Penetration Tester
Penetration testers run authorised attacks against an organisation's own systems to find the security weaknesses a real attacker would exploit.

- Median salary*
- $127,400
3.8%vs last year, before tax
- People employed
- 1,000
0.0%vs last year
- Projected growth*
- +18%
to 2035
- AI exposure*
- Low
- automation risk
- Average hours*
- 38/wk
−2h vs all jobs
- Shortage status*
- In shortage
national
Penetration testers work through networks, applications and infrastructure at an organisation's request, using the same techniques as an attacker to see what actually gives way. Unlike a cyber security analyst, who watches live systems for ongoing threats, a tester works to a defined scope and end date and then reports on what they found. Most work for consulting firms or in-house security teams, with the rest spread across banks, insurers, government and defence.
How much do penetration testers earn?
The median full-time salary for a penetration tester is $127,400 per annum, before tax, up $26,400 since 2018.
Consulting and contract work usually pays more than permanent in-house testing, and contract rates are quoted per day rather than per year. A security clearance opens government and defence work, which pays accordingly, and practical certifications such as OSCP or CREST are what move a tester up the bands. Pay also moves with how much of the job is client-facing consulting compared with internal testing.
What does a penetration tester do day to day?
The list below is what fills most weeks; the exact mix shifts with seniority and whatever stage the current work is at.
- Spending hours probing a system before one misconfiguration opens the way further in
- Reading source code, configuration files and architecture diagrams, which takes as long as actively attacking anything
- Chaining small weaknesses together to reach something an attacker would actually want, such as customer records or domain administrator access
- Writing a finding up so a non-technical executive understands what it means and what to do about it
- Retesting a fix to confirm the vulnerability is closed rather than just patched over
What skills do penetration testers need?
Employers look for cyber security, networks and systems administration, risk and internal controls, backed by Burp Suite fluency and strong problem solving.
Specialist skills
- Cyber security
- Networks and systems administration
- Risk and internal controls
- Regulatory compliance
- Data analysis
Software and tools
- Burp Suite
- Metasploit
- Nmap
- Wireshark
- Kali Linux
General skills
- Problem solving
- Written communication
- Attention to detail
Is the job growing?
About 1,000 people work as penetration testers in Australia, and employment is projected to grow 18% over the decade to 2035. That's healthy, above-average growth, and the role should stay in solid demand.
How do you become a penetration tester?
Here's the path most penetration testers take, step by step.
- 1Build an IT or security foundation
A bachelor degree in IT or cyber security is the most common path in, and about 38% of the people doing this work hold one. A diploma in networking or systems administration is a realistic alternative, particularly if you already work in IT.
- 2Practise on targets you are allowed to attack
Deliberately vulnerable labs and capture-the-flag platforms are where most testers learn the craft, using tools such as Burp Suite, Nmap and Metasploit. Employers ask about this practice in interviews, because it shows you can find things without a scanner telling you where to look.
- 3Add a practical certification
CompTIA Security+ or a similar entry certificate covers the fundamentals, and OSCP or CREST are the ones employers look for in testing roles specifically. These exams are hands-on, so study has to include time in a lab rather than reading alone.
- 4Start in a neighbouring role
Testing roles rarely go to people with no operational background. Cyber security analyst, systems administrator and network engineer work all build the knowledge of operating systems, networks and protocols that penetration testing depends on, and each is a reasonable first step.
- 5Get clearance if you want government and defence work
Many of the larger Australian testing contracts sit with government and defence clients, and those engagements require an AGSVA security clearance. It is obtained through an employer who sponsors it, so it often follows a first job rather than preceding it.
Ready to apply as a penetration tester?
Whether you're working toward becoming a penetration tester or already are one and want a hand with the next step (sharpening your resume for ATS screening, tightening your cover letter, or knowing what you'll actually be asked at interview), here are examples grounded in this specific role, not generic templates.
What jobs can a penetration tester move to?
Moving into Cyber Security Architect typically comes with the biggest pay rise, worth $7,800 a year more on average.
| Move to | Typical pay change | Overlap | Retraining |
|---|---|---|---|
| Cyber Security Architect Deep understanding of attack vectors informs the design of resilient security architectures. | +$7,800 | 52% | short course |
| Cyber Security Analyst A penetration tester's offensive mindset and vulnerability knowledge help detect and respond to threats as a security analyst. | +$600 | 79% | minimal |
| Cyber Security Engineer Hands-on exploitation experience translates into building and hardening defensive controls as a security engineer. | −$10,400 | 58% | short course |
| Cyber Security GRC Specialist Technical security expertise aids risk assessment and policy development as a grc specialist. | −$10,400 | 36% | reskill |
| IT Auditor Knowledge of system weaknesses supports assessing controls and compliance as an it auditor. | −$18,200 | 71% | minimal |
Moves are chosen from Jobs and Skills Australia's Data on Occupation Mobility, which follows income tax records between 2011-12 and 2020-21, together with entry requirements and skill overlap. A known move is one people were seen making in that data. Pay change compares median full-time pay for the two roles.
Who works as a penetration tester?
The typical penetration tester is 37 years old; 58% are men, 90% work full-time, and full-timers average 38 hours a week.
- 37
- Median age
- 42%
- Female share
- 90%
- Full-time
- −2h
- vs all-jobs avg
What's it like being a penetration tester?
The job alternates between long stretches of reading, reconnaissance and note-taking, and short bursts where something finally gives way. Engagements are time-boxed, so testers decide early where to dig deep and accept that they will not test everything in scope. It tends to suit people who enjoy taking systems apart to see how they work, and who can stay methodical when a day of probing produces nothing.
What people like
- The moment something gives way. A chain of small weaknesses that opens into a real foothold is the payoff the quiet hours are spent working towards, and it is what keeps most testers in the field.
- Every target is different. A web application, a hospital network and a bank's internal systems demand different techniques and tools, so the learning does not stop after the first few years.
- The report decides whether the work counted. A finding is only useful once it is understood and fixed, which makes clear writing and a good debrief as important as the technical result.
- Room to research. Outside scheduled engagements there is time for labs, new tooling and reading up on the vulnerabilities that are currently being exploited in the wild.
What people find hard
- Report writing takes up much of the week. On a short engagement, two or three days can go into the write-up, and a fair amount of it is restating findings and remediation advice that appeared in earlier reports.
- Scope limits what you can find. Clients cap the hours and rule systems out of scope, so testers regularly finish an engagement knowing there are areas they never got to look at.
- Findings get argued rather than fixed. Severity ratings are sometimes disputed by the team that owns the system, and remediation can sit on a backlog long after the report is signed off.
Based on our synthesis of professional-body surveys and public accounts of the role, not first-person verified reviews.
Which industries employ penetration testers?
Information Technology & Telecommunications employs the largest share of penetration testers, followed by Financial & Insurance Services.
Top employing industries
- 1Information Technology & Telecommunications
- 2Financial & Insurance Services
- 3Government Administration & Defence
- 4Professional Services & Consulting
Ranked by employment share; the source doesn't publish an exact percentage per industry.
| Bachelor degree | 38% | |
|---|---|---|
| Diploma / Advanced Diploma | 24% | |
| Certificate III/IV | 20% | |
| Postgraduate | 10% | |
| Other | 8% |
Will AI replace penetration testers?
Penetration testing is lightly exposed to AI overall. Scanners driven by machine learning already handle a share of reconnaissance and known-vulnerability checks, and language models can draft test plans and report sections from a tester's own notes. What keeps the exposure low is the exploitation path, where choosing which weaknesses to combine and how hard to push without disrupting a client's systems depends on experience.
Share of typical working time by exposure level
- Identifying and exploiting vulnerabilitiesWorking out that an expired certificate plus a forgotten admin endpoint adds up to a way in takes testing and curiosity that current tooling does not supply.30%low
- Scoping and reconnaissanceTools such as Nmap and automated scanners map a network quickly, but deciding which hosts and services are worth the remaining hours is still a human call.25%moderate
- Client scoping meetings and debriefsAgreeing rules of engagement before testing starts, and walking a client's engineers through what was found afterwards, depend on reading the room and answering questions on the spot.25%low
- Report writing and remediation adviceAI drafts a plausible finding from rough notes in seconds, and the tester then rewrites it so the wording lands with the executive who has to approve the fix.20%high
Common questions about becoming a penetration tester
Straight answers to the questions people ask most.
How much do penetration testers earn?
$127,400 per year before tax for full-time penetration testers. Contract and consulting work usually sits above permanent in-house roles, and a security clearance adds to what employers will pay. Certifications such as OSCP or CREST and a few years of engagements are what lift a tester through the bands.
How do you become a penetration tester?
Build a base in IT or networks first, then spend real time in deliberately vulnerable labs and earn a practical certification such as OSCP or CREST. Most people move across from a cyber security analyst, systems administrator or network engineer role rather than starting in testing straight from study. Hands-on proof matters more than the qualification on its own.
Are penetration testers in demand?
Penetration testers are currently in shortage nationally, and employment is projected to grow 18% over the decade to 2035 over the decade to 2035. It is a small occupation, with about 1,000 people working in it, so most openings sit with the consultancies and larger in-house security teams that run testing programs on a regular cycle. Experience in a related security or systems role is usually what gets an application past the first screen.
Will AI replace penetration testers?
Not the core of the job, though it is already changing parts of it. AI speeds up reconnaissance, scanning for known vulnerabilities and the first draft of a report, which used to be the slowest administrative work. Deciding how to chain individual weaknesses into a working attack path, and how far to push without disrupting a client's systems, still comes down to the tester.
Where can penetration testers move next?
Cyber security analyst is a close move, because the work overlaps heavily and pay is $600 more. Moving the other way into cyber security engineering suits testers who want to build and harden the defences they once probed, and pay there is $10,400 less. Some experienced testers eventually start their own testing practice or consultancy, which is often where earnings grow.
Do you need a degree to get into penetration testing?
No, but the technical base still has to come from somewhere. About 38% of the people in the role hold a bachelor degree, while others come through diplomas and years of systems or network administration. Employers look at what you can find in a lab and how well you write it up.
Related roles
- Cyber Security Analyst
- Cyber Security Engineer
- Cyber Security Architect
- IT Auditor
- Cyber Security GRC Specialist
- Cyber Security Analyst
Not sure this is you? Take the career quiz and get a ranked shortlist of roles that fit how you like to work.