Pentester (Offensive Security)
A pentester tests the security of systems and applications within an authorised framework and explains to the business which vulnerabilities need to be addressed.
Written by Romain PichouPublished on Updated on
Pentester: hiring for this role?
First candidates presented within three weeks.
Definition and scope
A pentester, or penetration tester, is an offensive cybersecurity specialist who looks for and exploits vulnerabilities within an authorised scope. Their penetration tests help the business understand the risks its systems face and the fixes it should consider. Their work includes technical investigations and explaining the results to those responsible for making decisions or taking action.
The assigned scope may cover systems, networks and web or mobile applications. It must be defined before testing begins: the environments concerned, objectives, constraints and expected deliverables. The ability to work in one of these areas does not establish expertise in all the others.
Authorisation to test sets the limits of the engagement. When a component is discovered outside this scope, the pentester explains its significance to the risk owner. The risk owner may decide to extend the test or retain the original scope. In the latter case, this limitation must appear in the test conclusions. The tester does not decide on this extension alone.
Pentester, technical security auditor and developer: who does what?
- The pentester carries out the agreed penetration tests and reports the vulnerabilities, risks and recommendations.
- The technical security auditor covers a wider range of assessments, which may include configuration or code reviews. Not all of this work is necessarily part of a pentester's role.
- During relevant application tests, the developer receives guidance on coding practices to improve. The pentester provides useful findings without taking over from the organisation responsible for remediation.
Why this hire matters
A penetration test should help the business decide which vulnerabilities to address and how. A list of flaws offers little value if it does not explain the risks, the systems affected and possible solutions. The value of the work therefore also depends on analysis and reporting, beyond the technical discovery itself.
The organisation remains responsible for assessing risk and deciding on remediation. The pentester may not know every way a system is used or the business consequences of exploiting a vulnerability. Their rating must be discussed with the relevant people in charge. This discussion serves to assess the risk to the business, not to play down an uncomfortable finding.
For bespoke software and web applications, the results should give developers feedback on coding practices to improve. Plan reporting that connects each problem to the technical details needed to understand it. Discussions with IT teams help turn recommendations into possible fixes, whose implementation the organisation then decides on.
Hypothetical example: a business commissions a test of an application used by several departments. The report describes a vulnerability and proposes a fix. Before a priority is set, the application owner explains how the application is used and what exploiting the vulnerability could mean for those activities. The pentester provides the technical explanation needed for this decision, while internal managers organise remediation.
A poorly matched candidate can make this reporting more difficult: expertise that does not fit the environment being tested, conclusions that are hard to understand or poorly explained limits to the engagement. To define the recruitment requirements, connect each requirement to a situation the role involves. Network expertise should not be taken as evidence of proficiency with mobile applications. Similarly, look for the ability to report in a way that suits the report's recipients, rather than simply proficiency with tools.
Salaries 2025-2026
| Level and experience | Annual gross base |
|---|---|
| Junior0-2 years | 42–50 k€ |
| Experienced2-5 years | 52–70 k€ |
| Senior5-8 years | 70–95 k€ |
| Lead / Red team8+ years | 95–130 k€ |
Paris market ranges, 2025-2026.
Outside the Paris region, expect 10 to 20 % less.
Key missions
- Agree with the commissioning party which systems to test, the objectives, constraints and expected deliverables.
- Prepare investigation scenarios suited to the environments and authorised actions.
- Look for and exploit vulnerabilities within the agreed limits.
- Document the tests carried out and the technical findings obtained.
- Analyse the vulnerabilities discovered and the risks they pose to the activities concerned.
- Propose fixes and explain their objectives to IT teams.
- Present the conclusions in a report suited to its recipients.
- Flag components outside the scope and refer any proposed extensions to the risk owner.
Skills
Technical skills
- Operating systems: understand the security mechanisms of the environment being tested.
- Networks and protocols: analyse services and communications to guide investigations.
- Applications: understand how the assigned web or mobile applications work and the vulnerabilities relevant to them.
- Penetration testing methods: develop scenarios consistent with the objectives and the limits of the authorisation.
- Scripting: write scripts to automate network tasks and vulnerability checks, as Nmap’s NSE engine allows, without making this tool a requirement for every role.
- Risk analysis: connect technical findings to possible impacts and potential fixes.
- Technical awareness: keep up with vulnerabilities and attack techniques relevant to the environments being tested.
Expected qualities
- Rigour: document an approach whose findings and conclusions remain understandable.
- Ethical conduct: respect the agreed limits and request a decision when they need to change.
- Clarity: adapt technical explanations to the recipients’ work and knowledge.
- Teamwork: discuss findings and recommendations with IT contacts to clarify them.
- Ability to synthesise information: highlight the risks relevant to decision-making in a readable report.
Common stack
Background and training
IT education pathways at French bac +3 to bac +5 level, with a specialisation in cybersecurity, are reference points described by ANSSI for technical security auditing. They do not establish a mandatory qualification for every pentester role.
A relevant pathway should develop an understanding of operating systems, networks and applications, followed by the ability to apply this knowledge in an investigation. The knowledge and skills acquired also cover conducting tests and analysing results.
The École 2600 framework includes a simulated technical audit, a detailed report and a presentation to experts. However, it covers a broader field than pentesting alone.
A certification alone does not guarantee the autonomy needed to carry out an engagement from start to finish.
Hiring this profile
When to hire
Consider hiring when penetration testing is a recurring need and you can define the environments the future employee will work on. Start by naming the systems, networks or applications concerned, then the expected results. This description helps you look for expertise suited to the planned work, without requiring every offensive cybersecurity specialism.
Next, specify the autonomy required. A role may involve carrying out tests within an established framework, or also preparing scenarios and reporting. Identify the person who can support the pentester, examine their conclusions and decide on an extension of scope. If this support is missing, make an explicit decision about putting it in place before finalising the candidate profile.
Also prepare your organisation to receive and review the findings. Appoint a technical contact who is available during testing and the people responsible for examining the recommendations. The hire must fit into a way of working where someone can assess risks and decide on remediation. Discovering a vulnerability does not, by itself, resolve how it should be addressed.
For a targeted test, an external team may be an appropriate option. Examine its expertise in the systems concerned, particularly when they are unusual, and keep an internal contact available. The choice between hiring and a one-off engagement then depends on how often the work recurs, the expertise needed and the support you can arrange. If your need mainly involves code or configuration reviews, specify a technical security audit engagement instead.
Career path
A pentester can deepen their expertise in the environments they test or broaden the assessments they conduct. Systems, networks and applications offer distinct technical fields. To plan progression, specify the new environments they will work on and the skills to develop, rather than automatically linking length of service to responsibility.
Another route is to take part in red team exercises, then develop their scenarios or oversee how those scenarios are carried out as skills develop. Engagements can also extend to a purple team approach intended to train incident detection teams. These developments require an understanding of the exercise's objectives and the limits of the engagement.
Technical security auditing also offers a broader framework, with activities such as configuration or code reviews. This broader remit builds on additional skills. It does not represent automatic progression into security leadership.
How to assess this profile
The common foundations of GetPro's assessment approach
GetPro uses a search criteria matrix that prioritises the requirements of the role and assigns an assessment method to each. It distinguishes aspects of a candidate's background that can be verified from skills to explore further at interview. Open questions and concrete examples are used to examine the key criteria. Reference checks complement this analysis by placing skills in the context of a past working relationship.
Adapting the assessment approach to a pentester role
The steps below suggest an adaptation for this role. They do not describe a specific protocol used by GetPro. You can adapt them to the environments and responsibilities of the position, particularly when designing a practical exercise.
1. Define criteria linked to the expected work
Separate essential skills from specialisms that are useful only for certain engagements. Name the systems to be tested, the expected deliverables and the decisions the candidate will need to refer to a person in charge.
Build a short assessment matrix around technical understanding, the investigative approach, respect for the agreed framework and reporting. For each criterion, distinguish what the candidate does independently from what requires support.
Treat a precise explanation of the environments they know well as a positive sign. Probe answers that claim universal expertise without corresponding examples of work.
2. Examine a past piece of work
Ask the candidate to describe an engagement whose details they can share without breaching their commitments. Have them specify the objectives, authorised limits, their own work and the conclusions delivered.
Ask about a choice of scenario and a difficulty they encountered. Ask what they were able to conclude, what remained uncertain and how this limitation appeared in the report.
Look for a clear distinction between tool output, an analysed finding and an explained risk. A string of tool names without a rationale for the approach calls for further questions.
3. Set an authorised practical exercise
Prepare an exercise representative of the role in an environment explicitly intended for assessment. Provide the objectives, permitted actions and expected deliverables before starting.
Hypothetical example: you give the candidate findings from a test application and ask them to prepare a short presentation of the results. Ask them to distinguish established findings from the information needed to assess their impact.
Ask for an explanation of their priorities and a report extract. Observe the consistency between the available evidence, the conclusions drawn and the recommendations.
Value the ability to recognise missing information. Treat a categorical conclusion that the candidate cannot connect to the evidence in the exercise as a warning sign.
4. Assess communication and autonomy
Ask for two explanations of the same finding: one for a technical contact, the other for a business manager. Assess how much precision is retained when the vocabulary becomes more accessible.
Then present the discovery of a component outside the scope. Look for a response that explains the problem and seeks a decision before any extension of testing.
If the role includes leading an engagement, ask the candidate to explain how they would allocate the work and prepare the reporting. Limit this criterion to the responsibilities actually envisaged.
5. Arrange technical input and reference checks
If your business does not have the necessary expertise, have the exercise and report examined by a specialist in the environments concerned. Ask HR to assess mutual expectations and working conditions.
With the candidate's agreement, use references to clarify the responsibilities they actually held. Ask about autonomy, report quality and communication with teams.
Compare this information with your interview observations. Document the skills established, remaining uncertainties and planned support before deciding.
Frequently asked questions
Can a vulnerability scanner replace a pentester?
No, not for the entire investigation. Automated checks do not offer the same depth or coverage as manual testing. To compare the two, specify the questions you expect to answer and the investigations required. A scanner result can complement the pentester’s work without replacing analysis of the findings.
Is a pentest the same as a red team exercise?
No. A pentest looks for vulnerabilities within a defined technical scope. A red team exercise simulates an attack to test, among other things, the organisation’s detection and response. The engagements can overlap. In your request, specify whether you are mainly looking for technical flaws or an assessment of how your defences respond.
Can a pentester test a service hosted by a third party?
Yes, subject to the applicable conditions and permissions. Check the provider’s policy for the services concerned before defining the tests. AWS, for example, allows certain tests on a list of services without prior agreement, but requires approval for activities involving command and control (C2). This policy does not apply to all hosting providers.
Does a pentest that finds no vulnerabilities guarantee the system is secure?
No. This result must be considered alongside the scope, date, available information and time spent testing. An investigation conducted without knowledge of the internal workings may leave vulnerabilities undiscovered within the allotted time. To interpret a report with no findings, therefore, ask what was examined and what limitations remain.
How should you read the pentester salary table?
The table in this profile presents gross annual fixed pay in euros for a Paris-centred market in France over the 2025-2026 period. It distinguishes levels and indicators of experience. Total remuneration figures are not provided: do not interpret this omission as an absence of variable pay. To compare an offer, separate fixed pay from the other components and examine the intended responsibilities.
Sources and method
- ANSSI : Panorama des métiers de la cybersécurité, édition 2020
- NCSC : Penetration testing
- NCSC : Vulnerability scanning tools and services
- France compétences / École 2600 : Expert de la sécurité des données, des réseaux et des systèmes (RNCP42335)
- AWS : Penetration Testing
- Nmap Project : Nmap: the Network Mapper
- PortSwigger : Burp Proxy
- Nmap Project : Chapter 9. Nmap Scripting Engine
Related job profiles
- CISO (Chief Information Security Officer)The CISO leads information systems security and helps management decide on actions to protect business activities and data.
- DevOps EngineerA DevOps engineer automates application delivery and environment management to help technical teams deploy and operate their services.
- SRE (Site Reliability Engineer)Guarantees the reliability, availability and performance of production systems with a software engineering approach.
- Software engineerA software engineer designs, develops and improves software to meet users’ needs and the company’s constraints.
About the author

Co-CEO
Romain Pichou a cofondé GetPro en 2015 avec Émile Pennes. Diplômé de l'ESCP Business School, il a débuté sa carrière dans des entreprises technologiques en forte croissance (Winamax, Betclic, Lucca où il dirigeait les ventes de la suite SaaS RH, puis ContentSquare).
Chez GetPro, il est l'associé référent des recrutements Tech, IA et Produit : CTO, VP Engineering, Head of Data, direction produit. Il intervient sur les mandats de direction technique, du cadrage du besoin à l'évaluation des candidats.