can use supervised projects, labs and transferable technical work. An experienced tester should lead with engagement scale, judgement, reporting quality and client impact.
Make the experience section easy to assess
For each position, provide the employer, title, location and dates, followed by focused achievement bullets. Show the engagement story: how the scope was agreed, what environment you assessed, what you did, how you checked the findings and what action followed. Penetration testing work can cover authorised tests of systems, networks, infrastructure, websites, and web or mobile applications. It can also involve identifying vulnerabilities and compliance issues, reporting their risk, recommending remediation and presenting conclusions to technical or senior audiences.
Five or six concise bullets can work better than a dense paragraph when a position contains enough substantial evidence. Give earlier or less relevant jobs fewer bullets. Write in plain language before adding technical terms; the reader should not need to decode a wall of acronyms to understand the result.
Group skills by purpose rather than creating a keyword strip. Possible categories include testing methods, operating systems, networking, scripting and reporting. Python and PowerShell can be relevant, as can work across macOS, Windows and Linux. Entry-level evidence may cover Linux command-line work; TCP/IP, DNS, routing, firewalls and packet-level traffic; Windows and Active Directory; web application testing; or network testing. Mention individual tools only where your experience shows how you used them.
Tailor the CV to each vacancy by using relevant language from the job description naturally. Do not copy whole passages. If the advert stresses communication with executives, use a genuine example of translating a technical flaw into business impact and remediation priorities. If it stresses web testing, move the most relevant engagement evidence nearer the top.
Personal statement examples
Penetration tester with three years' experience delivering owner-authorised web application and network assessments. Completed 28 engagements, validated findings before reporting and translated technical flaws into clear business risks and remediation priorities. Built a Python reporting utility that reduced evidence-preparation time by 30%, and regularly briefed technical teams and senior stakeholders.
Hard-working cybersecurity professional seeking an exciting penetration testing position. I know lots of security tools, learn quickly and can find weaknesses in any system. I am passionate about technology and work well alone or as part of a team.
Writing your experience
A useful experience bullet joins an action, a defined scope and a result. Start with what you did, identify the environment or engagement boundary, then state the defensible outcome. Numbers are helpful when they explain scale or improvement: engagements completed, systems assessed, findings validated, false positives removed, reports delivered, remediation agreed, retests closed or preparation time saved. Use only figures supported by your own records, and remove details that could identify a client or expose a target.
Penetration testers carry out authorised tests that simulate attacks against systems, networks, infrastructure and internet sites. They may agree testing requirements with clients, plan remote assessments of networks and applications, identify vulnerabilities or security gaps, validate findings, assign risk and recommend remediation. The experience section should make this accountable process visible. A list of exploits or scanner names does not show whether you understood the scope, checked the output or communicated the result.
| Before | After |
|---|---|
| Used security tools to find vulnerabilities. | Assessed 18 authorised web application endpoints, manually validated 11 findings and removed four scanner false positives before reporting. |
| Wrote penetration test reports for clients. | Produced 14 client reports that ranked verified issues by risk and set out remediation steps; technical owners accepted 92% of recommendations at first review. |
| Helped with network testing. | Scoped and tested a 120-host internal network, documented two privilege-escalation paths and supported a retest that closed 9 of 10 agreed findings. |
The revised bullets reveal scale, judgement and outcome. They also distinguish a completed assessment from running an automated scan. When you created a method, script or tool, explain the problem it solved. "Built a Python evidence parser that reduced report preparation from 90 to 55 minutes across 12 engagements" tells the reader far more than "Proficient in Python".
Use direct verbs that fit the work: assessed, scoped, enumerated, tested, validated, reproduced, documented, prioritised, automated, briefed and advised. Use "led" only when you genuinely directed the engagement or team. Senior bullets can cover setting scope, reviewing finding accuracy, explaining business consequences or presenting risk to executives. Junior bullets can be just as credible when they specify supervised scope, careful validation and a measurable contribution.
Keep most bullets to one or two lines. If several clauses obscure the result, split the point or remove incidental detail. A reader should be able to identify the scope, your action and the outcome in one pass.
Key skills & ATS keywords
Hard skills
Soft skills
ATS keywords
Education & certifications
List education in reverse-chronological order with the institution, exact awarded qualification, field and completion year. Do not turn a broad eligibility phrase into the title of a degree, and never present unfinished study as an awarded qualification. A recent graduate can add relevant modules, a final project or a carefully defined lab result. An experienced candidate can usually reduce older education to one line unless it remains closely connected to the vacancy.
The available role evidence does not establish a universal degree, GCSE profile, apprenticeship, licence or certificate for entry into penetration testing. Present your actual route without implying that every applicant needs the same one. Use the official title shown on the award, name the institution or issuer and distinguish completed study from training in progress. When space is tight, retain material that supports the vacancy and remove unrelated short courses.
Relevant penetration-testing certifications can have a separate section, especially when the job description asks for them. A credential records an assessment or learning route; practical evidence should appear elsewhere. Link the entry indirectly to experience or project bullets showing authorised engagement scope, validated findings, a defined test objective or a tool you wrote. This lets the reader see what you can do as well as what you studied. Never estimate engagement totals or outcomes.
Within the UK CHECK qualification assessment route, CESG's IT Health Check Service includes CHECK Team Member. It also includes CHECK Team Leader, with infrastructure and web-application routes. These details describe that particular route; they do not mean either qualification applies to every penetration tester vacancy. If you hold one, reproduce the credential and applicable route as they appear on your records, for example CHECK Team Leader with the infrastructure route rather than an ambiguous generic level.
A compact entry normally needs the qualification, issuer and year. Label an unfinished credential as "in progress" and add an expected completion date only when you have a firm date. Logos, copied syllabus text and unexplained strings of post-nominals take space away from useful evidence.
Common mistakes to avoid
Listing tools without showing what happened during an authorised engagement.
Connect each relevant tool to scope and outcome, such as systems tested, findings validated, time saved by a script or remediation accepted. Use only figures you can defend.
Describing testing as unrestricted hacking or leaving authorisation unclear.
Use precise wording such as "owner-authorised testing" and state the agreed target or engagement scope.
Reporting vulnerability counts without explaining severity, accuracy or business effect.
Show how you validated findings, assessed risk and explained the likely effect on a business function.
Writing dense paragraphs that bury the technical evidence.
Use concise achievement bullets covering engagement scope, the tested stack, relevant methods and the resulting report or remediation advice.
Sending the same penetration tester CV for every vacancy.
Match truthful experience and skills to the job description's language, giving the most relevant testing work the greatest prominence.
Making unsupported claims about qualifications, tools or results.
Name only credentials you hold, tools you have used and figures you can substantiate. A lab result should be labelled as lab or project work, not presented as client experience.
Junior vs senior: what changes
| Aspect | Junior | Senior |
|---|---|---|
| Evidence base | Lead with authorised labs, coursework, projects and transferable technical work, clearly labelled by context. | Lead with a sustained record of client engagements, varied target environments and defensible outcomes at scale. |
| Testing scope | Show sound fundamentals in a defined area such as networks, web applications or Active Directory. | Show ownership of complex scopes across systems, networks, infrastructure and applications, including decisions about testing depth and coverage. |
| Technical contribution | Demonstrate careful use of established tools, manual checks and basic scripting. | Show how custom methods, scripts or tools improved testing quality, repeatability or delivery. |
| Reporting | Prove that findings were validated and written with clear risk and remediation notes. | Show responsibility for report quality, conclusions and communication with technical teams, management and executives. |
| Client responsibility | Emphasise following scope, recording evidence and escalating uncertainties. | Emphasise defining requirements with clients, managing sensitive engagements and advising on practical risk reduction. |
| Achievement metrics | Use modest, verifiable measures such as lab scope, scripts written, services enumerated or report turnaround. | Use defensible measures such as engagements led, systems tested, critical findings validated, delivery time reduced or remediation progress. |
Frequently asked questions
For most applicants, one or two pages is enough. Keep the most relevant authorised testing, technical skills and evidence near the top; remove repetitive tool lists and old detail that does not support the vacancy.
Use clearly labelled labs, coursework, personal projects and transferable IT work. Describe the authorised scope, method and result, but never present practice environments as client engagements.
No. A British-style CV normally does not include a photo or date of birth; use the space for contact details, a focused personal statement and relevant evidence.
No. Include tools you can discuss confidently and connect them to a real task, such as scanning, manual web testing, vulnerability validation or reporting.
Include a role-specific qualification when you hold one and it is relevant to the vacancy. Do not let a credential replace evidence of authorised testing, validated findings and clear reporting.
Translate previous work into relevant evidence: network administration can demonstrate protocol knowledge, development can support code and web testing, and client-facing work can support scoping and presentation. Keep the claims precise and explain where the testing experience came from.