# Pentesting as Income A working document on monetizing offensive security skills, ranked certifications, career paths, the AI red team niche, and the OpenAI/Codex usage question. ## 1. Certifications, Ranked The market splits certs into three groups: practical/hands-on (high signal, what skilled hiring managers care about), enterprise/HR-filter (compliance theater, but unlocks bidding on government and Fortune 500 contracts), and emerging (HTB, BSCP, vendor-specific). | Cert | Vendor | Cost (USD) | Format | Validity | Tier | |------|--------|------------|--------|----------|------| | OSCP | OffSec | ~$1,649 (Learn One) | 24hr practical + report | 3 yr | Baseline practical | | OSEP | OffSec | ~$1,999 | 48hr practical | 3 yr | Senior AD/evasion | | OSWE | OffSec | ~$1,999 | 48hr code-review/web | 3 yr | Senior web | | OSED | OffSec | ~$1,999 | 48hr exploit dev | 3 yr | Senior binary | | OSCE3 | OffSec | bundle | three above | 3 yr | Top-tier portfolio | | CRTO | Zero-Point Security | ~£365 | 48hr practical (Cobalt Strike lab) | none | High-respect red team | | CRTO II | Zero-Point Security | ~£499 | practical advanced | none | Senior red team | | CRTP | Altered Security | ~$249 | 24hr AD lab | none | AD specialist starter | | CRTE | Altered Security | ~$549 | 48hr AD lab | none | Senior AD | | PNPT | TCM Security | ~$499 | 5-day + report + debrief | 3 yr | Practical mid | | eCPPTv2 | INE Security | ~$400 (with subscription) | practical | none | Stepping stone | | eWPTX | INE Security | ~$400 | practical web | none | Web mid | | GPEN | SANS/GIAC | ~$10,000 (incl. SEC560) | proctored MC | 4 yr | Enterprise HR | | GXPN | SANS/GIAC | ~$10,000 | proctored MC | 4 yr | Enterprise senior | | GWAPT | SANS/GIAC | ~$10,000 | proctored MC | 4 yr | Enterprise web | | CEH | EC-Council | ~$1,199 | MC + optional practical | 3 yr | HR filter only | | HTB CPTS | Hack The Box | ~$210 | 7-day practical | 3 yr | Rising baseline | | HTB CBBH | Hack The Box | ~$210 | 7-day practical (BB) | 3 yr | Rising web | | HTB CWEE | Hack The Box | ~$210 | 10-day practical web | 3 yr | Rising senior web | | BSCP | PortSwigger | $99 | online practical | none | Best web cert/$ | Reference URLs: - OffSec catalog: https://www.offsec.com/courses/ - Zero-Point Security: https://www.zeropointsecurity.co.uk/ - Altered Security: https://www.alteredsecurity.com/ - TCM PNPT: https://certifications.tcm-sec.com/pnpt/ - SANS/GIAC: https://www.giac.org/ - HTB Academy certs: https://academy.hackthebox.com/preview/certifications - PortSwigger BSCP: https://portswigger.net/web-security/certification **Ranked by salary impact and HR-filter power (combined):** 1. **OSCP** — still the universal industry floor. Most pentest job postings list it by name. 2. **OSEP** — the single largest jump in interview-callback rate after OSCP for red team roles. 3. **CRTO** — best price/respect ratio; hiring managers at boutique consultancies read this as "this person can actually drive a C2." 4. **OSWE** — opens the door to product-security and web-app-focused consultancy work. 5. **OSCE3** — portfolio-level signal, gets past senior-pentester filters. 6. **GPEN/GXPN** — only worth it if employer pays; GIAC certs unlock federal/DoD work via DoD 8570/8140. 7. **HTB CPTS / CWEE** — gaining respect fast among technical interviewers. Cheap, hard, very practical. 8. **BSCP** — $99 for a credible web-app credential. No-brainer regardless of seniority. 9. **CRTP/CRTE** — high signal for AD specialists; cheap. 10. **PNPT** — well-regarded mid-tier; cheaper alternative to OSCP for some hiring managers. 11. **eCPPTv2 / eWPTX** — useful résumé filler, low ceiling. 12. **CEH** — buy only if a government/Big 4 contract demands it. ## 2. Career Paths ### Internal / Corporate Red Team Banks, FAANG, defense primes, large healthcare. The job is usually less varied than consulting (one network, indefinitely), but pay and stability are high. Comp ranges (US, total comp incl. equity, 2025-2026): - 0-2 yr: $90-130k - 2-5 yr: $140-200k - 5+ yr senior / staff: $220-400k+ (FAANG staff red team can exceed $500k with stock) Remote-friendly at most tech companies, less so at banks and defense. ### Boutique Pentest Consultancies Higher base, less equity, more variety, exposure to novel research. Day rates billed to clients $2,500-5,000/day; consultants see roughly 30-50% of that as comp. | Firm | Focus | Hiring | Comp tier (senior) | Reputation | |------|-------|--------|-------------------|------------| | Bishop Fox | App/cloud/red team/Cosmos CTEM | https://bishopfox.com/careers | $180-280k | Top-tier | | NCC Group | Broad, incl. crypto/hardware | https://www.nccgroup.com/us/careers/ | $150-230k | Top-tier, UK-anchored | | Mandiant (Google Cloud) | IR, red team, threat intel | https://cloud.google.com/security/mandiant/careers | $200-350k | Top-tier brand | | Trail of Bits | Smart contracts, crypto, binary | https://www.trailofbits.com/careers | $200-400k | Elite research | | IOActive | Hardware, embedded, automotive | https://ioactive.com/careers/ | $170-260k | Elite hardware | | Praetorian | App/cloud/AD | https://www.praetorian.com/careers/ | $180-280k | Strong | | Atredis Partners | Hardware, binary, deep research | https://www.atredis.com/careers | $200-350k | Elite low-volume | | Doyensec | Web/cloud research | https://www.doyensec.com/careers.html | $180-280k | Boutique elite, EU-friendly | | Include Security | App/cloud | https://www.includesecurity.com/careers/ | $170-260k | Solid mid | | SpecterOps | AD, BloodHound, red team | https://specterops.io/careers/ | $190-300k | Top AD shop | | GRIMM | Embedded, OT, federal | https://www.grimm-co.com/careers | $180-280k | Federal/embedded | | Cure53 | Browser/web research | https://cure53.de/ | EU rates | Elite browser | ### Big 4 / Big Consulting Deloitte, EY, KPMG, PwC, Accenture (and IBM X-Force). Comp lower (~70-80% of boutique), promotion ladder fast for those who like it. Work is heavier on compliance/PCI/SOX, lighter on novel research. Useful if you want a clearance or international placement. - 0-2 yr: $75-110k - 2-5 yr: $110-160k - 5+ yr: $160-230k ### Freelance / Solo Consultant Rates depend on niche. Web app generalist: $150-250/hr. AD red team specialist: $250-350/hr. Smart-contract auditor: $300-500/hr (or per-LOC engagement). Hardware/firmware: $300-450/hr. You will spend at least 30% of your hours on sales, scoping, and reporting. Finding clients without a network is brutal; most solo pentesters route through: - Referrals from prior employer's clients (non-compete dependent) - LinkedIn outreach to mid-market CTOs - Acting as a subcontractor for a larger firm (50-60% gross retention) - Pentest-as-a-Service platforms (next section) ### Bug Bounty as Primary Income Covered in `/home/krisyotam/dev/100x/income/bug-bounty.md`. Short version: variance is brutal; a top 1% hunter clears $300k+, the median full-time hunter clears $40-80k. ## 3. Pentest-as-a-Service / Freelance Platforms ### Synack Red Team (SRT) https://www.synack.com/red-team/ The serious one. Closed, vetted private pool. Monthly payouts ($200-2,000+ per submitted vuln depending on severity, plus hourly research credits and missions). Application process (multi-stage): 1. Online application + résumé. 2. Background check (criminal + ID). 3. Technical written assessment (multiple-choice + scenario, ~90 min). 4. Practical SRT challenge: live target with timed objectives. 5. Interview with a Synack engineer. 6. Sign NDA + onboarding. Pass rate is estimated 10-15%. Strong OSCP-level skill is the floor. ### Cobalt.io https://www.cobalt.io/pentesters Crowdsourced managed pentests. Hourly model (~$80-150/hr depending on tier and country). Application requires CV, references, and a technical interview. Easier to join than SRT but lower ceiling. Solid steady income while studying. ### HackerOne Pentest / Bugcrowd Pentest https://www.hackerone.com/product/pentest-as-a-service https://www.bugcrowd.com/products/penetration-testing/ Managed pentest gigs distinct from public BB programs. Invite-only; you build up via the BB platform first, then they tap you for paid managed work. Rates similar to Cobalt. ### Bishop Fox Cosmos / Continuous Pentest https://bishopfox.com/platform/cosmos Continuous external attack-surface testing. Generally only available to Bishop Fox employees, not freelancers. ### Other relevant - **Yogosha** (https://yogosha.com/) — EU-anchored private bug bounty + pentest platform. - **Intigriti** (https://www.intigriti.com/) — EU equivalent, very active. - **Federacy** and **YesWeHack** — smaller pools. ## 4. Specializations, Ranked by 2025-2026 Earning Potential 1. **AI / LLM red team** — emerging, low supply, rates climbing fast. $250-500/hr or salary $250-400k for staff. Covered in §5. 2. **Web3 / smart contract audit** — Trail of Bits, Spearbit, Cantina, Code4rena, Sherlock. Senior auditors clear $300-700k. Path: master Solidity, audit dozens of open-source contracts, place in Code4rena contests, get a referral. https://code4rena.com/ , https://spearbit.com/ , https://cantina.xyz/ 3. **OT / ICS / SCADA** — utilities, oil and gas, defense. SANS ICS515, GICSP cert. Limited supply of qualified people, day rates $3,000-5,000. 4. **Cloud (AWS/Azure/GCP)** — perennial high demand. Path: SEC588 (GCSA), AWS Security Specialty, Azure AZ-500, then practical via HTB Pro Labs and Pentester Academy AWS/Azure red-team courses. Altered Security and Pentester Academy run cloud red-team labs. 5. **AD red team** — high demand, mature market. CRTO/CRTP/CRTE/OSEP track. Salary $180-300k senior. 6. **Embedded / IoT / firmware** — high pay, small market. Atredis, IOActive, GRIMM hire. Path: practice on routers/cameras, JTAG/UART, learn binary analysis (Ghidra, Binary Ninja). 7. **Hardware** — niche, side-channel/glitching/fault injection. Joe Grand-tier territory. 8. **Automotive** — growing post-UN R155. NCC, IOActive, Block Harbor. CAN bus, RF, ECU reverse engineering. 9. **Mobile (iOS/Android)** — growing, stable. Frida, Objection, jadx, Ghidra, Corellium. 10. **Web app generalist** — saturated but always hireable. BSCP + OSWE is the lane. For a mathematician learning Rust who already does AD via OSCP/HTB Omniscient, the fastest-growing curves are **AI red team** and **smart-contract audit** — both reward formal-math thinking, both are still under-staffed, both pay senior-engineer salaries within 2-3 years. ## 5. AI / LLM Red Teaming The niche where supply is shortest and the OpenAI question lives. ### Programs and applications - **OpenAI Red Teaming Network** — https://openai.com/index/red-teaming-network/ . Rolling applications. Mostly paid contract engagements per project; not a salary. They look for domain experts (biosecurity, chemistry, cybersecurity, persuasion, etc.) plus traditional offensive-security skill. The application asks for a CV, research areas, and prior red-team work. Pay reported by past participants is $100-200/hr for the engagement window. - **Anthropic** — no public "red team network" enrollment as of 2025-Q4. Hiring is via standard Trust & Safety / Frontier Red Team job listings: https://www.anthropic.com/jobs . They also run targeted contract red-teams via invitation; the route in is a public research presence (papers, write-ups) plus a referral. - **Microsoft AI Red Team** — internal team; hires via https://careers.microsoft.com/ . External researchers contribute via the MSRC Researcher Portal and Zero Day Quest. - **US AI Safety Institute (USAISI/NIST)** — https://www.nist.gov/aisi . Public-private red-team consortium AISIC. - **UK AI Safety Institute** — https://www.aisi.gov.uk/ . Hires evaluators; remote-friendly for UK residents. - **Holistic AI** — https://www.holisticai.com/ - **HiddenLayer** — https://hiddenlayer.com/ - **Robust Intelligence** (acquired by Cisco) — https://www.robustintelligence.com/ - **Lakera** — https://www.lakera.ai/ . Publishes the Gandalf prompt-injection corpus; respected research output. ### Competitions and corpora - **HackAPrompt** — https://www.hackaprompt.com/ . First-mover prompt-injection contest; the dataset is the de facto field standard. - **OWASP Top 10 for LLM Applications** — https://genai.owasp.org/ - **Gray Swan AI** — https://www.grayswan.ai/ . Hosts ongoing jailbreak arenas, pays cash bounties. ### Required skillset - Solid pentest fundamentals (OSCP-level). - Transformer/attention mechanics, RLHF, RLAIF basics. Read the original GPT-2/3/4 papers, the Anthropic Constitutional AI paper, OpenAI's RLHF papers. - Prompt-injection patterns: Simon Willison's blog (https://simonwillison.net/tags/prompt-injection/), Riley Goodside's writeups, the Lakera and Gray Swan corpora. - Multi-agent and tool-use attack surfaces (function calling, MCP, Computer Use). This is where 2026 research is heading. - Adversarial ML basics: evasion, model extraction, membership inference. Nicolas Carlini's papers are the canonical reading list. ### Bug bounties paying for AI vulns Cross-link to `/home/krisyotam/dev/100x/income/bug-bounty.md`. Key programs: OpenAI on Bugcrowd, Anthropic on HackerOne, Google's AI VRP (Vulnerability Reward Program), Microsoft's AI bounty. ## 6. OpenAI Security Approval / Codex Usage for Pentest This deserves a direct answer because Kris asked it directly. ### Short answer There is **no formal "authorized security researcher" status with OpenAI** that grants permission to use ChatGPT or Codex CLI for offensive security work against third-party targets. OpenAI's Usage Policies (https://openai.com/policies/usage-policies/) and the older Business Terms govern all API and product use, and they apply equally to security researchers and everyone else. ### What the policies actually say Reading the consolidated Usage Policies (last revised Jan 2025): - You may not use the services to "compromise the privacy of others" or "engage in unauthorized activities that violate the security of any service or system." - You **may** use the services to "do security research" — explicitly carved out — provided you have authorization to test the target system. In practice this means: - **Authorized pentest engagements** (signed SOW, rules of engagement, written authorization from the asset owner): permitted. You can use Codex CLI to write payloads, analyze code, generate exploits for your authorized scope. - **CTFs, HTB, OSCP labs, your own homelab**: explicitly permitted. - **Bug bounty work within an in-scope program**: permitted. The program scope is your authorization. - **Unauthorized testing, mass scanning of third parties, building offensive infrastructure aimed at random targets**: prohibited regardless of researcher status. There is no application form, no badge, no special API tier for pentesters. You operate under the same Usage Policies as anyone else, and the burden is on you to ensure you have authorization for whatever you're testing. ### OpenAI's actual security-researcher-facing programs These are distinct from "approval to use Codex": - **OpenAI Bug Bounty Program** (Bugcrowd-hosted) — https://bugcrowd.com/openai . Pays for vulns in OpenAI's own infrastructure and products. Standard responsible-disclosure terms. - **OpenAI Cybersecurity Grant Program** — https://openai.com/index/cybersecurity-grant-program/ . $10k API credit awards for defensive AI security research proposals. Application-based. - **OpenAI Red Teaming Network** — covered in §5. Paid contract work as a domain-expert red-teamer of OpenAI's own models. Apply at https://openai.com/index/red-teaming-network/ ### Practical implication For a working pentester: keep your standard OpenAI / ChatGPT / Codex CLI account, log your engagements (SOW + RoE) per client, and use the tools as you would any other. You don't need permission beyond that. If you do unusual research at scale (mass exploit generation, etc.), open a dialogue with OpenAI Trust & Safety before, not after. For genuinely sensitive client work (signed NDA, regulated industries, classified) the cleanest answer is **don't send the client's data through any third-party API at all**. Local models are the right tool: - **DeepSeek-Coder-V2** (236B MoE, 16B active) or DeepSeek-V3 family — strong coding/exploit-dev capability, self-hostable. - **Qwen2.5-Coder-32B** — excellent local coding model, runs on a single 3090/4090 quantized. - **CodeLlama-70B** — older but established. - **Mixtral-8x22B** — general-purpose, reasonable code performance. Self-host via **vLLM** or **llama.cpp** on a workstation with enough VRAM (24GB minimum for quantized 32B, 48-80GB for larger). Stargate's GPU situation is fine for inference of 32B-class models; anything bigger wants a Mac Studio or a multi-GPU rig. ### Comparison: other vendors - **Anthropic Usage Policy** — https://www.anthropic.com/legal/aup . Similar carve-out: security research with authorization is allowed; unauthorized intrusion is not. Anthropic has no public "authorized security researcher" tier. Bug bounty via HackerOne: https://hackerone.com/anthropic . - **Google Bug Hunters / VRP** — https://bughunters.google.com/ . Public bug bounty across all Google products incl. AI. No special API-usage status. - **Microsoft Researcher Portal / MSRC** — https://msrc.microsoft.com/ . Bug bounty across MS products. Microsoft offers "Researcher Recognition" tiers but these are reputation badges, not API-policy exemptions. - **GitHub Security Lab** (Microsoft) — https://securitylab.github.com/ . CodeQL research grants, bug bounties on OSS. **Bottom line for Kris**: there is no door to knock on to get a "Codex for pentest" approval. The policy already permits authorized security work, so use it for that. For client work under NDA, run a local model on stargate or moirai. Apply to OpenAI's Red Teaming Network if you want paid AI-red-team contract work — that's the closest thing to a real "researcher status." ## 7. Tooling and Homelab You're already Linux-fluent and have BlackArch on a dedicated laptop. Coverage at the level of "what to buy and what's free." **Paid worth-it:** - **Burp Suite Pro** — $475/yr. https://portswigger.net/burp/pro . Essential for any web work. No real alternative. - **Cobalt Strike** — $7,500/yr per user. https://www.cobaltstrike.com/ . Only if employed somewhere with a license; freelancers should use one of the free alternatives. - **Nessus Professional** — $4,000/yr. https://www.tenable.com/products/nessus . Compliance/automated-vuln scanning; some engagements require it. **Free C2 (modern Cobalt Strike alternatives):** - **Sliver** — https://github.com/BishopFox/sliver . Go-based, actively developed. - **Mythic** — https://github.com/its-a-feature/Mythic . Modular, agent-agnostic. - **Havoc** — https://github.com/HavocFramework/Havoc . Hottest right now. - **Brute Ratel** — paid, harder to get a license than CS. **Adversary emulation:** - **Caldera** (MITRE) — https://github.com/mitre/caldera - **Atomic Red Team** — https://github.com/redcanaryco/atomic-red-team **Standard kit (all free):** - Network: nmap, masscan, naabu, rustscan - Web fuzz: ffuf, gobuster, feroxbuster, dirsearch - AD: BloodHound, SharpHound, PowerView, PingCastle - Cred dump: Mimikatz, Rubeus, Kekeo - AD relay: Impacket suite, Responder, NetExec (the rename of CrackMapExec — https://github.com/Pennyw0rth/NetExec) - Linux post-exploit: linpeas, pspy, LinEnum - Exploit dev: pwntools, GEF/pwndbg, Ghidra, radare2, Binary Ninja (commercial) For Rust-leaning offensive tooling, look at **RustHound** (BloodHound collector), **rustcat**, and **kageshirei** as starting points. ## 8. Pricing and Contracts for Solo Work ### Scoping A standard external pentest of a small/mid web app is 5-10 days. Internal AD assessment of a 500-user network is 10-15 days. Red team objective-based: 15-30 days minimum. Day rate $1,500-3,000 for solo, billed to client. ### Contract structure - Master Services Agreement (MSA) — terms, liability, indemnification. - Statement of Work (SOW) per engagement — scope, dates, deliverables, price. - Rules of Engagement (RoE) — what's in scope, who to call, allowed times, allowed techniques. - Authorization letter (the "get out of jail" letter, signed by an executive with authority to authorize testing). Templates worth starting from: - NCC Group: https://research.nccgroup.com/ (search "pentest agreement templates") - SANS reading-room contract templates: https://www.sans.org/white-papers/ - PTES (Penetration Testing Execution Standard): http://www.pentest-standard.org/ ### Insurance - **Errors & Omissions / Professional Liability** — $1M coverage roughly $1,200-2,500/yr from Hiscox, Thimble, or specialty cyber-insurance brokers (Coalition, At-Bay). - **General Liability** — $400-800/yr. - **Cyber liability** — separately if you handle client data. Most enterprise clients will require proof of $1-5M E&O coverage before signing an SOW. Get this before you start pitching, not after. ### Entity structure (US) - LLC taxed as S-corp once net is over ~$60-80k/yr; saves on self-employment tax. - File in your home state unless there's a specific reason for Delaware/Wyoming. - Quarterly estimated taxes. - Use a CPA who has worked with security consultants; the typical small-business CPA misunderstands the industry. ## 9. Building a Reputation The currency is public work. Hiring managers and clients both Google your name. - **Writeups**: HTB walkthroughs (after machines retire), CTF retrospectives, novel research. Pick a focus — one well-researched AD or web post per quarter beats ten shallow ones. - **CVEs**: aim for 2-3 per year under your name. Pick a product, audit it properly, follow responsible disclosure, publish the writeup after the patch. - **Tools**: release one substantial open-source tool. SpecterOps' careers were largely built on BloodHound; HarmJ0y's on PowerView. A Rust port of an existing slow Python tool is a high-leverage move for you specifically. - **Talks**: progression is BSides local → BSides bigger city → DEF CON village (AppSec, Cloud, AI) → DEF CON main / Black Hat → OffensiveCon (the technical bar is highest), Recon.mtl, NorthSec, ShmooCon (US), BlueHat (MS), Insomnihack (CH). - DEF CON: https://defcon.org/ - Black Hat: https://www.blackhat.com/ - OffensiveCon: https://www.offensivecon.org/ - Recon: https://recon.cx/ - NorthSec: https://nsec.io/ - ShmooCon: http://shmoocon.org/ - **Infosec Twitter/X / Mastodon**: the network effect is real. Follow and engage with: SwiftOnSecurity, gentilkiwi, harmj0y, _wald0, dirkjanm, mubix, hasherezade, taviso, halvarflake, Carnal0wnage. Bluesky and Mastodon (infosec.exchange) have most of the same crowd now. ## 10. Realistic 12-Month Plan **Months 1-2: finish OSCP** - Complete remaining HTB Omniscient track + OffSec Proving Grounds machines. - Schedule and pass OSCP. - Buy BSCP at $99 the same week as OSCP passes; clear it in 2-4 weeks. **Months 3-4: income floor + AD depth** - Apply to Cobalt.io (easier, faster) and Synack Red Team (harder, higher ceiling). Aim for both. Cobalt should pay first. - Knock out CRTP ($249, 30-45 days of evenings) — Active Directory in a serious lab. - Start a public writeup cadence: one HTB retired-machine writeup per fortnight on the krisyotam.com notes site. **Months 5-7: specialize toward AI red team** - Read in this order: GPT-2/3/4 papers, Constitutional AI (Anthropic), OpenAI's RLHF papers, OWASP LLM Top 10, Carlini's adversarial ML papers, Simon Willison's prompt-injection tag end-to-end. - Compete: HackAPrompt past events, Gray Swan jailbreak arenas. Place in something. - Publish one substantial original AI red-team piece (e.g. novel attack against multi-agent tool use, or a Rust harness for systematic prompt-injection fuzzing). - Apply to OpenAI Red Teaming Network and Anthropic's Frontier Red Team contract roles. The published research is the application. **Months 8-9: senior credentials** - CRTO (£365, weekend lab). Apply to OSEP if budget allows. - Pitch krisyotam.com + the published research + the CRTO + OSCP to two boutique consultancies (Bishop Fox, Doyensec, SpecterOps, Trail of Bits). Target a senior-engineer / senior-consultant slot, not entry-level. **Months 10-12: optimize income mix** - Settle into the highest-paying single source (likely SRT + 1-2 boutique freelance referrals + occasional OpenAI Red Team contract). - Open an LLC, get E&O insurance, file as S-corp once net trends past $80k. - Optional: CFP for BSides + DEF CON AI Village 2027 with the year's published research. By month 12 the realistic income mix is: $40-80k from Cobalt/SRT, $20-60k from referral freelance, $5-25k from OpenAI/Anthropic contract red-team work, plus any boutique salary if a full-time role was the chosen exit. Total reachable: $120-250k in year one of monetization, with a clear runway into $250-400k by year three on the AI red-team curve.