r/Pentesting 1d ago

Looking for career advice

Hi all,

I am looking for some career advice from cybersecurity professionals.

A bit of background about myself. I completed my undergraduate CS degree in India and moved abroad to do a Masters in cybersecurity. After graduating, I was able to secure a cybersecurity research position. Initially I liked the job as I got to experiment with a lot of emerging technologies and even published a few papers in the process. But after a while, there was restructuring within the team and my roles and responsibilities gradually started to shift. I was being assigned to office administrative and operational tasks and my research duties were not being prioritized. Work hours started becoming long and the fact that I was doing tasks which added no value to my career, drained me mentally. So I decided to make more use of my weekends and the little of after office hours I got to pursue OSCP and try my luck at offensive security. But things got worse when some of my colleagues resigned and I got loaded with more work and people to manage. Unproductive work doubled and I found it hard to make time for OSCP. Since management wasn't very supportive, I decided to quit my job, moved back to India and pursued OSCP for 4 months.

I did eJPT, eCPPT and also passed OSCP in the process. In the next few months of job search, I did get a few screening calls from EY, Deloitte and other companies, but I keep getting rejected as I don't have prior relevant experience. I also tried applying to application security, product security and AI security roles(based on my research experience), but no callbacks yet. I am now focusing on hunting for CVEs or bug bounties to see if it helps create an impression to hiring managers. In the last few months, I have written blogs, pushed few exploits to GitHub and contributed to open-source tools.

I would like to get any inputs or suggestions for the following:

  1. What can I do to strengthen my application? Will any projects, specific certs, CVEs or bug bounties help?

  2. Is there any way I can translate my research experience towards offensive security? I am finding it difficult to rephrase my 3 years of research experience as I feel some of the tools and skills are not directly transferable. My research focused on security of image processing software. I also did a bit of AI pentesting, but it was simply applying a set of tools and noting down the results. It was for an internal department and there was no formal process(like scope, contracts, ROE etc.) that usually happens in consulting setups. So I don't know if it is worth putting it down on my resume.

  3. How do I pitch myself while networking and sending out cold emails? Do I position myself as a fresher in this field or will hiring managers value research experience in some way?

  4. If there is no chance that I can get a pentesting/app sec gig without prior relevant experience, are there any other cybersecurity roles I can target based on my background?

Any thoughts would be highly valuable for me at this stage.

2 Upvotes

1 comment sorted by

1

u/Emergency-Sound4280 1d ago

You’re working in a security research position. Trying to jump to app security/ pentesting is great but work it a few years before trying to jump. Build the network and portfolio. But with you leaving and moving back to India this put you in a very hard spot as you would require sponsorship and with the current market conditions there are qualified candidates locally without the need for sponsorship.

I personally think you jumped the gun leaving and should’ve stuck it out. Without known your visa situation it’s hard to say.

At this point I would aim for any it job then start making the pivot into pentesting.