Skip to content
careertips

Home IT & Software

Penetration Tester

Penetration testers run authorised attacks against an organisation's own systems to find the security weaknesses a real attacker would exploit.

Illustration of a person working as a penetration tester
Median salary*
$127,400

3.8%vs last year, before tax

People employed
1,000

0.0%vs last year

Projected growth*
+18%

to 2035

AI exposure*
Low
automation risk
Average hours*
38/wk

−2h vs all jobs

Shortage status*
In shortage

national

Penetration testers work through networks, applications and infrastructure at an organisation's request, using the same techniques as an attacker to see what actually gives way. Unlike a cyber security analyst, who watches live systems for ongoing threats, a tester works to a defined scope and end date and then reports on what they found. Most work for consulting firms or in-house security teams, with the rest spread across banks, insurers, government and defence.

How much do penetration testers earn?

The median full-time salary for a penetration tester is $127,400 per annum, before tax, up $26,400 since 2018.

Consulting and contract work usually pays more than permanent in-house testing, and contract rates are quoted per day rather than per year. A security clearance opens government and defence work, which pays accordingly, and practical certifications such as OSCP or CREST are what move a tester up the bands. Pay also moves with how much of the job is client-facing consulting compared with internal testing.

Median annual salary, 2018–2028
Salaries rose $26,400 a year to 2024; the dashed line shows a projection to 2028 based on the real ABS Wage Price Index growth rate, not a role-specific forecast.
Full penetration tester salary breakdown →

What does a penetration tester do day to day?

The list below is what fills most weeks; the exact mix shifts with seniority and whatever stage the current work is at.

  • Spending hours probing a system before one misconfiguration opens the way further in
  • Reading source code, configuration files and architecture diagrams, which takes as long as actively attacking anything
  • Chaining small weaknesses together to reach something an attacker would actually want, such as customer records or domain administrator access
  • Writing a finding up so a non-technical executive understands what it means and what to do about it
  • Retesting a fix to confirm the vulnerability is closed rather than just patched over

What skills do penetration testers need?

Employers look for cyber security, networks and systems administration, risk and internal controls, backed by Burp Suite fluency and strong problem solving.

Specialist skills

  • Cyber security
  • Networks and systems administration
  • Risk and internal controls
  • Regulatory compliance
  • Data analysis

Software and tools

  • Burp Suite
  • Metasploit
  • Nmap
  • Wireshark
  • Kali Linux

General skills

  • Problem solving
  • Written communication
  • Attention to detail

Is the job growing?

About 1,000 people work as penetration testers in Australia, and employment is projected to grow 18% over the decade to 2035. That's healthy, above-average growth, and the role should stay in solid demand.

Employment, 2015–2024, projected to 2035
Employment grew 100 to 2024; the dashed line shows the official projection to 2035.

How do you become a penetration tester?

Here's the path most penetration testers take, step by step.

  1. 1
    Build an IT or security foundation

    A bachelor degree in IT or cyber security is the most common path in, and about 38% of the people doing this work hold one. A diploma in networking or systems administration is a realistic alternative, particularly if you already work in IT.

  2. 2
    Practise on targets you are allowed to attack

    Deliberately vulnerable labs and capture-the-flag platforms are where most testers learn the craft, using tools such as Burp Suite, Nmap and Metasploit. Employers ask about this practice in interviews, because it shows you can find things without a scanner telling you where to look.

  3. 3
    Add a practical certification

    CompTIA Security+ or a similar entry certificate covers the fundamentals, and OSCP or CREST are the ones employers look for in testing roles specifically. These exams are hands-on, so study has to include time in a lab rather than reading alone.

  4. 4
    Start in a neighbouring role

    Testing roles rarely go to people with no operational background. Cyber security analyst, systems administrator and network engineer work all build the knowledge of operating systems, networks and protocols that penetration testing depends on, and each is a reasonable first step.

  5. 5
    Get clearance if you want government and defence work

    Many of the larger Australian testing contracts sit with government and defence clients, and those engagements require an AGSVA security clearance. It is obtained through an employer who sponsors it, so it often follows a first job rather than preceding it.

Ready to apply as a penetration tester?

Whether you're working toward becoming a penetration tester or already are one and want a hand with the next step (sharpening your resume for ATS screening, tightening your cover letter, or knowing what you'll actually be asked at interview), here are examples grounded in this specific role, not generic templates.

What jobs can a penetration tester move to?

Moving into Cyber Security Architect typically comes with the biggest pay rise, worth $7,800 a year more on average.

Move toTypical pay changeOverlapRetraining
Cyber Security Architect

Deep understanding of attack vectors informs the design of resilient security architectures.

+$7,800
52%short course
Cyber Security Analyst

A penetration tester's offensive mindset and vulnerability knowledge help detect and respond to threats as a security analyst.

+$600
79%minimal
Cyber Security Engineer

Hands-on exploitation experience translates into building and hardening defensive controls as a security engineer.

$10,400
58%short course
Cyber Security GRC Specialist

Technical security expertise aids risk assessment and policy development as a grc specialist.

$10,400
36%reskill
IT Auditor

Knowledge of system weaknesses supports assessing controls and compliance as an it auditor.

$18,200
71%minimal

Moves are chosen from Jobs and Skills Australia's Data on Occupation Mobility, which follows income tax records between 2011-12 and 2020-21, together with entry requirements and skill overlap. A known move is one people were seen making in that data. Pay change compares median full-time pay for the two roles.

Who works as a penetration tester?

The typical penetration tester is 37 years old; 58% are men, 90% work full-time, and full-timers average 38 hours a week.

37
Median age
42%
Female share
90%
Full-time
−2h
vs all-jobs avg

What's it like being a penetration tester?

The job alternates between long stretches of reading, reconnaissance and note-taking, and short bursts where something finally gives way. Engagements are time-boxed, so testers decide early where to dig deep and accept that they will not test everything in scope. It tends to suit people who enjoy taking systems apart to see how they work, and who can stay methodical when a day of probing produces nothing.

What people like

  • The moment something gives way. A chain of small weaknesses that opens into a real foothold is the payoff the quiet hours are spent working towards, and it is what keeps most testers in the field.
  • Every target is different. A web application, a hospital network and a bank's internal systems demand different techniques and tools, so the learning does not stop after the first few years.
  • The report decides whether the work counted. A finding is only useful once it is understood and fixed, which makes clear writing and a good debrief as important as the technical result.
  • Room to research. Outside scheduled engagements there is time for labs, new tooling and reading up on the vulnerabilities that are currently being exploited in the wild.

What people find hard

  • Report writing takes up much of the week. On a short engagement, two or three days can go into the write-up, and a fair amount of it is restating findings and remediation advice that appeared in earlier reports.
  • Scope limits what you can find. Clients cap the hours and rule systems out of scope, so testers regularly finish an engagement knowing there are areas they never got to look at.
  • Findings get argued rather than fixed. Severity ratings are sometimes disputed by the team that owns the system, and remediation can sit on a backlog long after the report is signed off.

Based on our synthesis of professional-body surveys and public accounts of the role, not first-person verified reviews.

Which industries employ penetration testers?

Information Technology & Telecommunications employs the largest share of penetration testers, followed by Financial & Insurance Services.

Top employing industries

  1. 1Information Technology & Telecommunications
  2. 2Financial & Insurance Services
  3. 3Government Administration & Defence
  4. 4Professional Services & Consulting

Ranked by employment share; the source doesn't publish an exact percentage per industry.

Highest qualification held
Bachelor degree
38%
Diploma / Advanced Diploma
24%
Certificate III/IV
20%
Postgraduate
10%
Other
8%

Will AI replace penetration testers?

Penetration testing is lightly exposed to AI overall. Scanners driven by machine learning already handle a share of reconnaissance and known-vulnerability checks, and language models can draft test plans and report sections from a tester's own notes. What keeps the exposure low is the exploitation path, where choosing which weaknesses to combine and how hard to push without disrupting a client's systems depends on experience.

high · 20%
moderate · 25%
low · 55%

Share of typical working time by exposure level

  • Identifying and exploiting vulnerabilities
    Working out that an expired certificate plus a forgotten admin endpoint adds up to a way in takes testing and curiosity that current tooling does not supply.
    30%
    low
  • Scoping and reconnaissance
    Tools such as Nmap and automated scanners map a network quickly, but deciding which hosts and services are worth the remaining hours is still a human call.
    25%
    moderate
  • Client scoping meetings and debriefs
    Agreeing rules of engagement before testing starts, and walking a client's engineers through what was found afterwards, depend on reading the room and answering questions on the spot.
    25%
    low
  • Report writing and remediation advice
    AI drafts a plausible finding from rough notes in seconds, and the tester then rewrites it so the wording lands with the executive who has to approve the fix.
    20%
    high

Common questions about becoming a penetration tester

Straight answers to the questions people ask most.

How much do penetration testers earn?

$127,400 per year before tax for full-time penetration testers. Contract and consulting work usually sits above permanent in-house roles, and a security clearance adds to what employers will pay. Certifications such as OSCP or CREST and a few years of engagements are what lift a tester through the bands.

How do you become a penetration tester?

Build a base in IT or networks first, then spend real time in deliberately vulnerable labs and earn a practical certification such as OSCP or CREST. Most people move across from a cyber security analyst, systems administrator or network engineer role rather than starting in testing straight from study. Hands-on proof matters more than the qualification on its own.

Are penetration testers in demand?

Penetration testers are currently in shortage nationally, and employment is projected to grow 18% over the decade to 2035 over the decade to 2035. It is a small occupation, with about 1,000 people working in it, so most openings sit with the consultancies and larger in-house security teams that run testing programs on a regular cycle. Experience in a related security or systems role is usually what gets an application past the first screen.

Will AI replace penetration testers?

Not the core of the job, though it is already changing parts of it. AI speeds up reconnaissance, scanning for known vulnerabilities and the first draft of a report, which used to be the slowest administrative work. Deciding how to chain individual weaknesses into a working attack path, and how far to push without disrupting a client's systems, still comes down to the tester.

Where can penetration testers move next?

Cyber security analyst is a close move, because the work overlaps heavily and pay is $600 more. Moving the other way into cyber security engineering suits testers who want to build and harden the defences they once probed, and pay there is $10,400 less. Some experienced testers eventually start their own testing practice or consultancy, which is often where earnings grow.

Do you need a degree to get into penetration testing?

No, but the technical base still has to come from somewhere. About 38% of the people in the role hold a bachelor degree, while others come through diplomas and years of systems or network administration. Employers look at what you can find in a lab and how well you write it up.

Related roles

Not sure this is you? Take the career quiz and get a ranked shortlist of roles that fit how you like to work.

careertips is an independent, data-first guide to Australian careers, built to help you understand what a role actually pays and where it can take you, not to sell you something.

Where available, figures are sourced from Jobs and Skills Australia and the Australian Bureau of Statistics (CC BY 4.0). Figures marked * are our own analysis. How we source and label our data. Last updated 2026-09-01.