Penetration Tester resume example

A resume for a Penetration Tester needs to show the work itself: evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Day to day that means work like this: assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters; collect stakeholder data to evaluate risk and to develop mitigation strategies. Recruiters and applicant tracking systems both read for the tasks and tools this role actually involves, so the strongest resume names them in your own experience rather than describing the job in the abstract. Below are the tasks O*NET records for this occupation, the software and tools it uses, the titles it is advertised under, and the skills worth naming if they are genuinely yours.

Also advertised as

The same job is posted under many titles. Searching only your own job title hides most of the openings you could apply to.

  • Cyber Engineer
  • IT Security Tester
  • Application Security Assessor
  • Application Security Hacker
  • Application Security Tester
  • Certified Hacker
  • Certified Tester
  • Consulting Advisory Tester
  • Cyber Assessment Tester
  • Cyber Assessor
  • Cyber Security Engineer
  • Cyber Security Tester
  • Cyber Tester
  • Cybersecurity Engineer
  • Embedded Tester
  • Forensic Analysis Tester
  • Hacker
  • Hardware Hacker

O*NET records 37 titles for this occupation in total.

What this work actually involves

Tasks recorded for this occupation, in O*NET's words. If your experience covers one of these, it belongs on your resume in your own words.

  • Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
  • Collect stakeholder data to evaluate risk and to develop mitigation strategies.
  • Conduct network and security system audits, using established criteria.
  • Configure information systems to incorporate principles of least functionality and least access.
  • Design security solutions to address known device vulnerabilities.
  • Develop and execute tests that simulate the techniques of known cyber threat actors.
  • Develop infiltration tests that exploit device vulnerabilities.
  • Develop presentations on threat intelligence.
  • Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
  • Discuss security solutions with information technology teams or management.
  • Document penetration test findings.
  • Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.

22 tasks are recorded in total; these are the most central.

Example bullets for this role

Built from this occupation's own tasks. The brackets stay empty on purpose: we will not invent a number for you, and a fabricated metric is the fastest way to lose an interview you had already won.

  • Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters, for [who or what it served], at [what volume].
  • Collect stakeholder data to evaluate risk and to develop mitigation strategies, for [who or what it served], at [what volume].
  • Conduct network and security system audits, using established criteria, for [who or what it served], at [what volume].
  • Configure information systems to incorporate principles of least functionality and least access, for [who or what it served], at [what volume].

Software used in this role

Recorded for this occupation by O*NET. An applicant tracking system matches the exact product name, so write the tool the way the posting writes it.

  • Amazon Web Services AWS software
  • Ansible software
  • Apple iOS
  • Apple macOS
  • Bash
  • C
  • C#
  • C++
  • Database management systems
  • Docker
  • Firewall software
  • Ghidra
  • GitHub
  • Go

68 software entries are recorded in total.

Skills an ATS reads for

Worth naming only if they are genuinely yours. Keyword overlap is one input to a resume's score, not a verdict.

  • AWS
  • Bash
  • C
  • C#
  • C++
  • Firewall
  • Ghidra
  • Hex-Rays IDA Pro
  • JavaScript
  • Kali Linux

What level this role is pitched at

O*NET places this occupation in “Considerable Preparation Needed”. Most of these occupations require a four-year bachelor's degree, but some do not.

A considerable amount of work-related skill, knowledge, or experience is needed for these occupations. For example, an accountant must complete four years of college and work for several years in accounting to be considered qualified.

Common questions

What does a Penetration Tester do?
Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Day to day that includes work like assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters and Collect stakeholder data to evaluate risk and to develop mitigation strategies.
What software should a Penetration Tester list?
Software recorded for this occupation includes Amazon Web Services AWS software, Ansible software, Apple iOS, Apple macOS, and Bash. Applicant tracking systems match on the exact product name, so write the tool as the posting writes it rather than describing it in general terms.
What other job titles cover Penetration Tester work?
O*NET records 37 titles for this occupation, including Cyber Engineer, IT Security Tester, Application Security Assessor, and Application Security Hacker. Searching only your own job title hides most of the openings you could apply to.
Will this resume pass an ATS for a Penetration Tester role?
No tool outside an employer can tell you how that employer's system is configured, including ours. What you can control is that the resume parses cleanly, names the work in the words the posting uses, and does not claim anything you cannot back up.

Related roles

Occupations O*NET records as closest to this one, and worth looking at if this search is not moving.

What this page cannot tell you

  • No tool outside an employer can tell you how that employer’s ATS is configured, including ours.
  • This page makes no claim about pay, demand or how many people hold this job. O*NET does not publish that here and we will not estimate it.
  • Keyword overlap is one input to a resume’s score, not a verdict on you. A resume that names skills you do not have is worse than one that names fewer.

If this is the job you are aiming at, the guide to tailoring a resume covers how to aim one posting properly, and building and exporting a resume here is free.

Occupation data from the O*NET 29.1 Database by the U.S. Department of Labor, Employment and Training Administration (USDOL/ETA), used under CC BY 4.0. O*NET is a trademark of USDOL/ETA. SpartanResume is not endorsed by USDOL/ETA.