Penetration Tester

Penetration Tester is described by 20 tasks that reveal what counts as part of the role and when to escalate. The practical steps are written for quick learning and practice. Each one shows where we found it, and comes with an AI prompt you can copy and use straight away.

20evidenced tasks
20ready prompts
9tools of the trade
15-1299.04O*NET-SOC code
435,370hold this job (US, BLS 2025)
$116,580median pay/yr (US)
Open Penetration Tester in the interactive atlas →

What it pays

Government survey numbers — not estimates, not ads.

Half of all Computer Occupations, All Other in the U.S. earn more than $116,580 a year — the middle 80% land between $55,940 and $188,470. About 435,370 people in the U.S. do this work. Figures are for the U.S. occupation group “Computer Occupations, All Other”. (U.S. Bureau of Labor Statistics survey, published 2025.) In India, Professionals earn about ₹38,298 a month on average — around ₹4.6 lakh a year (government PLFS survey via ILOSTAT, occupation-family figure).
$116,580typical pay / year
435,370people in this work
$188,470+top 10% earn
₹4.6 lakha year in India (family avg)
Think you get this job?Six quick questions on how it really works — with a hint and the reason behind every answer.
Test yourself →

The work, task by task

These are the real jobs-to-be-done, not a wish list. Each task shows where we found it, and the prompt underneath is written for that exact task.

Convincing2

Simulate cyberattacks to evaluate security

+
Plan and execute a red-team simulation of likely attacker paths against the corporate web portal and VPN,…
Plan and execute a red-team simulation of likely attacker paths against the corporate web portal and VPN, document each exploit attempt, evidence collected, and impact on confidentiality and availability, then hand results to the SOC with mitigations within three working days.
The tools that do the workDockerjob descriptionsO*NETWikipedia

Perform security vulnerability assessments

+
Run an automated vulnerability scan across the external IP range and the main application stack, validate…
Run an automated vulnerability scan across the external IP range and the main application stack, validate high and critical findings manually, produce a ranked remediation list with proof-of-concept notes and suggested fixes for the ops team by Monday.
The tools that do the workBashESCOjob descriptionsO*NET
The daily work15

Perform penetration tests

+
Conduct time-boxed penetration testing of the public-facing APIs and authentication flows, attempt privilege…
Conduct time-boxed penetration testing of the public-facing APIs and authentication flows, attempt privilege escalation and lateral movement, capture steps and artifacts for each successful access and deliver a priority action list to the CTO within 48 hours.
The tools that do the workC++ESCOO*NETWikipedia

Collect stakeholder data to evaluate risk and to develop mitigation strategies.

+
Collect contact lists, system owners, network diagrams, authentication flows and recent incident summaries…
Collect contact lists, system owners, network diagrams, authentication flows and recent incident summaries from Lisa in IT ops and Marcus in risk, then map stakeholder influence and exposure so I can prioritise attack surface testing by Wednesday.
The tools that do the workGitHubO*NET

Configure information systems to incorporate principles of least functionality and least access.

+
Harden the web and API environments: lock down service ports, remove unused daemons, enforce role-based…
Harden the web and API environments: lock down service ports, remove unused daemons, enforce role-based accounts and minimal permissions for service accounts across production and staging before the next deployment window on Friday.
The tools that do the workAnsibleO*NET

Develop presentations on threat intelligence.

+
Draft a 12-slide briefing for the CISO and three business unit heads summarising current threat actors,…
Draft a 12-slide briefing for the CISO and three business unit heads summarising current threat actors, notable indicators from last quarter, likely attack paths against our critical assets, and three prioritized mitigation actions for the next 90 days.
The tools that do the workGitHubO*NET

Update corporate policies to improve cyber security.

+
Rewrite the acceptable use and remote access sections in the corporate cyber policy to require multi-factor…
Rewrite the acceptable use and remote access sections in the corporate cyber policy to require multi-factor authentication, restrict lateral admin privileges, and mandate quarterly privileged access reviews, then send to legal and HR for sign-off by Friday.
The tools that do the workGitHubO*NET

Document findings and generate detailed reports

+
Compile the test evidence, risk ratings, exploited vectors and reproducible steps into a technical report,…
Compile the test evidence, risk ratings, exploited vectors and reproducible steps into a technical report, include a one-page executive summary and an appendix with remediation tickets, then publish to the security team and ops by close of business Tuesday.
The tools that do the workGitHubjob descriptions

Recommend security improvements based on test results

+
Produce a prioritized remediation plan listing code fixes, configuration changes and compensating controls…
Produce a prioritized remediation plan listing code fixes, configuration changes and compensating controls tied to each finding, estimate effort and risk reduction, and assign owners so IT ops can start fixes next sprint planning on Monday.
The tools that do the workAnsiblejob descriptions

Identify ICT system weaknesses

+
Run a focused assessment of the corporate network and web applications to list exploitable misconfigurations,…
Run a focused assessment of the corporate network and web applications to list exploitable misconfigurations, weak credentials, unpatched services, and privileged access paths, prioritise findings by business impact, and draft remediation steps for the IT manager by Wednesday.
The tools that do the workBashDockerESCOsee the evidence ↗

Tools for ICT test automation

+
Build an automated test suite that runs credentialed scans, fuzzing against public endpoints, and privilege…
Build an automated test suite that runs credentialed scans, fuzzing against public endpoints, and privilege escalation checks on a schedule, store results with diffs, and fail the pipeline when new critical exposures appear so security ops get alerted.
The tools that do the workGitHubAnsibleESCOsee the evidence ↗

Perform follow-up tests to verify remediation

+
Run the retest plan against the fixed web app and the patched API endpoints, confirm the original SQL…
Run the retest plan against the fixed web app and the patched API endpoints, confirm the original SQL injection and auth bypass are closed, capture exploit attempts with logs, and email Caroline in ops with evidence and a revised risk score by Wednesday.
The tools that do the workBashjob descriptions

Support testing in cloud and virtualized environments

+
Provision isolated ephemeral instances and the same application stack used in production, deploy the test…
Provision isolated ephemeral instances and the same application stack used in production, deploy the test harness and simulated users, then run the cloud-focused attack scenarios against the virtual network while recording network flows for the infrastructure team.
The tools that do the workDockerAmazon Web Services AWSjob descriptions

Determine target systems for testing

+
Compile the target inventory from the asset register and live scans, prioritise internet-facing services,…
Compile the target inventory from the asset register and live scans, prioritise internet-facing services, admin panels and third-party integrations, and hand the shortlisted systems to Mike in client IT with justification and test windows.
The tools that do the workGitHubWikipedia
N

Attain specific testing goals

+
Translate the statement of work into measurable testing objectives: show where privilege escalation is…
Translate the statement of work into measurable testing objectives: show where privilege escalation is possible, prove data exfiltration paths, and validate MFA bypass resistance, then map each objective to a test case and share with the engagement PM.
The tools that do the workGoWikipedia

Identify ICT security risks

+
Run threat modelling workshops with the app owners to list assets, likely attackers, attack paths and…
Run threat modelling workshops with the app owners to list assets, likely attackers, attack paths and business impact, then produce a ranked risk register and send it to Sarah in security for remediation planning.
The tools that do the workC#ESCOsee the evidence ↗

Analyse the context of an organisation

+
Interview the CTO and ops leads, review network diagrams and supplier contracts, map technology, data flows…
Interview the CTO and ops leads, review network diagrams and supplier contracts, map technology, data flows and trust boundaries, then produce a contextual assessment that shows where testing will cause business impact and where extra approvals are needed.
The tools that do the workIBM TerraformESCOsee the evidence ↗
Protecting2

Assess potential for unauthorized access

+
Assess the likelihood of unauthorized access by reviewing access logs, misconfigurations, and default…
Assess the likelihood of unauthorized access by reviewing access logs, misconfigurations, and default accounts on critical servers, demonstrate at least one plausible attack chain and recommend immediate mitigations for the identity team by end of day tomorrow.
The tools that do the workGitHubjob descriptionsO*NETWikipedia

Identify vulnerabilities in computer systems

+
Run a focused attack campaign against the corporate Windows and Linux hosts used by Finance and HR this week,…
Run a focused attack campaign against the corporate Windows and Linux hosts used by Finance and HR this week, document every exploited weakness, the exact exploit steps, and the business impact so the CISO can prioritise fixes by next Tuesday.
The tools that do the workBashESCOO*NETWikipedia
Analysing1

Analyze network traffic and security protocols

+
Capture and analyse a full day of ingress and egress traffic across the London office gateway, map protocol…
Capture and analyse a full day of ingress and egress traffic across the London office gateway, map protocol use and anomalous sessions, identify weak or misconfigured crypto and authentication flows, and hand a remediation brief to the network team on Friday.
The tools that do the workGojob descriptionsO*NET

Says who?

These are the pages we read to build this. Open any of them and check us.

Activities this job lives in

The human activities behind the tasks — each with its honest AI ceiling.

The logs, files & records this job keeps

Shared with other careers — the same record means something different in each.

Related careers

Same family of work — each with its own tasks and prompts.

The LLOS Work Atlas is the world's largest evidenced task library — a map of human work, with a ready prompt behind every task. 1,774 careers · every task named by the sources that witnessed it — O*NET, ESCO, real job descriptions, Wikipedia — and the deepest tasks by several at once. And it is honest about limits: where AI cannot help, the map says so.

The rest of the map

Same library, five ways in.

Copyright © LLOS.ai · 2026 — original pedagogy, voice, and design — all rights reserved.
Built on public evidence: O*NET®, ESCO, Wikipedia, U.S. Bureau of Labor Statistics, ILOSTAT. All sources & licenses