NSXNational Skills ExchangeSign in
Back to Framework

Penetration Testers

SOC 15-1299.04Job Zone 4 · Considerable Preparationv.26.05

Context coveredThis framework covers offensive security and penetration testing practice across network, application, cloud, and enterprise environments, from supervised entry-level assessments through executive leadership of organizational red team programs.

Emerging
Entry / Apprentice
  1. Basic penetration testing tools and scanning utilitiesexecute under direct supervision to enumerate open ports and services on a controlled lab network.
  2. Common vulnerability databases and CVE repositoriesreference and interpret to identify known weaknesses in target systems during guided assessments.
  3. Operating system software environments including Linux and Windowsnavigate and configure under direction to support initial reconnaissance activities.
  4. Structured test plans and assessment checklistsfollow precisely to conduct entry-level security scans within a defined scope and rules of engagement.
  5. Program and system malfunctions identified during testingdocument observations and escalate to senior testers for diagnosis and remediation guidance.
  6. Network security and VPN equipment softwareoperate under supervision to establish secure testing connections and monitor basic network traffic.
  7. Technical findings from automated vulnerability scannerscompile into preliminary reports using standardized templates under reviewer oversight.
  8. Database user interface and query softwareapply foundational SQL knowledge to test for basic injection vulnerabilities in supervised web application assessments.
  9. Reading comprehension skills and vendor security advisoriesapply to understand patch notes, exploit disclosures, and testing prerequisites before each engagement.
  10. Organizational security policies and rules of engagementadhere to with strict attention to detail to ensure authorized-only testing on client systems.
Developing
Mid-level / Established
  1. Multi-phase penetration testing methodologiesexecute with reduced oversight across network, web application, and social engineering test vectors in client environments.
  2. Exploitation frameworks such as Metasploit and custom scriptsdeploy independently to validate discovered vulnerabilities and demonstrate proof-of-concept exploits.
  3. Operating system and application server softwareanalyze configurations and misconfigurations to identify privilege escalation paths on enterprise infrastructure.
  4. Complex problem-solving techniquesapply when encountering non-standard defenses or unexpected system behaviors during live penetration engagements.
  5. Intermediate-level assessment reportsauthor with clear technical narratives, risk ratings, and remediation recommendations for both IT staff and business stakeholders.
  6. Database management system softwaretest for authentication bypass, privilege abuse, and data exposure vulnerabilities in routine client database assessments.
  7. Cloud-based management software and infrastructureassess for misconfigured permissions, exposed storage buckets, and insecure API endpoints in cloud tenancy reviews.
  8. Staff and end users reporting security incidentsassist in troubleshooting and correlating symptoms to identify whether issues stem from active compromise or system malfunction.
  9. Object-oriented and scripting development environmentswrite and adapt exploit proof-of-concept code to validate specific vulnerability classes in target applications.
  10. Inductive reasoning and pattern recognitionapply across multiple client engagements to identify recurring vulnerability trends and refine testing efficiency.
Proficient
Senior / Expert IC
  1. Full-scope penetration testing engagementsplan and execute autonomously across network, application, cloud, and physical attack surfaces for complex enterprise clients.
  2. Advanced persistent threat simulation and red team operationsdesign and conduct to replicate realistic adversary tactics, techniques, and procedures against hardened environments.
  3. Non-routine system malfunctions and anomalous behaviors encountered during testingdiagnose independently and differentiate between pre-existing issues and artifacts of the assessment.
  4. Custom exploit development and tool creationproduce using expert system software and development environments to address gaps where commercial tooling is insufficient.
  5. Business problem analysis and integrated security risk modelingperform to translate technical findings into quantified business impact for executive decision-making.
  6. Computer-aided design and network architecture diagramsinterpret and leverage to identify architectural weaknesses and high-value lateral movement paths before active testing begins.
  7. Comprehensive penetration test reports and executive briefingsdeliver independently with precise written and oral communication tailored to both technical and non-technical audiences.
  8. Adversarial threat intelligence and emerging exploit researchsynthesize continuously to keep testing methodologies current with real-world attacker capabilities.
  9. Judgment and decision-making in high-stakes testing scenariosexercise with disciplined cautiousness to halt or modify test activities when unplanned system impact is detected.
  10. Integrated production system assessments and regression testing programscoordinate alongside development and operations teams to embed security validation into software delivery pipelines.
Advanced
Lead / Principal / Executive
  1. Organizational penetration testing strategy and program maturity roadmapdefine and champion at the executive level to align offensive security capabilities with enterprise risk posture.
  2. Enterprise-wide red team and adversary simulation programsarchitect and oversee, setting scope, methodology standards, and success criteria across multiple concurrent engagements.
  3. Junior and mid-level penetration testersmentor and develop through structured coaching, technical review, and career progression frameworks within the security organization.
  4. Cross-functional security improvement initiativeslead by translating red team findings into prioritized remediation programs coordinated across engineering, operations, and compliance teams.
  5. Novel attack research and proprietary tooling innovationsponsor and direct to advance the organization's offensive security capabilities beyond commercially available solutions.
  6. Organizational security policies, testing governance frameworks, and rules of engagement standardsauthor and maintain to ensure legally compliant and ethically sound testing practices at scale.
  7. Executive and board-level security briefingsdeliver with authoritative oral and written communication, contextualizing technical risk findings within strategic business objectives.
  8. Industry partnerships, threat intelligence consortia, and external research communitiesrepresent the organization within, fostering knowledge exchange that elevates internal team expertise.
  9. Staffing, budget allocation, and technology investments for the penetration testing practicemanage with accountability for demonstrating return on security investment to organizational leadership.
  10. Education and training curricula for offensive security disciplinesdesign and institutionalize to build a continuous pipeline of competent practitioners aligned to evolving threat landscapes.

AI-at-Work Competency Framework

A 4-level framework describing how a worker at each mastery level uses, directs, and evaluates AI tools in this occupation. Each statement cites its evidence inline. Subscribe for $19.99/mo to read the full framework — or sign in if you have a subscription.

  1. Emerging
  2. Developing
  3. Proficient
  4. Advanced
Monthly subscription · Stripe-hosted · unlocks AI-at-Work and Pathsmith Durable Skills across the full library

Ten durable-skill domains mapped to four proficiency levels for this occupation. Subscribe to unlock the full Pathsmith Durable Skills Framework across all 1,016 occupations.

Monthly subscription · Stripe-hosted · unlocks AI-at-Work and Pathsmith Durable Skills across the full library
Show O*NET source anchors42 anchors · skillscrosswalk.com

O*NET enrichment · skillscrosswalk.com

Suggest an O*NET correction

Source anchors that ground each statement

Related titles
Application Security Assessor · Application Security Hacker · Application Security Tester · Certified Hacker · Certified Tester · Consulting Advisory Tester · Cyber Analyst · Cyber Assessment Tester · Cyber Assessor · Cyber Security Engineer · Cyber Security Tester · Cyber Tester
RAPIDS apprenticeships
O*NET skills
Critical ThinkingReading ComprehensionActive ListeningComplex Problem SolvingSpeakingJudgment and Decision MakingWritingActive Learning
Knowledge domains
Computers and ElectronicsEnglish LanguageMathematicsEngineering and TechnologyCustomer and Personal ServiceAdministration and ManagementEducation and TrainingDesign
Abilities
Written ComprehensionOral ComprehensionDeductive ReasoningOral ExpressionInductive ReasoningInformation Ordering
Work styles
Attention to DetailDependabilityIntellectual CuriosityIntegrityCautiousnessInnovation
Technology
Data base user interface and query softwareExpert system softwareOperating system softwareDevelopment environment softwareObject or component oriented development softwareData base management system softwareApplication server softwareNetwork security and virtual private network VPN equipment softwareComputer aided design CAD softwareCloud-based management software
Tasks · seed anchors for statements
  1. Troubleshoot program and system malfunctions to restore normal functioning.
  2. Provide staff and users with assistance solving computer-related problems, such as malfunctions and program pr
  3. Test, maintain, and monitor computer programs and systems, including coordinating the installation of computer
  4. Use the computer in the analysis and solution of business problems, such as development of integrated producti
CIP education codes
11.010111.030111.040111.070111.100526.110326.110430.080130.160130.300130.310140.051243.040351.2706

Sources: O*NET v30.2 (CC BY 4.0), SkillsCrosswalk.com, LER.me®, Anthropic Economic Index, SAFI (Jadhav & Danve, 2026), WEF Skills Taxonomy 2021, Pathsmith Durable Skills Framework. © 2026 EBSCOed.