The Roles · Who defends it

Penetration tester

Written from published sources

The specialist who tests defences by behaving like an attacker, inside an agreement that says exactly what is permitted. The national skills framework places it at the second or third tier, normally reached after several years in security operations, which is worth stating because the role is frequently imagined as an entry point and is in practice an advanced one.

What the day looks like

  • Reading the scope and the rules of engagement until both are unambiguous, since everything afterwards depends on them.
  • Reconnaissance, scanning and enumeration, which is most of the time and produces most of the findings.
  • Exploiting what was found, to establish impact rather than to demonstrate cleverness.
  • Documenting as it happens, because a finding reproduced two weeks later from memory is a finding somebody will dispute.
  • Writing the report, which is the deliverable the client actually buys.

What it answers for

  • Staying inside the authorised scope, at every moment.
  • Findings that are real, reproducible and ranked by what they would cost this organisation.
  • A report that the people who have to fix things can act on.

What it is measured on

  • Findings of genuine severity, rather than volume.
  • Engagements delivered to the statement of work.
  • Remediation that follows, which belongs to somebody else and reflects the report's quality.

Who it receives from

The client
Scope, rules of engagement, and the authorisation that makes the work lawful.
Threat intelligence and research
Techniques currently in use, which is what makes the simulation realistic.
Previous reports
What was found last time, and what happened to it.

Who it serves

The defenders
Evidence of what an adversary could reach, obtained safely.
Leadership
A view of exposure grounded in demonstration rather than in inventory.
The vulnerability management function
The starting list, which they then carry over time.

Who else has a stake

  • Everybody whose systems are in scope, most of whom learn about it afterwards.
  • Legal, since authorisation is what separates this work from the offence it resembles.
  • The teams whose weekend a critical finding will occupy.

What it takes

  • Depth across systems, networks and applications, and the patience for the unglamorous enumeration that precedes anything interesting.
  • Precision with scope, held under the temptation of an interesting path leading outside it.
  • Writing that an engineer can act on and an executive can weigh, in the same document.
  • Judgement about impact, since a technically real finding with no consequence spends attention a serious one needed.

What the job turns on

The technical work is shared with the adversary; the authorisation is what makes it a profession. Scope, rules of engagement and the discipline to stay inside them are the whole distinction, and they are also what makes the findings usable — a test conducted where somebody agreed it would be produces a report the organisation can act on, while anything obtained outside that boundary creates a problem rather than a finding. The good ones treat the scope document as the first deliverable rather than as paperwork preceding the real work.

The published sources

Where it leads

The work itself

The Practice covers how this work is done — triage, escalation, evidence, handover — across the whole corpus.

Read The Practice