Cybersecurity

How to Become a Penetration Tester in India

September 19, 2026 ·10 min ·by Rudra Pratap Singh
How to Become a Penetration Tester in India

The working path is: networking and Linux fundamentals, then web fundamentals and hands-on OWASP exploitation, then network and Active Directory, then a public portfolio, then a certification if your target employers filter on one. Most people invert this by buying a certification first, which is why they finish courses without becoming employable.

The honest timeline

At twelve to fifteen hours a week, roughly twelve months to entry level employable. Faster with more hours. Not faster by skipping stages, because every stage depends on the one before it.

Stage 1: Fundamentals, months 1 to 3

Unskippable and the stage everyone rushes.

  • Networking. TCP handshake, DNS, HTTP, TLS, NAT, reading a packet capture
  • Linux. Permissions, processes, services, cron, file system layout, living in a terminal
  • Windows. Services, registry, users and groups, enough Active Directory concept to know what a domain is
  • Python. Enough to read and modify someone else's exploit

Checkpoint: build a home lab with a Linux and a Windows VM on a shared network and get them talking. If that took a frustrating week, that week was the lesson.

Stage 2: Web, months 4 to 6

Where most Indian entry level work actually sits, so highest return per hour.

  • How HTTP, cookies, sessions and authentication really work
  • OWASP Top 10, exploited by hand, not read
  • Burp Suite properly, Repeater and Intruder included
  • SQL injection and XSS until the patterns are automatic

Checkpoint: find and exploit a SQL injection and a stored XSS without a walkthrough.

Stage 3: Network and Active Directory, months 7 to 9

The part that separates a web tester from someone who can run an internal engagement, which is most of the Indian market.

  • Enumeration and service exploitation
  • Privilege escalation on both Linux and Windows, taken equally seriously
  • Domain enumeration, Kerberoasting, lateral movement
  • Pivoting into networks you cannot reach directly

Stage 4: Portfolio, months 10 to 12

This stage gets you hired and it is the one people skip in favour of another course.

A candidate with three well documented writeups and no certification consistently outperforms one with a certification and nothing to show. Specifics in projects that get you interviews.

Minimum: three technical writeups, one full penetration test report, a documented home lab, one small tool you wrote, and an ATS ready resume per the resume guide.

Stage 5: Certification, only if it buys access

Open twenty real job listings for the roles you want and count which certifications appear. If one shows in more than half, it is buying you access. If it shows in three, it is not.

Comparisons: OSCP vs CEH, is OSCP worth it, and cost against realistic impact in certifications ranked by ROI.

Getting the first role

What worksWhat does not
Boutique security consultanciesApplying only to large brands
Internships, even short or unpaidWaiting until you feel ready
Public writeups and disclosuresA private GitHub with forked repos
A resume built for the ATSA designed two column PDF
Applying while still learningCollecting one more course first

Boutique consultancies hire on demonstrated skill far more readily than large firms. That is where most people's first offer actually comes from.

The India specific advantage

A large share of demand here is compliance driven under CERT-In, RBI and SEBI requirements, so hiring is steadier than most engineering roles. Detail in CERT-In VAPT requirements. The trade-off is that a meaningful part of the work is repetitive checklist testing.

Remote hiring has also flattened the city premium. A tester in a tier two city working remotely for a metro product company earns metro compensation at local cost of living.

What to skip

  • Buying a certification first, the most expensive common mistake
  • Collecting courses instead of finishing one project
  • Memorising forty tools with no methodology
  • Waiting to feel ready, interviews are the fastest feedback loop available

Start free

Every stage above needs a lab, not a video. Hacklido is free with a progression path from zero.

Frequently asked questions

How long does it take to become a penetration tester in India?

Around twelve months at twelve to fifteen hours a week to reach entry level employability, assuming you build a portfolio rather than only completing courses.

Do I need a computer science degree?

No. It helps with HR screening at large firms, but boutique consultancies and product companies hire on demonstrated ability.

Which certification should I get first?

None, until you can do the work. Then check twenty real listings for your target roles and buy the one that actually appears in them.

Can I get a pentesting job as a fresher?

Yes, most commonly at a boutique consultancy, and the portfolio has to do the work the experience would have.

Is penetration testing a stable career in India?

Unusually so, because much of the demand is regulatory rather than discretionary and does not disappear in a downturn.

See the full VAPT syllabus

Live instructor led training, hands on labs and a verifiable certificate. Or start free on Hacklido before paying anyone.

See the full VAPT syllabus

Keep reading