Penetration Tester resume example for Fresher (0 years), ai-era template, showing professional summary, work experience, projects, skills, education and certifications

Penetration Tester Resume Format, with 3 Full Samples

A penetration tester is hired on evidence of findings that mattered: the authentication bypass nobody had caught, the domain admin walk from a single phished user, the report a developer could actually act on. Yet most offensive security resumes list every tool in Kali and forget the vulnerabilities they found and the risk they retired. Below are three complete resumes, one for a CEH and eJPT certified fresher with real bug-bounty submissions, one for an OSCP-certified web and network pentester with four years of client engagements, and one for a senior red teamer leading assessments at scale. After the samples come the format rules, the difference between naming Burp Suite and proving you drove it, the terms a parser matches literally, and the mistakes that end a security screening before a human reads the page.

Build my resume

Updated 17 August 2026 · 22 min read · 3 full examples

Penetration Tester resume example for Fresher (0 years), ai-era template, showing professional summary, work experience, projects, skills, education and certifications

Fresher (0 years) Penetration Tester

ai-era template
Read it
Penetration Tester resume example for Mid-level (4 years), modern template, showing professional summary, work experience, skills, education and certifications

Mid-level (4 years) Penetration Tester

modern template
Read it
Penetration Tester resume example for Senior (9 years), header-band template, showing professional summary, work experience, skills, education and certifications

Senior (9 years) Penetration Tester

header-band template
Read it
Penetration Tester resume example for Fresher (0 years), ai-era template, showing professional summary, work experience, projects, skills, education and certifications

Fresher (0 years) Penetration Tester

ai-era template
Read it
Penetration Tester resume example for Mid-level (4 years), modern template, showing professional summary, work experience, skills, education and certifications

Mid-level (4 years) Penetration Tester

modern template
Read it
Penetration Tester resume example for Senior (9 years), header-band template, showing professional summary, work experience, skills, education and certifications

Senior (9 years) Penetration Tester

header-band template
Read it

Penetration Tester resume example, Fresher (0 years)

ai-era template
Penetration Tester resume example for Fresher (0 years), ai-era template, showing professional summary, work experience, projects, skills, education and certifications
Fresher (0 years) ai-era template

Is your resume good enough?

Upload the resume you have now and see what an applicant tracking system reads before a penetration tester recruiter ever does.

Free to run. Sign in with your mobile number to see your score.

Penetration Tester resume example, Mid-level (4 years)

modern template
Penetration Tester resume example for Mid-level (4 years), modern template, showing professional summary, work experience, skills, education and certifications
Mid-level (4 years) modern template

Want this structure with your own details? Build it in the resume builder.

Penetration Tester resume example, Senior (9 years)

header-band template
Penetration Tester resume example for Senior (9 years), header-band template, showing professional summary, work experience, skills, education and certifications
Senior (9 years) header-band template

The format that works for penetration tester resumes in India

Reverse chronological is the only layout worth using. Put the most recent role first, work backwards, and let the dates sit in plain view. Functional resumes that group everything under Skills and Tools and quietly drop the dates read as an attempt to hide a gap, and security hiring teams, who verify carefully, treat them that way. A gap is better explained in one honest line than buried. Length is decided by evidence. One page holds everything a fresher and most testers up to roughly six years have to say. Past that, a second page is fine when it carries real engagement work, red team operations or published research, not a longer tool list. A page two built from a declaration paragraph and a hobbies line is a padded one-page resume. Four things belong nowhere on a security resume here: a photograph, date of birth, marital status and father's name. They survive from an older template that circulated through campus placement cells. Nobody screening a penetration tester is looking for them, and every line they occupy is a line a finding or a certification could have used. Be careful with anything that could look like disclosure of a real client's data. Name the vulnerability class, the impact and the fix, never a client's name where an NDA covers it, and never a live proof-of-concept payload against a named production system. Write "a BFSI client" or "a lending platform" rather than the brand. Send a PDF unless the posting asks for DOCX, name the file with your own name and the target role, and use a single column all the way down, because two-column layouts parse unpredictably. The table below sets out the section order.

SectionWhere it goesWhy
Name and headlineTop, above everythingThe headline is the role you want, penetration tester or security consultant. Recruiters match on it.
Professional summaryDirectly under the headerThree lines. Testing domains, years, and the single strongest finding or outcome.
CertificationsHigh, often just under the summaryOSCP and OSEP gate offensive roles, so they earn a spot near the top, not buried at the bottom.
Work experienceNext, for anyone with a jobMost recent first. Newest role gets the most bullets.
Bug bounty and projectsAbove experience for freshers, below it after thatFor a fresher, accepted reports and labs are the evidence. For a senior they are supporting proof of research.
SkillsBelow experienceGrouped: testing domains, tools, scripting, frameworks. Not a 40-tool wall.
EducationBottom, unless you are a fresherDegree, institution, years. Drop the percentage after your first job.

Listing Burp Suite is not the same as proving you drove it

The single most common pentester resume failure is a tools line that reads Nmap, Nessus, Burp Suite, Metasploit, Wireshark, Nikto, SQLmap, Hydra, John, Hashcat, Aircrack, Maltego, Cobalt Strike with no bullet anywhere that shows a real finding produced with any of them. A parser matches those terms, but a technical interviewer reads the wall and assumes it is a Kali menu screenshot, then goes looking for the one vulnerability you can actually walk through end to end. The fix is to let the experience prove the tradecraft. If you write Burp Suite, at least one bullet should describe a finding you produced with it: the IDOR, the access-control bypass, the injection. If you write BloodHound, a bullet should mention the Active Directory path you mapped and walked. The mid-level sample lists Burp, BloodHound and AWS review precisely because the bullets show a chained bypass, a Kerberoasting-to-domain-admin path and an IAM misconfiguration report. The tools line and the experience agree, which is what makes both believable. Be specific about vulnerability classes, not just tool names. Writing that you found an IDOR, an SSRF that reached cloud metadata, or a Kerberoasting path tells a reviewer you understand the exploit, not just that you ran a scanner. Anyone can run Nessus. A tester who can explain why a finding is exploitable and how to fix it is the hire. Do not pad with tools you have opened once. On an offensive resume, listing Cobalt Strike or Ghidra when you cannot discuss C2 tradecraft or a real reversing task reads as inflation, and the interview exposes it in minutes. List what you can defend, and let the depth show in the findings.

For every tool on your line, ask: is there a bullet describing a real finding I produced with it. If not, either add the finding or cut the tool. A wall of unproven Kali tools helps the parser and sinks the technical round.

Writing a summary a security hiring manager actually reads

The block under your name is the part you can be reasonably sure gets read, so it should carry three facts: what you test, how long you have been testing it, and the strongest finding or outcome your work produced. Three or four lines, no adjectives that cannot be checked. The old objective line, seeking a challenging position in a reputed organisation to utilise your ethical hacking skills, tells the reader nothing they did not assume from the application. Replace it with a summary. An objective describes what you want, a summary describes what you have already found and fixed, and only one is evidence. Freshers often believe they have nothing to summarise. Look at the fresher sample: it names the testing domains, states the internship, and points at accepted bug-bounty reports with a real IDOR and a stored XSS. That is a genuine summary built from coursework, one internship and public submissions. What it avoids is "passionate about cyber security and hacking", a phrase so common on graduate resumes it now carries no information. A practical test: read your summary and ask whether a classmate with the same CEH could paste it onto their resume unchanged. If they could, it describes the certification, not you. Add the specific vulnerability, the specific impact and the specific ownership until it stops being transferable.

Professional summary, mid-level pentester
Weak

Passionate and hardworking ethical hacker with 4+ years of experience in penetration testing, VAPT and cyber security seeking a challenging role in a reputed organisation.

Strong

Offensive security engineer with four years running web, network and cloud penetration tests for BFSI clients, owning engagements from scoping to retest. Found a critical pre-auth bypass and IDOR on a lending platform before go-live, OSCP certified.

The rewrite trades a keyword list and self-description for testing domains, an ownership scope and one verifiable critical finding.

Experience bullets: what you tested, what you found, what it risked

Every strong bullet in the samples follows the same shape. It opens with an action verb, names the specific system or engagement you tested, and closes with the finding and the risk it carried. The verb establishes that you did the work. The target tells a technical reviewer whether the engagement is relevant. The finding and its blast radius do the persuading. Lead with impact, not activity. Testers usually write the task first, then struggle to attach a result, which produces bullets like "performed VAPT on web applications using Burp Suite and Nmap". Instead ask what you found and what it would have cost the client: an account takeover avoided, a full customer record set that would have been exposed, a domain compromised, a critical count driven down. Then write the sentence that ends in that fact. Vary the evidence. Ten severity ratings in a row read as one trick repeated. Across a real role you can honestly reach for the vulnerability class, the number of critical or high findings, the risk retired, the mean-time-to-detect improvement, the false positives removed, the clients or engagements covered, and the fixes shipped after your report. The mid-level sample mixes finding severity, a criticals-reduced count and a tooling time saving, which reads as range. Where you cannot share a number under NDA, give scope and class: how many engagements, which environment, which vulnerability, without naming the client. "Found a chained pre-auth bypass and IDOR on a lending platform, rated critical and fixed before go-live" carries weight without disclosing a brand or inventing a percentage. Allocate bullets by recency. Current role gets five or six, the previous role four or five, anything older two or three.

LevelWhat bullets must proveTypical evidence
FresherYou can find and clearly report a real vulnerabilityAccepted bug-bounty reports, confirmed internship findings, CVSS writeups
1 to 3 yearsYou run a standard engagement with light supervisionFindings by class and severity, false positives validated out, clients covered
4 to 6 yearsYou own an engagement end to end and drive the fixCritical findings, risk retired, remediation shipped, tooling built, mentoring
7 years and upYou lead red team ops and set methodologyAdversary outcomes, detection gaps closed, MTTD improvement, standards set
Experience bullet, VAPT role
Weak

Responsible for performing vulnerability assessment and penetration testing on client web applications using various tools and preparing reports.

Strong

Found a chained pre-auth bypass and IDOR on a lending platform that would have exposed the full customer record set, rated critical and fixed before go-live after a same-day disclosure call.

"Responsible for" describes a job description; the rewrite names the finding, its blast radius and the outcome it drove.

Experience bullet, red team work
Weak

Worked on red team engagements and successfully compromised the internal network and Active Directory environment.

Strong

Led an assumed-breach operation that chained a phished user to domain admin and a crown-jewel database undetected in 4 days, then drove the detection-engineering work that closed 6 gaps.

Names the attack path, the time, the stealth and, crucially, the defensive fixes that followed, so a reviewer sees value delivered, not just a flag captured.

If a bullet would read identically on any Kali user's resume, it is describing the tool, not you. Rewrite it until it only fits the finding you actually produced and the risk you actually retired.

The skills section: grouped, honest, and short enough to defend

A pentester resume's skills section has two audiences with opposite preferences. The parser wants literal terms it can match, Burp Suite and OSCP and Active Directory. A human wants a short, organised list that signals what kind of tester you are: web, network, cloud, red team. Grouping satisfies both. Group by function rather than one long line. Testing domains, offensive tools, scripting, and frameworks and standards is a grouping that works for almost every penetration tester. The exact headings matter less than the fact that structure exists. Write names the way the industry writes them: Burp Suite not BurpSuite, Metasploit not MetaSploit, OWASP not owasp. A parser matches on strings, and a sloppy tool name on a security resume reads worse than on any other. Twelve to sixteen skills is the working range. Below eight the section looks thin. Above twenty it stops being a signal, and a pentester resume is especially prone to Kali-menu padding: listing forty tools that ship on the distribution as if each were a skill. The list is a contract: every item is a question you have agreed to answer in the technical round, and a tester who lists Ghidra and cannot reverse a simple binary loses more than the keyword was worth. Do not include a proficiency bar. Star ratings invite an argument you cannot win, and nobody agrees on what four stars in Active Directory exploitation means. Let the findings prove the depth instead.

GroupWhat goes in itHow many
Testing domainsWeb, API, network, cloud, mobile, Active Directory, red team3 to 5
Offensive toolsBurp Suite, Nmap, Metasploit, BloodHound, Nessus, Cobalt Strike4 to 6
ScriptingPython, Bash, PowerShell, and any custom tooling you built2 to 3
Frameworks and standardsOWASP Top 10, MITRE ATT&CK, PTES, CVSS, PCI DSS2 to 4
Reporting and processThreat modelling, scoping, risk reporting, remediation retest2 to 3
Skills section
Weak

Skills: Kali Linux, Nmap, Nessus, OpenVAS, Burp Suite, Metasploit, Wireshark, Nikto, SQLmap, Hydra, John, Hashcat, Aircrack-ng, Maltego, Ghidra, IDA, Cobalt Strike, Empire, Responder, Mimikatz, BloodHound, Nuclei, ffuf, gobuster, MS Office

Strong

Domains: web, API and network penetration testing, AWS review, Active Directory. Tools: Burp Suite Pro, Nmap, BloodHound, Impacket, Nessus. Scripting: Python, Bash. Standards: OWASP Top 10, MITRE ATT&CK, CVSS, PCI DSS.

Cuts the Kali-menu dump to tools you can defend, groups by domain so a human reads it in one pass, and drops the filler like MS Office that no security panel cares about.

Bug bounty, labs and research: what to include and how to describe it

For a fresher, findings are the resume. Accepted bug-bounty reports, confirmed lab exploits and a home Active Directory range sit above experience, get the most space, and are where a reviewer decides whether you can actually break software or only pass exams about it. For an experienced tester they move below experience and shrink to one or two entries, kept only if they show research or a class the day job does not cover. The common failure is describing the platform instead of the finding. "Solved many machines on a hacking platform" tells a reviewer nothing, because thousands of resumes carry that line. Describe what you found, why it was exploitable, and its impact. The bug-bounty entry in the fresher sample is a stronger entry than a fancier one would be, because it names a real IDOR that exposed other users' invoices and the fix, not just a platform badge. Pick work that shows range rather than three web-XSS finds. One accepted bounty with real impact, one lab that demonstrates a systems concept such as an Active Directory attack path or SSRF-to-cloud-metadata, and one piece of tooling or a writeup is a stronger set than a list of solved-box counts. Two well-described findings beat ten box names. If your writeups or tools are public, say so in plain text, and keep them ethical: no live payloads against real named systems, no data you should not have. An interviewer who opens your GitHub reads the commit history and the responsibility of the content as a work sample. Bug-bounty hall-of-fame credit, CVE assignments and conference or meetup talks count and are often undersold: name the finding, the impact and the recognition, and stay within disclosure rules.

Project description, fresher resume
Weak

Bug Bounty: found and reported many bugs on various platforms and solved 100+ machines on hacking platforms.

Strong

Bug bounty: 7 accepted reports across public programs, including an IDOR that exposed other users' invoices by incrementing an object id and a stored XSS, each with steps to reproduce and a suggested fix, 2 with hall-of-fame credit.

Swaps a vague count for named vulnerability classes, real impact, the quality of the writeup and verifiable recognition.

Where education and certifications belong

Education goes at the bottom for anyone with a full-time job, and near the top for a fresher, who has nothing stronger to lead with. Degree, institution, years. That is the whole entry for most people. A degree is not a hard gate for offensive security the way it is for some fields, since findings and certifications carry the load, but list it honestly. CGPA or percentage is worth keeping while you are a fresher and it is good, roughly 7.5 out of 10 and above, because campus and early-career screening still filters on it. Once you have your first full-time role, drop it. A number from four years ago competes for space with real findings that are far more predictive. Certifications are unusual on a pentester resume in that they belong high, often just under the summary, not buried at the bottom. OSCP and OSEP function as gates for hands-on offensive roles, so a reviewer wants to see them fast. Write the full name, the issuing body and the year. CEH clears HR and campus filters, OSCP proves hands-on exploitation, and the specialist certifications like OSEP, OSWE, CRTO and the GIAC track signal depth in a particular direction. An expired or in-progress certification listed as held is a dishonesty that a security team, of all teams, will verify, so state "in progress" plainly or leave it off. Coursework lines are for freshers only, and only when directly relevant. Networking, operating systems and cryptography are worth naming for a security role. Engineering mathematics is not. Skip school details once you have a degree.

Getting through the applicant tracking system

An applicant tracking system is a parser and a search index, not a judge. It reads your file, tries to break it into name, dates, employers, titles and skills, and stores the result so a recruiter can search across candidates. Almost every ATS problem is a parsing problem, and parsing problems come from layout, not wording. The layout rules are short. One column. Standard section headings, so use Work Experience rather than My Missions, and Skills rather than My Arsenal. No text inside images, because a certification-badge strip reads as empty space. No critical information in the header or footer region, which some parsers drop. Avoid text boxes and nested tables in the resume body. On wording, mirror the language of the job description where it is honest. If the posting says penetration testing, write penetration testing, not only VAPT. If it says OSCP, write OSCP. Include the expansion alongside an acronym at least once, for example "VAPT (vulnerability assessment and penetration testing)" and "OSCP (Offensive Security Certified Professional)", so both searches find you. Security recruiters search on specific certifications and vulnerability classes, so having OSCP, Burp Suite and OWASP appear naturally in your bullets matters. Keyword stuffing does not work, and security resumes are a common offender with a hidden block of every certification acronym in white text. Recruiters find it quickly, and on a security hire the dishonesty is disqualifying, not just filtered. Write real bullets that naturally contain the right terms, because a bullet describing an OWASP-mapped finding contains the words that survive human review too. Save as PDF from a tool that embeds real text, then open the file and confirm you can select and copy a sentence. If you cannot select the text, neither can the parser.

Section heading
Weak

My Hacking Arsenal

Strong

Skills and Tools

Parsers look for standard headings; a creative one can push your entire tool list into an unclassified bucket the recruiter never searches on.

Test your own file before you send it. Copy the text out of the PDF into a plain text editor. Whatever you can read there is roughly what the parser sees, and anything scrambled is a real risk.

What gets penetration tester resumes rejected

Most rejections at the resume stage are not close calls. They come from a small set of recurring problems, and all of them are fixable in an afternoon. The list below covers what reviewers of Indian penetration tester resumes see most often, in rough order of how much damage each one does.

  • A Kali-menu tool wall with no bullet describing a real finding produced with any of it. Every tool is a question you have agreed to answer in the technical round.
  • Job duties copied from the job description instead of the vulnerabilities you found. "Responsible for performing VAPT" is the tell.
  • No findings anywhere. Vulnerability class, severity, risk retired, remediation shipped. Pick whichever is honest and NDA-safe for the work.
  • Disclosing a client's name or a live payload against a named production system. It signals you cannot be trusted with scope, which is the whole job.
  • A certification listed as held when it is in progress or expired. A security team verifies, and a false credential ends the process on trust alone.
  • A photo, date of birth, marital status or father's name. None of it belongs on a technical security resume, and it takes a finding's space.
  • Listing OSCP, OSEP, OSWE and CRTO when you hold none of them yet, hoping the acronym passes the filter. It does not survive the interview.
  • A generic objective line. Replace it with a summary that states testing domains, years and one strong finding.
  • Only automated-scanner work with no manual exploitation, so a reviewer cannot tell whether you can exploit a finding or only report a Nessus dump.
  • Typos in the tools and standards you claim to know. Writing "Metasploit" as "Metaexploit" or "OWASP" as "OSWAP" undoes an otherwise strong page on a security team.

Read your resume aloud once before sending it. Anything you would be embarrassed to defend in a technical round, or anything that discloses a client, is a line to cut or rewrite.

Skills to put on a penetration tester resume

Technical

  • Web Application Penetration Testing
  • API Security Testing
  • Network Penetration Testing
  • Active Directory Exploitation
  • Cloud Penetration Testing (AWS, Azure)
  • Red Team and Adversary Emulation
  • OWASP Top 10
  • Vulnerability Assessment (VAPT)
  • Exploit Development Basics
  • Threat Modelling
  • Privilege Escalation
  • Wireless and Mobile Testing
  • CVSS Scoring
  • Detection and Purple Teaming

Tools and platforms

  • Burp Suite Pro
  • Nmap
  • Metasploit
  • Nessus and Nuclei
  • BloodHound and Impacket
  • Cobalt Strike
  • Wireshark
  • SQLmap and ffuf
  • Kali Linux
  • Python
  • PowerShell
  • Bash

Working skills

  • Clear finding and report writing
  • Client disclosure and communication
  • Engagement scoping
  • Remediation guidance
  • Mentoring
  • Presenting to technical and executive audiences
  • Working within rules of engagement
  • Prioritisation by business risk
  • Continuous learning

Certifications worth listing as a penetration tester

CertificationFull nameWorth it for
OSCPOffensive Security Certified ProfessionalThe single most recognised hands-on offensive credential in Indian security hiring, and a near-gate for a real penetration testing role. Worth it once you can already exploit, since the 24-hour exam proves it under pressure rather than teaching it. Carries weight at every level from early career upward.
CEHCertified Ethical Hacker (EC-Council)The certification that clears HR and campus filters, especially at BFSI, consulting and government-adjacent employers who list it by name. Best value for a fresher or career switcher needing to pass the resume screen. Recognised as knowledge-based rather than hands-on, so pair it with OSCP or eJPT to prove you can actually exploit.
eJPTeLearnSecurity Junior Penetration TesterAn affordable, fully hands-on entry credential that proves a fresher can run a basic engagement, not just recall theory. A strong first certification before OSCP, and a good signal on a fresher resume that the CEH alone does not give.
OSEPOffensive Security Experienced Penetration TesterThe advanced Offensive Security certification for evasion, lateral movement and Active Directory tradecraft. Worth it for mid-to-senior testers moving into red team and adversary-emulation work, where bypassing defences, not just finding bugs, is the job. Overkill for a pure web-app VAPT role.
OSWEOffensive Security Web ExpertThe deep web-application and white-box exploitation certification. Worth it for testers who specialise in application security and source-assisted testing, since it proves you can chain vulnerabilities in real code, not just run Burp. Less relevant if your work is network and infrastructure focused.
CRTOCertified Red Team Operator (Zero-Point Security)A practical, well-regarded red team certification centred on Cobalt Strike and modern C2 tradecraft. Worth it for testers moving into full-scope red teaming who need to prove OPSEC and adversary emulation, not just single-target exploitation. Pairs naturally with OSEP for a red team profile.
GPENGIAC Penetration TesterA respected, methodology-heavy certification recognised by enterprises and government-adjacent employers, often the ones that also value GIAC across their SOC. Worth it for senior testers in large organisations where the GIAC brand carries budget weight. Expensive, so employer sponsorship is common.

Keywords an ATS scans for in a penetration tester resume

These are the literal terms a parser matches against the job description. Use the ones that are true of you, in the sentences where you did the work, not as a list at the bottom.

  • penetration tester
  • ethical hacker
  • VAPT
  • web application penetration testing
  • OSCP
  • CEH
  • burp suite
  • OWASP Top 10
  • network penetration testing
  • active directory
  • red team
  • vulnerability assessment
  • metasploit
  • nmap
  • cloud security
  • python
  • CVSS
  • MITRE ATT&CK
  • bug bounty
  • security consultant

Penetration Tester resume FAQ

What salary can a penetration tester expect in India?

A fresher with CEH or eJPT and some real findings typically starts around 4 to 7 LPA, higher at product security teams and specialist firms. A penetration tester with four to six years and OSCP usually sits in the 12 to 22 LPA band, more with cloud and red team depth. Senior testers and red team leads with nine years and above commonly earn 25 to 50 LPA and beyond at consulting majors and strong product companies. OSCP, OSEP and demonstrable red team or research work push the top of every band upward, and a strong bug-bounty or CVE record can shortcut the early ones.

How long should a penetration tester resume be?

One page up to about six years of experience, two pages after that only if the second page carries real engagement work, red team operations or published research rather than a longer tool list. Nobody has been rejected for a resume that was too easy to read. If you are struggling to fit one page, cut the oldest role to a single line, remove coursework, and delete any tool you would not want to be tested on in the technical round.

Do I need OSCP to get a penetration testing job in India?

Not strictly for your first role, but it is close to a gate for a genuine hands-on penetration testing job, and many postings list it by name. A fresher can enter with CEH plus eJPT and a real bug-bounty or lab record, then target OSCP within the first year or two. For mid and senior offensive roles it is effectively expected, and the specialist certifications like OSEP, OSWE and CRTO signal depth in a direction. Findings still matter more than any badge, but OSCP is the badge that opens the most doors.

How does a fresher write a penetration tester resume with no experience?

Lead with findings, then certifications, then education and skills. Treat bug-bounty submissions, confirmed internship findings and lab exploits as your work: name the vulnerability class, why it was exploitable and its impact. An accepted IDOR report counts, a home Active Directory lab where you reached domain admin counts, and a deliberately vulnerable app you built to teach a class counts. Add anything checkable, such as an eJPT certification, hall-of-fame credit or a platform ranking, since verifiable findings carry more weight than adjectives like passionate.

Can I put client engagements and findings on my resume under NDA?

Yes, if you describe them safely. Name the vulnerability class, the severity, the environment type and the risk, never the client's brand where an NDA covers it, and never a live payload against a named production system. Write "a BFSI client" or "a lending platform" and "a critical pre-auth bypass" rather than the company name and a working exploit. A tester who clearly respects scope and disclosure on their own resume signals exactly the judgement the job requires, and one who leaks a client name signals the opposite.

Should I list every tool in Kali Linux on my resume?

No. A forty-tool wall that reads like the Kali menu is padding that a technical interviewer sees through in seconds, and every tool you list is a question you have agreed to answer. List the four to six you can genuinely drive, group them by testing domain, and let a bullet prove a real finding for the important ones. The tools line and the experience should agree, because a tool you cannot back with a finding costs you far more in the interview than it gains you in the parser.

Do certifications go at the top or bottom of a pentester resume?

Higher than on most resumes, often just under the summary. OSCP and OSEP function as gates for offensive roles, so a reviewer wants to see them fast rather than hunting at the bottom of page two. Write the full name, issuing body and year, keep the list to what you actually hold, and mark anything in progress plainly. For education, the reverse is true: it drops to the bottom once you have real engagement experience to lead with.

Does an ATS reject resumes with two columns?

It does not reject them outright, but some parsers read multi-column layouts out of order, which interleaves your certifications sidebar with your experience and produces nonsense in the recruiter's view. A single-column layout removes the risk, which is why all three samples above use one. Test your own file by copying the text out of the PDF into a plain text editor, and if it reads in order there it will most likely parse correctly.

How important is report writing on a penetration tester resume?

Very. Finding a vulnerability is half the job; writing it so a developer can fix it is the other half, and it is what separates a senior tester from a scanner operator. Show it on the resume by describing findings that led to a fix, not just a flag: a bullet that ends in "remediated before go-live" or "which the blue team turned into an alert" proves you communicate, not only exploit. Reporting, disclosure and remediation guidance belong in your skills and your bullets alike.

Related resume examples and guides

Build your own in any of these formats

Start from a blank resume or upload the one you have. Goodspace renders it in 24 templates and flags the OSCP, Burp Suite and OWASP keywords an applicant tracking system will look for, and the Kali-menu padding it will not credit.

Build my resume