Penetration Tester CV Example
Professional penetration tester CV example with recruiter-tested sections you can customise in minutes.
Example only
All personal details and career history in this example are fictional. Customise this CV with your own real information before applying.
Resume preview

Skills
Certifications
OffSec Certified Professional (OSCP)
Offensive Security
2023-06-01
GIAC Penetration Tester (GPEN)
GPEN
2022-06-01
Languages
English (Native)
Tyler Jenkins
Penetration Tester
6 years of experience performing web, network, and application security assessments for enterprise clients.
Experience
Senior Penetration Tester
BlackBox Ridge, Full-time
2020-06-01 – Present
Amsterdam, Netherlands
Offensive security against web and cloud — SSRF exploitation chains, red-team simulations, and custom fuzzing tools.
- Led offensive security engagements against web and cloud environments
- Discovered chained SSRF-to-credential theft path in staging cloud metadata service and delivered prioritized remediation plan.
- Conducted red-team simulations with phishing and lateral movement phases to validate detection and response controls.
- Built custom Burp and Python tooling for authenticated API fuzzing against GraphQL and REST endpoints.
Penetration Tester
Adversary Proof Labs, Full-time
2018-05-01 – 2020-05-01
Austin, TX, US
Offensive assessments for enterprises and startups — network pivoting, deserialization exploits, and cloud privilege escalation.
- Executed offensive assessments for enterprise and startup clients
- Performed network exploitation tests with segmented pivoting to evaluate internal trust boundary assumptions.
- Identified insecure deserialization issue in Java service chain and provided proof-of-concept exploit safely.
- Ran cloud configuration reviews and privilege escalation tests for IAM roles across multi-account setups.
Junior Penetration Tester
Red Harbor Security, Full-time
2016-04-01 – 2018-04-01
Prague, Czech Republic
Vulnerability validation and reporting — manual false-positive triage, reproducible attack paths, and recon automation.
- Supported vulnerability validation and reporting delivery
- Validated scanner findings manually to reduce false positives before final client reports.
- Documented reproducible attack paths with remediation guidance tailored to engineering teams.
- Automated recon workflows with Nmap, httpx, and nuclei templates for faster engagement kickoffs.
Education
Information Security, Bachelor of Science
Purdue University
2016-09-01 – 2020-06-01
Bachelor's-level training in information security at Purdue University. Completed coursework in Burp Suite, Metasploit, Kali Linux, capstone projects, and collaborative assignments that prepared for professional roles.
CV writing guide
- Show depth in exploit validation and practical remediation communication.
- Include examples across web, network, cloud, and identity attack surfaces.
- Demonstrate responsible testing methodology and scope discipline.
- OffSec Certified Professional (OSCP)
- GIAC Penetration Tester (GPEN)
- eLearnSecurity Web Application Penetration Tester (eWPT)