Most junior penetration tester CVs read like a stack of certificate logos with a name bolted on top. The ones that earn a callback prove you can find a real vulnerability, write it up clearly, and never break the client's production estate.
Breaking in is the hard part. UK demand leans mid-level and senior, so an entry CV has to work harder to convince a hiring manager you are worth training. You do that with evidence of hands-on testing, not a wish list of tools.

Key takeaways
- Junior openings are scarce, so lead with proof you can test: labs, capture-the-flag events, a home lab, and any write-ups you can show.
- Name the skills the adverts name, in their words: penetration testing, Linux, Windows, Nmap, and web application testing.
- Put your GitHub, a write-up blog, and a Hack The Box or TryHackMe profile in the header. For a junior tester, that is your portfolio.
- OSCP and CREST recur across UK adverts. List what you hold and what you are studying towards.
- Two pages, reverse chronological once you have roles to show, sent as a PDF unless the advert asks for Word.
- Open with a short personal statement built on one concrete test you have run, not a line of adjectives.
Breaking in as a junior penetration tester
Penetration testing is a craft the UK market mostly hires at mid-level and above. Genuinely junior openings are rare, so your first CV has to close the gap between "keen to learn" and "safe to put in front of a client".
With a thin work history, use a skills-led structure: personal statement, then skills and hands-on evidence, then education, with any paid work lower down.
The good news is that this is one of the few fields where you can build real evidence at home, legally and for free. Employers know it, and they look for it. Mine these:
- A home lab: a deliberately vulnerable Active Directory domain, a few virtual machines, and notes on what you broke and how.
- Hack The Box, TryHackMe, and PortSwigger's Web Security Academy, with your profile or completion count as proof.
- Capture-the-flag events, university projects, and any dissertation with a security focus.
- Bug bounty submissions, even low-severity ones, and any CVE you have contributed to.
Then write those in the language of the job. "Compromised 45 machines on Hack The Box, documenting the full kill chain and remediation for each" is a testing bullet that happened in your bedroom.
A hiring manager's real worry with a junior is not whether you can pop a box. It is whether you will scope an engagement properly, stay inside the rules of engagement, and hand back a report the client can use. Every line that shows judgement, not just exploitation, calms that worry.
When we screen a junior pentester CV, the first thing we look for is a report, not a certificate. Anyone can list OSCP as in progress. Far fewer can point to a write-up that walks through how they found a flaw, why it mattered, and how to fix it. Link one public write-up, even from a retired Hack The Box box, and you have already shown the part of the job most applicants only claim.
The write-up is what separates a hobbyist from a hireable junior. Penetration testing is a reporting job as much as an exploitation job, and a clear, well-scoped report is the deliverable a client actually pays for.
One line signals you are already on the path: "Studying towards OSCP" or "eJPT certified, OSCP booked for spring". It tells a hiring manager where you will be in six months, not just where you are today.
Do not hide the ordinary parts either. Name the operating systems you are fluent in, the scripting you can do in Bash or Python, and the frameworks you work to, such as the OWASP Testing Guide or PTES. A junior who names a methodology reads as someone who tests to a standard, not by luck.

PRO TIP
Keep a public evidence trail. A GitHub with your scripts, a blog with two or three lab write-ups, and an active TryHackMe or Hack The Box profile do more for a junior CV than a fourth certificate. Put the links in your header, not buried at the bottom.
What the UK penetration tester market looks like
Knowing the market shapes the CV. Here is where the work happens and what employers keep asking for.
| What | UK penetration tester roles |
|---|---|
| Where the work happens | Split between hybrid and on-site (across 20 UK penetration tester postings in the last ~30 days, Enhancv's internal job feed) |
| Experience level asked for | Mostly mid-level and senior, with genuinely junior openings rare |
| Skills that recur most | Penetration testing, Linux, Windows, security controls, Nmap, and web application testing |
| Certifications that recur | OSCP and CREST |
Two rows should shape the CV directly.
The split between hybrid and on-site means location still counts, so put your base and your willingness to travel or work in a secured facility near the top. Consultancies often test on client sites.
And the tilt towards mid and senior roles is exactly why the junior route above leans so hard on evidence. You are asking a team to train you, so show them you have already started.
The certifications row is worth taking literally. Where a senior advert lists OSCP or CREST as essential, the junior version of the same team often lists them as desirable, which is your opening. Show those names in progress and you speak the language the screener is scanning for.
Formatting your penetration tester CV
Keep it to two pages, one column, standard headings, and a clean, readable font. A security hiring manager skims for tooling and evidence before they read a line of prose.
Use a reverse chronological structure once you have testing roles or a placement to show. Before that, the skills-led layout above keeps your evidence at the top where it counts.
Put your links in the header, not the footer: GitHub, a write-up blog, LinkedIn, and your Hack The Box or TryHackMe handle. For a tester, those are the portfolio, and a recruiter should reach them in one click.
Send a PDF for direct applications so the layout holds, and keep a Word copy for agencies that reformat CVs into their own template. If the advert names a file type, follow it. Recruitment software still parses most applications, so keep the headings standard for an ATS-friendly CV. Build it from a tested layout rather than a blank page: Enhancv's CV templates export to a clean PDF.
Writing your penetration tester personal statement
Three or four sentences at the top: who you are, the environments and tools you are comfortable in, one piece of concrete evidence, and the kind of team you want to join. See more personal statement examples if the opening line is fighting you.
Skip the enthusiast opener every other junior uses. "Passionate about ethical hacking with a strong desire to learn" tells a hiring manager nothing they can check.
Lead with evidence a tester would respect:
Penetration tester personal statement example (junior)
Aspiring penetration tester with a first-class BSc in Cyber Security and 18 months of self-directed lab work, including 45 compromised Hack The Box machines and a documented home Active Directory lab. eJPT certified and studying towards OSCP. Comfortable across Linux, Windows, and web application testing, and known for write-ups a client can act on. Looking to join a CREST-accredited team in the North West as a junior tester.
Penetration tester personal statement to avoid
Passionate and highly motivated cyber security enthusiast with a keen interest in ethical hacking and a strong desire to learn. A hard-working team player looking for an exciting opportunity to grow and develop my skills in a challenging environment.
Writing your penetration tester experience section
Whether it is a placement, a part-time SOC role, or a run of supervised freelance tests, write each entry the same way: a dated heading, then bullets that show what you tested, what you found, and what the client did with it. Lead each bullet with an action verb. For the mechanics, see work experience on a CV.
Testing work is measurable even when the engagement is confidential. Findings raised, severity ratings, systems in scope, time saved by automation, and reports delivered are all CV achievements. Never name a client under NDA, but you can always describe the work.
No paid testing yet is fine. A capture-the-flag placing, a documented lab project, or a supervised university engagement can each take a dated heading and the same bullet treatment, as long as the work was authorised and you can talk through it in an interview.
Tailor every application to the advert: pull the tools and testing types it lists and mirror the ones you can honestly back. Enhancv's CV tailoring feature reads the ad and suggests the matching edits, which saves rewriting from scratch for each firm.
- Run authorised web application and internal network tests for SME clients, scoping each engagement with the lead consultant before touching a live system
- Identified and documented 30+ findings across OWASP Top 10 categories, from SQL injection to broken access control, with remediation steps written for non-technical stakeholders
- Automated reconnaissance with Nmap and custom Bash scripts, cutting enumeration time on a standard external assessment by roughly a third
- Wrote client-facing reports rated "clear and actionable" by the delivery manager, each with an executive summary and CVSS-scored risk ratings

PRO TIP
Never claim access to a system you were not authorised to test. State that the engagement was authorised and scoped. Employers read an unscoped "hack" as a liability, not a skill, so make the boundaries of your work explicit on every bullet.
Skills to put on a penetration tester CV
Read a run of live UK penetration tester adverts and the same demands repeat. Penetration testing, Linux, Windows, security controls, Nmap, and web application testing recur most on Enhancv's internal job feed over the last ~30 days. Those are your hard skills, listed in the words the adverts use.
The soft skills that matter here are checkable, not decorative. Written communication carries real weight, because the report is the product. Pair it with analytical thinking, methodical curiosity, and professional integrity.
List only what you can defend in a technical interview. If you have used a tool in a lab, say so. If you have only read about it, leave it off, because an interviewer will ask you to prove it.
Top skills for your penetration tester CV:
Penetration testing
Web application testing
Network security
Linux
Windows
Active Directory
Nmap
Burp Suite
Metasploit
Report writing
Written communication
Analytical thinking
Methodical curiosity
Attention to detail
Professional integrity
Certifications and education for a penetration tester CV
Certifications carry unusual weight in this field, and two names recur across UK adverts: OSCP and CREST. List what you hold, and list what you are studying towards with a target date. Treat them like the certificates on a CV that they are, near the top for a junior.
Below those, an entry-level ladder helps a first CV: eJPT, PNPT, and CompTIA Security+ or PenTest+ show you are building towards the harder certs. A cyber security degree or a conversion course belongs in your education section, alongside any security modules or dissertation.
Recruiters in this field expect you to keep learning, so a short line on recent activity helps: a lab retired last month, a conference talk you applied, or a tool you have just picked up. It signals momentum, which matters more for a junior than a long back catalogue.
If a role needs security clearance, note your eligibility and any clearance you already hold. It answers a question the employer would otherwise have to ask, and for government and defence work it is often the first filter.
Conclusion
Lead with proof you can test, name the tools the adverts name, and make your write-ups easy to find. That is how an entry-level CV earns a place on a shortlist weighted towards mid and senior testers.
Pair it with a short cover letter that says why security and why this team, and you turn "keen to learn" into a credible first application.

Author's take - The Enhancv team
When we screen a junior pentester CV, the first thing we look for is a report, not a certificate. Anyone can list OSCP as in progress. Far fewer can point to a write-up that walks through how they found a flaw, why it mattered, and how to fix it. Link one public write-up, even from a retired Hack The Box box, and you have already shown the part of the job most applicants only claim.




















