RefolkCandidates

Resume example

Penetration Tester resume example

Breaks systems on purpose and writes down exactly how. Below is a complete penetration tester resume, written the way one has to be written to survive a first screen, with every bullet explained underneath.

Alex Moreno

Penetration Tester

alex.moreno@example.com · +1 555 0134 · Berlin · alexmoreno.example

Summary

Penetration Tester with eight years of experience. Found and reported an authentication bypass affecting every tenant, with a working proof of concept and a fix path. Looking for a penetration tester role with more ownership of Burp Suite and the decisions around it.

Experience

Senior Penetration Tester, Northwind Systems

2022 - Present

  • Found and reported an authentication bypass affecting every tenant, with a working proof of concept and a fix path.
  • Ran 25 web and network engagements a year, each closed with a report developers acted on without follow-up questions.
  • Built an internal tooling wrapper that cut recon time on each engagement by roughly half a day.

Penetration Tester, Meridian Labs

2018 - 2022

  • Owned the Network exploitation side of the work at a 40-person product company, and documented it well enough to hand over cleanly.
  • Set the approach the team still uses for Web app testing.

Skills

Burp Suite · Network exploitation · Web app testing · Python · Report writing · OSCP methodology

Education

BSc Computer Science, 2018

A sample, not a real person. The name, the employers, and the figures are invented to show the shape of a strong page - use the structure and put your own evidence in it.

How to read this penetration tester resume example

The sample above is not a template to copy word for word - copied resumes read as copied. It is here to show the shape of a page that gets past a first screen: one column, standard headings, and bullets that end in an outcome rather than a duty. Findings with real severity, and reports a developer could act on.

  • Every bullet opens with a verb and carries a number. That is the pattern, not a coincidence.
  • The summary makes a claim and then supports it in the first bullet underneath.
  • Skills are named tools, not adjectives, and each one appears again in the experience section.
  • The earlier role is short. Recent work carries the weight of the page.

The numbers in a penetration tester resume

The most common thing missing from a penetration tester resume is a number. Not because the work had none, but because nobody wrote them down at the time. These are the measures a penetration tester can usually reach for, and the example uses them.

  • Found and reported an authentication bypass affecting every tenant, with a working proof of concept and a fix path.
  • Ran 25 web and network engagements a year, each closed with a report developers acted on without follow-up questions.
  • Built an internal tooling wrapper that cut recon time on each engagement by roughly half a day.

Before and after: rewriting a weak bullet

Most penetration tester resumes are one edit away from being much stronger, and the edit is the same every time: replace the description of the job with the result of doing it. The pairs below are the same work, written twice.

  • Weak: "Responsible for burp suite and related tasks." Strong: "Found and reported an authentication bypass affecting every tenant, with a working proof of concept and a fix path."
  • Weak: "Worked on network exploitation projects across the team." Strong: "Ran 25 web and network engagements a year, each closed with a report developers acted on without follow-up questions."
  • Weak: "Helped improve processes and supported penetration tester initiatives." Strong: "Built an internal tooling wrapper that cut recon time on each engagement by roughly half a day."

Adapting the example to your own history

Work backwards from the posting. Find the two or three things it actually screens for, then make sure the top third of your page answers them. Everything below that is supporting evidence.

  • Reorder your bullets so the one closest to the posting comes first in each role.
  • Rewrite the summary for the specific job. It is the only part a human reliably reads.
  • Cut any skill you would not want to be asked about for ten minutes.
  • Keep Burp Suite, Network exploitation, Web app testing visible in context, not stranded in a list.

FAQ

Can I copy this penetration tester resume example?
Copy the structure, not the sentences. The layout, the ordering, and the shape of the bullets all transfer. The content does not: a recruiter who reads twenty resumes for the same role notices identical phrasing quickly, and the numbers in this sample are illustrative rather than anyone's real history.
What if I do not have numbers like these?
Most people have more than they think. Look for volume, frequency, time, cost, error rate, or a before-and-after on anything you touched. Where the number genuinely does not exist, say what changed and who noticed - "the process that used to need a weekly meeting now does not" is a real outcome without a metric.
How long should a penetration tester resume be?
One page up to about eight years of experience, two pages beyond it. This example is one page. Length signals scope, so a long page with small-scope bullets reads worse than a short one.
Will this format pass an applicant tracking system?
Yes. One column, real text, standard headings, and no graphics or tables is the format parsers handle reliably. Most parsing failures come from multi-column layouts, text inside images, and headings the parser does not recognise.
Should the example change for a more senior penetration tester role?
The structure stays. What changes is the scope in the bullets: more ambiguity you resolved yourself, more decisions with a tradeoff, and more effect on work that was not directly yours. Findings with real severity, and reports a developer could act on.

More for penetration testers

Other resume examples

Pick a layout

Put this to work

Reading about the job search is not the job search.

Paste your career in once. I write the resume, then every week I rank the live openings against your history, tailor a resume and a cover letter to the best of them, and keep going until you land. You press send, and that is the whole of your part.

  • 140+ curated roles a week, found, written, and scored for you.
  • Every bullet stays inside what your history actually supports.
  • Queued, submitted, interviewing, offer, all in one place instead of a spreadsheet.

500 free credits on sign-up. No card.