

My first offensive security job
TLDR. If you are looking for an offensive security job, go to a pen testing company first, one that engages with many different types of clients.
When I first joined EY as a pentester, that was my very first offensive security job. Honestly I did not expect much from it, because I only applied for one job and I had one interview, and I just got it.
There was no technical exam. It was just interviews. I interviewed with HR, and then I interviewed with the partner that was leading the team. I think they liked me.
Why professional services, and not finance
Cyber security was always the plan. What I wanted was professional services, because I wanted to open up my horizons first. I didn't want to go into finance right away, because that would get me stuck in finance. By joining EY I was able to serve multiple different clients.
Before I started pen testing I thought it was exactly what I thought it to be, because I was already doing CTFs and competitions even before working. So I knew what I was getting into. I just didn't expect that it was super heavy on web.
The first three months
For the first three months my main job was really web testing with Burp Suite, and mobile pen testing. Of course there were other tools involved, but most of the time I'd be in Burp Suite trying to do business logic attacks, and the OWASP Top 10 attacks like file inclusion and command injection.
This was pre-AI. It was really a lot of trying and testing. Yes, there was automated testing by Burp Suite, but this was really very basic.
What surprised me most in the first week was that they didn't throw me into my own engagement right away. They were trying to help me at first. They let me do retests. That means a vulnerability that has been found before, and the client has fixed it. Once the vulnerability has been fixed, you need to do a retest.
So I was trying to recreate vulnerabilities for attack vectors that were found by my teammates. That was fun. Eventually I got more comfortable with that, and then they started giving me my own engagements, where I handled all of it.
What an engagement actually looks like
It really varies, from web applications to mobile applications to doing scanning on certain endpoints.
For a typical engagement there'll be one manager, and depending on the size of it there'll be one senior and one junior. What happens day to day is you come in and you have a checklist of attacks, and typically you'll go through the checklist. It also depends on how thorough you can be. Ideally we're as thorough as possible.
I really love finding vulnerabilities, so I'd try a lot of creative ways, following the checklist but also going beyond it. That's how I was finding attacks that weren't very typical.
The tools I lived in were really Burp Suite and Kali Linux, and nmap for enumeration.
The first finding I was excited about
The first real finding I was really excited about was an admin page that was supposed to be hidden. It was the admin page for the client's network server, which they did not close. And the password that was there was a very basic password. So I managed to get in.
What university gave me, and what it didn't
University taught me the basics, but it didn't give enough practice of what offensive security actually was, or the breadth of it.
I never did mobile testing in university. I had to learn how to proxy the connections from a mobile phone to my local computer so that I could test like that. Testing APKs and mobile apps statically, which I'd never learned before.
University did give me a lot of preparation. But most of the preparation I had was really from CTFs, just by being curious and playing around with things.
The reports
For pen testing I'd say it's eighty-twenty. Eighty percent is trying to find the vulnerabilities, twenty percent is writing them up.
At the start I was having difficulty, because I wasn't following the format that they wanted. That was the thing I got wrong repeatedly: the formatting of how they wanted things. I really had to refer to people's previous reports so that I could copy what they liked. After a while it just got easier.
The people
The people who taught me were really my seniors and my manager. But at the same time I was learning a lot by reading and by practising. I basically completed the entire PortSwigger Web Security Academy and all of the labs, so that I knew exactly what I was trying to do.
The team was very generous. They were willing to help out.

One of the really good things about it was that they celebrate things like birthdays and events. There was something happening every month.

Certs
I was already working on the OSCP right away, because even before I came into the company I told them I wanted to be part of a red team eventually. There was also a 2,000 bonus every month for people holding OSCP, so it was really highly incentivised to take it.
I studied for about six months. I did all of the homework so that I could get the extra five points, and I studied in the mornings. That meant waking up at 4am and studying from four until six before going to work. That was the discipline it took, and it kept my evenings for myself.
I was definitely weakest at Active Directory. That was the first time I had really been exposed to it.
I did almost a hundred boxes to prepare, on Hack The Box and on Offensive Security's own machines. What OSCP really hones is reconnaissance. It is about finding information, and then knowing how to use the information you found.
I passed on 14 June 2022.

Take it if you want to go deep into the offensive security route. It is one of the first genuinely practical exams you will sit.
There are certs you take just so that you can pass the HR filter, and there are certs you take for the fun and the learning of the actual job. OSCP was really fun to take, because it was very practical.
After OSCP I got the CREST certificate, and CRTP for red teaming.
Doing too good a job
On one project I had two very strong findings. One was a privilege escalation from a normal user to an admin user. On the same engagement I found a public facing IP address on the client's network with a very weak password on it.
Because of those findings the engagement stalled. There were too many strong findings for it to carry on as planned, and I was told indirectly that I had done too good a job.
It is my job to find those things. But I got the feeling that the client would not engage us again, because we had been too strict in our reports. That is a very funny feeling to have in offensive security. If you do too good a job, you may not get the business next time.
What breaking software teaches you about building it
What I think after breaking software is that people rarely think about security. People bolt on security after it has been built.
I don't want to say lazy. Maybe not lazy. Cyber security is just not the main thing they think about when they're trying to build something. That's why it's important for people like me to come in and check.
Takeaways
If you are looking for your first security job, go to a professional consulting service. You get exposed to many different types of clients, and many different types of attacks, straight away.
It is a lot of fun, but be prepared for the work. A lot of it is study in your own time, and do not expect your seniors and managers to spoon feed you. It is independent learning.
I was looking for something exciting. I did not really care about the money, I was looking for experiences.
And on day one I would tell myself this: integrate cyber security into building an application, from the start.
Filed under security, career. If any of this is wrong, or you have hit the same thing, tell me.
Published 11 September 2026.