๐ Why You Need to Know This
In 2023, a large Russian company, Positive Technologies, announced a recruitment for Junior Pentester positions. Out of 5 available positions, 1200 applications were received. Only 200 of them were valid, and only 30 had practical experience on HackTheBox and bug bounty platforms. Only 8 had at least 3 published write-ups.
All 5 hired candidates were from those 8.
Lesson: it's not about the diploma or years of experience. It's about demonstrable skills that allow HR and tech leads to be convinced that you are already doing it. This lesson is about how to properly "package" yourself to pass the selection process.
๐ What Makes a Pentester's Resume Different
๐ฏ In a Nutshell (30 seconds)
A typical IT resume includes education and work experience.
A pentest resume, on the other hand, focuses on portfolio: links to your HackTheBox account, bug bounty profile, write-ups, and CTF participation. These are verifiable proof of your skills.
A good pentester resume should include:
- Contacts + Summary โ 2-3 lines about who you are
- Skills โ specific tools: Burp Suite, nmap, Metasploit, sqlmap, hashcat
- Certifications โ OSCP / CPTS / CRTO + date of completion
- Portfolio โ the most important part: HTB profile, HackerOne profile, GitHub
- Write-ups โ links to 3-5 of your public write-ups
- Work Experience โ even non-security related (programmer, sysadmin, IT support)
- Education โ even without a diploma (courses, self-study)
๐ฏ What to Include in Your Portfolio
| What | Why |
| HackTheBox profile | Shows your rank and solved machines |
| HackerOne / Bugcrowd profile | Reputation and valid reports |
| GitHub | Your scripts, tools, and write-ups |
| Personal blog / Medium | Your technical articles |
| CTFtime.org | Participation in team CTFs |
| YouTube (optional) | Video write-ups of CTFs (a big plus) |
๐ LinkedIn โ The Main Channel in 2024
LinkedIn is the main channel for hiring in international companies. In Russia, it's growing.
๐ What Should Be on Your LinkedIn
- Headline: "Junior Penetration Tester | OSCP | HTB Pro Hacker" โ immediately visible who you are
- About: 3-5 sentences with keywords (pentest, OWASP, red team)
- Experience: even non-standard experience (participation in CTF, bug bounty finds)
- Skills: 20+ skills, ask friends to confirm (endorsements)
- Activity: respond to security posts, publish your write-ups 1-2 times a week
๐ข Where to Apply (for Russian speakers)
Russian companies:
- Positive Technologies โ the largest security company in Russia
- Group-IB / F.A.C.C.T. โ incident response, threat intel
- Bi.Zone โ security from Sber
- Kaspersky โ antivirus, research
- Solar Security โ SOC, monitoring
- Tinkoff / Yandex / VK / Sber โ internal security teams
Foreign companies (for remote work):
- Bishop Fox, NCC Group, Mandiant โ global pentest consulting
- Praetorian, Cobalt โ boutique pentest
- EPAM, Luxoft โ outsourcing with a security focus
- Y Combinator startups โ often hire junior security
๐ง Template for a Letter to a Recruiter
Cold email in 10 lines, specifics + links:
Subject: Junior Penetration Tester โ interested in a position at [Company]
Hello, [Name]!
I'm Ivan, a beginner pentester with a focus on web vulnerabilities.
Over the past year:
- Passed CPTS (HackTheBox)
- Solved 50+ machines on HackTheBox (rank: Pro Hacker)
- Found 3 valid bugs on bug bounty (HackerOne, reputation: 45)
- Maintaining a blog with write-ups of real cases โ [URL]
I saw an open position for Junior Pentester at [Company].
I'm ready for a technical screening at any convenient time.
Resume and portfolio: [URL]
HTB: [URL]
HackerOne: [URL]
Best regards, Ivan
๐ค Technical Interview โ Top 7 Questions
๐ What to Prepare For
- "Tell me about the last machine you hacked on HackTheBox" โ your story
- "Explain how SQL Injection works" โ in simple terms, like to a friend
- "What's the difference between XSS and CSRF" โ in simple terms
- "What is OWASP Top 10" โ name 3-5 from the list
- "Show me your pentest methodology" โ reconnaissance โ attack โ post-exploitation โ report
- "Practical" โ they'll give you a virtual machine, ask you to show how you'd start
- "What's the last thing you read in security" โ books, blogs, podcasts
๐ช Soft Skills Are Also Important
- Communication โ pentesters write a lot (reports) and explain to clients
- Curiousity โ they might ask "what would you try on such a stack" โ the desire to dig is important
- Responsibility โ pentest = sensitive data. NDA, ready to answer for actions?
- Willingness to Learn โ security changes quickly, need to constantly catch up
๐ First 3 Months on the Job
- Keep quiet and learn โ observe how seniors work
- Ask "dumb" questions โ while you're junior, it's allowed and encouraged
- Do your first pentest under the supervision of a senior
- Have a weekly 1-on-1 meeting with your mentor
- Maintain a personal knowledge base (Notion / Obsidian) โ record new experiences
๐ฐ Career Path and Salaries (Russia, 2024)
| Level | Experience | Salary |
| Junior | 0-2 years | 80-180 thousand โฝ/month |
| Middle | 2-4 years | 200-400 thousand โฝ/month |
| Senior | 4-6 years | 400-700 thousand โฝ/month |
| Lead / Principal | 6-10 years | 700 thousand โ 2 million โฝ/month |
| Own consulting / startup | โ | no ceiling |
๐ค Simple Test to Check Understanding
- What makes a pentest resume different from a regular IT resume? โ The focus on portfolio (HTB, bug bounty, write-ups), not education/experience
- Where should you "package" yourself for security? โ LinkedIn โ the main channel for hiring in the industry
- What are 5 companies in Russia for junior pentesters? โ Positive Technologies, Group-IB, Bi.Zone, Kaspersky, Solar Security
- What question do newbies typically "fail" on? โ "Tell me about the last machine you hacked" โ lack of specifics
- How long does it take to go from Junior to Senior? โ 4-6 years of active work
๐ You Can Skip This, But It's Interesting
Go to LinkedIn Jobs and search for "Junior Pentester" / "Junior Penetration Tester" / "Security Engineer Intern". Open 10 job postings, look at what skills and certifications are required. This is your next "shopping list" for learning.
๐ค Final Vibe-task
Open Claude and ask:
I've completed the "Hacking from Scratch. AI-powered" course.
Create a personal action plan for the next 12 months:
Months 1-2 โ basic practice:
- What to do every day?
- Which platforms?
- How many hours?
Months 3-6 โ first bug bounty payment or first job:
- What specific steps?
- What to learn?
Months 7-12 โ junior pentester position or $1k/month from bug bounty:
- What to specialize in?
- Which companies to apply to?
Let's compare results with this plan in a year.
Explain it like you would to a 10-year-old. No jargon.
๐ก Main Takeaways from the Lesson
๐ What to Take Away
- Pentest resume = portfolio: HTB, HackerOne, write-ups. Not a diploma.
- LinkedIn with the right headline (role + certifications + skills) โ the main channel.
- 5 companies in Russia to start with: Positive Technologies, Group-IB, Bi.Zone, Kaspersky, Solar Security.
- Cold email to a recruiter โ 10 lines, specifics + links.
- Junior salary in Russia: 80-180 thousand โฝ. Grows quickly with experience and certifications.
- First 3 months on the job: keep quiet, learn, ask questions, maintain a knowledge base.
๐ Final Thought
This course is 0% of your future career. 100% is what you'll do after.
Hacking is a marathon, not a sprint. Those who practice 2-4 hours a day become professionals in a year. Those who complete the course and give up forget everything in a year.
Good luck. Do it. Don't give up.
๐ Congratulations on Completing the Course!
What you now have:
- โ
Understanding of the basics โ ethics, law, career path
- โ
Linux, network protocols, web
- โ
Experience with SQL Injection, XSS, CSRF on DVWA
- โ
Knowledge of Burp Suite, Metasploit, hydra, sqlmap, hashcat
- โ
OSINT and social engineering recognition
- โ
A ready plan for bug bounty
- โ
A ready plan for your first job
Next โ practice. Every day. For a long time. Calmly.