Information Security

Penetration Testing

Former hackers make the best security executives because they think like attackers, not defenders. This hands-on technical foundation creates CISOs who understand real threats and can translate complex vulnerabilities into board-level business risk.

L1 – L9 · 9 tours Leads to: CISO → What's a Reference DRS?

The Career Arc

Rotational · L1–L3

Build the Penetration Testing craft. Prove you can wield the tools of Information Security.

  • L1 : Learn penetration testing fundamentals
  • L2 : Conduct assessments under guidance
  • L3 : Own assessments end-to-end

Transformational · L4–L7

Deliver Penetration Testing outcomes — each Information Security tour at this altitude has a defined mission and success criteria.

  • L4 : Lead complex assessments and mentor team
  • L5 : Develop testing methodology and capability
  • L6 : Own offensive security program
  • L7 : Shape offensive security vision and adversary simulation strategy

Manage a Team?

Great Penetration Testing managers are practitioners first. The Information Security IC responsibilities in L4–L7 are your foundation — your management responsibilities are additive:

  • Hire security professionals who can communicate risk to non-technical leaders
  • Build a culture where security is everyone's job—not just your team's
  • Run 1:1s that develop both technical depth and executive presence
  • Give feedback that balances paranoia with pragmatism—security enables, not blocks
  • Remove blockers—fight for budget, tools, and a seat at leadership tables

Foundational · L8–L9

Shape the Information Security organization from the Penetration Testing chair — build institutions, not just products.

  • L8 : Scale offensive security across organization
  • L9 : Define offensive security strategy
→ C-Suite: L10 is the CISO path — a distinct page, not duplicated here.

L1 — Associate Penetration Tester Rotational

Mission

Learn penetration testing fundamentals

This tour of duty

Complete your first penetration test

Own the outcomes

  • Learn penetration testing fundamentals including tools and techniques
  • Execute basic penetration tests with guidance
  • Write exploit scripts and testing tools
  • Document findings with clear reproduction steps
  • Support senior testers on complex assessments
  • Participate in assessments to learn attack methodologies

Penetration Testing at L1 — the competency bar

Information Security
2
Quality Engineering
2
Software Engineering
1

AI in this role

  • Analyzing vulnerability data
  • Drafting assessment reports
  • Generating finding summaries

L2 — Junior Penetration Tester Rotational

Mission

Conduct assessments under guidance

This tour of duty

Own assessments and find impactful vulnerabilities

Own the outcomes

  • Conduct penetration tests independently for defined scope
  • Identify and exploit common vulnerability types
  • Write custom tools for testing automation
  • Design assessment approaches for standard targets
  • Contribute to testing methodology improvements
  • Report findings with remediation guidance

Penetration Testing at L2 — the competency bar

Software Engineering
2
Information Security
2
IT Operations
1
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Building exploitation workflows
  • Analyzing target patterns
  • Creating testing checklists

L3 — Senior Penetration Tester Rotational

Mission

Own assessments end-to-end

This tour of duty

Lead assessments that uncover critical risks

Own the outcomes

  • Own penetration testing engagements end-to-end
  • Design assessment approaches for complex systems
  • Develop advanced exploitation techniques
  • Lead assessments for web, network, and cloud targets
  • Mentor junior testers on offensive techniques
  • Drive improvements in testing methodology

Penetration Testing at L3 — the competency bar

Information Security
3
Software Engineering
2
IT Operations
1
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Modeling attack scenarios
  • Synthesizing vulnerability data
  • Generating remediation recommendations

L4 — Staff Penetration Tester / Manager, Security Transformational

Mission

Lead complex assessments and mentor team

This tour of duty

Develop testing approaches that improve security posture

Own the outcomes

  • Lead offensive security initiatives across targets
  • Design penetration testing programs at scale
  • Mentor testers on advanced attack techniques
  • Define testing standards and methodologies
  • Drive cross-team red team exercises
  • Own offensive security for critical systems

Penetration Testing at L4 — the competency bar

Information Security
3
Software Engineering
2
Quality Engineering
2
IT Operations
1
Operational Excellence
1

AI in this role

  • Analyzing testing patterns
  • Building assessment playbooks
  • Creating training content

L5 — Senior Staff Penetration Tester / Senior Manager, Security Transformational

Mission

Develop testing methodology and capability

This tour of duty

Drive offensive security methodology

Own the outcomes

  • Drive offensive security strategy organization-wide
  • Design red team programs that test organizational defenses
  • Define offensive security standards and best practices
  • Lead evaluation of offensive tools and techniques
  • Mentor senior testers and shape offensive culture
  • Solve the most challenging offensive security problems

Penetration Testing at L5 — the competency bar

Information Security
4
Software Engineering
3
Quality Engineering
2
IT Operations
1
Operational Excellence
1

AI in this role

  • Designing testing methodologies
  • Modeling threat scenarios
  • Generating strategic recommendations

L6 — Principal Penetration Tester / Red Team Lead Transformational

Mission

Own offensive security program

This tour of duty

Own the red team program

Own the outcomes

  • Set direction for offensive security company-wide
  • Define red team strategy and multi-year roadmap
  • Establish standards ensuring effective offensive testing
  • Drive alignment on offensive security investments
  • Represent offensive security in executive discussions
  • Shape the vision for red team evolution

Penetration Testing at L6 — the competency bar

Information Security
4
Software Engineering
3
Quality Engineering
3
Strategy
2
IT Operations
1
Operational Excellence
1

AI in this role

  • Analyzing strategic risks
  • Building red team frameworks
  • Creating executive content

L7 — Senior Director, Offensive Security Transformational

Mission

Shape offensive security vision and adversary simulation strategy

This tour of duty

Build the team that scales offensive security

Own the outcomes

  • Shape the company's offensive security vision and strategy
  • Define innovative approaches to adversary simulation
  • Establish principles guiding offensive security decisions
  • Influence industry offensive security practices
  • Mentor directors and senior red team leaders
  • Drive offensive security innovation

Penetration Testing at L7 — the competency bar

Software Engineering
2
Information Security
2
Strategy
2
IT Operations
1
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Designing team capabilities
  • Building offensive tools
  • Creating hiring frameworks

L8 — VP, Offensive Security Foundational

Mission

Scale offensive security across organization

This tour of duty

Create the operating model for offensive security excellence

Own the outcomes

  • Build and lead red teams that test organizational defenses
  • Define organizational structure for offensive security
  • Establish hiring standards for penetration testers
  • Create the operating model for offensive excellence
  • Partner with security leadership on red team investments
  • Develop offensive security managers and leaders

Penetration Testing at L8 — the competency bar

Information Security
2
Quality Engineering
2
Software Engineering
1
Strategy
1

AI in this role

  • Modeling offensive maturity
  • Analyzing efficiency patterns
  • Generating operating models

L9 — SVP, Offensive Security Foundational

Mission

Define offensive security strategy

This tour of duty

Define the offensive security strategy

Own the outcomes

  • Own offensive security strategy organization-wide
  • Define multi-year roadmap for adversary simulation
  • Build culture that attracts top offensive talent
  • Partner with executives on adversarial testing strategy
  • Establish offensive security as organizational strength
  • Shape the future of red teaming at the company

Penetration Testing at L9 — the competency bar

Quality Engineering
2
Software Engineering
1
Information Security
1
Strategy
1

AI in this role

  • Building strategic planning systems
  • Analyzing threat landscape
  • Creating offensive architectures

What Hiring Managers Look For

L1-L3: Hands-on exploitation of real vulnerabilities in lab environments and demonstrated ability to write clear, actionable remediation reports that developers actually follow.

L4-L6: Track record of designing comprehensive testing methodologies across diverse tech stacks and leading cross-functional security initiatives that measurably reduced organizational risk.

L7+: Proven ability to translate technical security findings into business risk language that drives C-suite investment decisions and board-level security strategy.

Common Career Transitions

Penetration Testing → Security Architecture at L4-L5 for proactive defense design

Penetration Testing → Product Security at L5-L6 to embed security in development lifecycle

Penetration Testing → Security Consulting at L4-L7 for client-facing risk advisory

Official Classifications

System Code Official Title
O*NET-SOC (US) 15-1299.04 Penetration Testers
ISCO-08 (UN/ILO) 2529 Database and Network Professionals Not Elsewhere Classified
ESCO (EU) Ethical hacker
SSOC 2024 (Singapore) 25242 Penetration testing specialist
NCO-2015 (India) 2529.9900 Database and Network Professionals Not Elsewhere Classified, Other

At L6 and above, the manager classification 1330 — Information and Communications Technology Service Managers applies IN ADDITION to the professional code — a manager is a superset of the individual contributor, never a replacement.

Measure yourself against this ladder — pin it to your Career Record.

Build Your Career Record