How to Become a Penetration Tester in India
The working path is: networking and Linux fundamentals, then web fundamentals and hands-on OWASP exploitation, then network and Active Directory, then a public portfolio, then a certification if your target employers filter on one. Most people invert this by buying a certification first, which is why they finish courses without becoming employable.
The honest timeline
At twelve to fifteen hours a week, roughly twelve months to entry level employable. Faster with more hours. Not faster by skipping stages, because every stage depends on the one before it.
Stage 1: Fundamentals, months 1 to 3
Unskippable and the stage everyone rushes.
- Networking. TCP handshake, DNS, HTTP, TLS, NAT, reading a packet capture
- Linux. Permissions, processes, services, cron, file system layout, living in a terminal
- Windows. Services, registry, users and groups, enough Active Directory concept to know what a domain is
- Python. Enough to read and modify someone else's exploit
Checkpoint: build a home lab with a Linux and a Windows VM on a shared network and get them talking. If that took a frustrating week, that week was the lesson.
Stage 2: Web, months 4 to 6
Where most Indian entry level work actually sits, so highest return per hour.
- How HTTP, cookies, sessions and authentication really work
- OWASP Top 10, exploited by hand, not read
- Burp Suite properly, Repeater and Intruder included
- SQL injection and XSS until the patterns are automatic
Checkpoint: find and exploit a SQL injection and a stored XSS without a walkthrough.
Stage 3: Network and Active Directory, months 7 to 9
The part that separates a web tester from someone who can run an internal engagement, which is most of the Indian market.
- Enumeration and service exploitation
- Privilege escalation on both Linux and Windows, taken equally seriously
- Domain enumeration, Kerberoasting, lateral movement
- Pivoting into networks you cannot reach directly
Stage 4: Portfolio, months 10 to 12
This stage gets you hired and it is the one people skip in favour of another course.
A candidate with three well documented writeups and no certification consistently outperforms one with a certification and nothing to show. Specifics in projects that get you interviews.
Minimum: three technical writeups, one full penetration test report, a documented home lab, one small tool you wrote, and an ATS ready resume per the resume guide.
Stage 5: Certification, only if it buys access
Open twenty real job listings for the roles you want and count which certifications appear. If one shows in more than half, it is buying you access. If it shows in three, it is not.
Comparisons: OSCP vs CEH, is OSCP worth it, and cost against realistic impact in certifications ranked by ROI.
Getting the first role
| What works | What does not |
|---|---|
| Boutique security consultancies | Applying only to large brands |
| Internships, even short or unpaid | Waiting until you feel ready |
| Public writeups and disclosures | A private GitHub with forked repos |
| A resume built for the ATS | A designed two column PDF |
| Applying while still learning | Collecting one more course first |
Boutique consultancies hire on demonstrated skill far more readily than large firms. That is where most people's first offer actually comes from.
The India specific advantage
A large share of demand here is compliance driven under CERT-In, RBI and SEBI requirements, so hiring is steadier than most engineering roles. Detail in CERT-In VAPT requirements. The trade-off is that a meaningful part of the work is repetitive checklist testing.
Remote hiring has also flattened the city premium. A tester in a tier two city working remotely for a metro product company earns metro compensation at local cost of living.
What to skip
- Buying a certification first, the most expensive common mistake
- Collecting courses instead of finishing one project
- Memorising forty tools with no methodology
- Waiting to feel ready, interviews are the fastest feedback loop available
Start free
Every stage above needs a lab, not a video. Hacklido is free with a progression path from zero.
Frequently asked questions
How long does it take to become a penetration tester in India?
Around twelve months at twelve to fifteen hours a week to reach entry level employability, assuming you build a portfolio rather than only completing courses.
Do I need a computer science degree?
No. It helps with HR screening at large firms, but boutique consultancies and product companies hire on demonstrated ability.
Which certification should I get first?
None, until you can do the work. Then check twenty real listings for your target roles and buy the one that actually appears in them.
Can I get a pentesting job as a fresher?
Yes, most commonly at a boutique consultancy, and the portfolio has to do the work the experience would have.
Is penetration testing a stable career in India?
Unusually so, because much of the demand is regulatory rather than discretionary and does not disappear in a downturn.
See the full VAPT syllabus
Live instructor led training, hands on labs and a verifiable certificate. Or start free on Hacklido before paying anyone.
See the full VAPT syllabus