This is where the second pass actually plays out, the last gate before an interview hits your
inbox. The recruiter slows down right here, and even then your current role still drives
around 95% of the decision.
Makes sense: nothing tells a hiring team what you can run in production right now the way your
current job does. To clear that "yes", this section has to walk the full
Penetration Tester role profile, one bullet per slot you listed in Domain
Expertise above. Every bullet has to come off something you actually held in production,
not a Jira card that wandered past your queue.
1
External Network Penetration Testing
You break in from the outside, the way a real attacker would. One exposed service is all an attacker
needs, so hiring managers want proof you found the foothold before they did. Talk about how you used
OSINT and service enumeration, with Nmap and Shodan, to land footholds and report critical findings.
Techniques
OSINT & ASM
Service enumeration
Credential discovery
Initial-access chains
Tools
Nmap, Masscan, RustScan
Amass, Subfinder, httpx
Shodan, Censys, GitHub dorking
Metrics
External engagements/year
Footholds achieved
Critical findings
2
Internal Network & Active Directory Exploitation
You go from a single foothold to domain admin. Getting domain admin is the money shot of an internal
test, so hiring managers want the path you actually walked, not theory. Show them how you used
Kerberoasting and ADCS abuse, with BloodHound and Impacket, to reach domain admin and map the paths that
got you there.
Techniques
Kerberoasting & AS-REP
NTLM relay & coerced auth
ADCS abuse (ESC1-13)
ACL & GPO paths
Tools
BloodHound, SharpHound
Impacket, NetExec, Rubeus
Certify, Certipy, Mimikatz
Metrics
Domain admin time-to-compromise
Internal engagements/year
Critical AD findings
3
Web Application Penetration Testing
You crack web apps through auth, injection, and logic flaws. Hiring managers look here to see whether
you find the auth-bypass chain, or just re-run a scanner. Point out how you used auth and injection
testing, in Burp Suite Pro with sqlmap, to chain an auth bypass into a critical finding.
Techniques
OWASP Top 10 + Top 10 LLM
AuthN/AuthZ chains
SSRF, RCE, deserialization
GraphQL & API testing
Tools
Burp Suite Pro, Caido
OWASP ZAP, sqlmap
Postman, Insomnia, ffuf
Metrics
Web engagements/year
Critical web findings
Auth-bypass chains
4
Mobile, API & Cloud Penetration Testing
You hit the mobile apps, APIs, and cloud accounts too. Two things ride on it for a hiring manager: cloud
privilege-escalation paths, and the sensitive data you could actually exfiltrate. Mention how you used
cloud IAM path mining and metadata abuse, with Pacu and ScoutSuite, to find privilege-escalation paths
to sensitive data.
Techniques
Mobile dynamic analysis
Cloud IAM path mining
S3 / blob misconfig
Metadata service abuse
Tools
Frida, Objection, MobSF
Pacu, CloudSploit, Prowler
ScoutSuite, weirdAAL
Metrics
Mobile/cloud engagements/year
Cloud-priv-esc paths found
Sensitive data exfil chains
5
Red Team & Adversary Emulation
You emulate a real adversary, EDR evasion and all. EDR-evasion success is a measurable result, so hiring
managers weigh objectives achieved, not tools run. Walk them through how you used C2 tradecraft and EDR
evasion, with Cobalt Strike and Sliver, to hit objectives and raise your evasion success rate.
Techniques
C2 OPSEC tradecraft
EDR & AV evasion
Adversary emulation (ATT&CK)
Purple-team collaboration
Tools
Cobalt Strike, Sliver, Mythic
Havoc, Brute Ratel
Atomic Red Team, CALDERA
Metrics
Red-team engagements/year
Objectives achieved
EDR-evasion success rate
6
Social Engineering & Phishing Campaigns
You phish the humans, not just the machines. People are the softest target, so hiring managers read a
real credential-harvest campaign as testing the whole attack surface, not half of it. Lay out how you
used pretext design and token theft, with GoPhish and Evilginx, to harvest credentials and land
footholds.
Techniques
Pretext design
Credential harvest
Token theft / MFA fatigue
Vishing & on-site
Tools
GoPhish, Evilginx, Modlishka
SET, ResponderForge
SpiderFoot, Maltego
Metrics
Campaigns run
Credential rate
Footholds via SE
7
Reporting, Remediation & Client Briefing
You turn findings into a report the client can act on. A test is only worth the fixes it drives, so a
report that gets remediated tells a hiring manager you close the loop. Spell out how you used clear
executive and technical reporting, in PlexTrac, to lift the remediation rate and client NPS.
Techniques
Executive + technical report
CVSS / OWASP risk scoring
Remediation guidance
Retest & close-out
Tools
PlexTrac, Dradis, Sysreptor
Markdown + LaTeX pipelines
Confluence, Notion, Jira
Metrics
Remediation rate
Reports delivered on schedule
Client NPS
8
Tooling & Workflow
You script the repetitive parts of an engagement. Firms keep the testers who build reusable tooling, not
the ones who start from scratch each time, so this shows up fast. Tell them how you built reusable
tooling and engagement runbooks, in Git with Python, to cut engagement setup time.
Techniques
Secure-by-default templates
Internal CLI / runbooks
Inner sourcing
Self-serve docs
Tools
Git, GitHub
Bash, Python, Go
Backstage TechDocs
Metrics
Templates maintained
PR cycle time
Secure-onboarding ramp cut