CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingThe roles OSCP unlocks, realistic US pay data with sources, and how holders progress to OSEP, OSWE and senior offensive security positions.

Open ten penetration testing job adverts and count how many say "OSCP preferred" or "OSCP required". The Offensive Security Certified Professional has become the closest thing offensive security has to a standard entry ticket — which makes two questions worth answering precisely: which roles does it actually open, and what do they pay? This guide maps both, then traces the progression beyond OSCP through OffSec's advanced certifications to senior offensive security roles.
For pay, one point up front: certification-tagged salary data is noisy, and figures vary sharply by source, country, city, employer type and experience. Every number in this guide is US data, named to its source and date. Treat the figures as orientation, not a promise.
The OSCP, awarded by OffSec (formerly Offensive Security) on passing the exam attached to the PEN-200 "Penetration Testing with Kali Linux" course, certifies something unusually concrete: the holder compromised real machines — three standalone targets plus an Active Directory set — during a 24-hour proctored exam, then wrote a professional report. Since November 2024, passing awards both the lifetime OSCP and the three-year OSCP+ designation.
That maps almost one-to-one onto the daily work of a consulting penetration tester: enumerate, exploit, escalate, pivot through Active Directory, document. Employers hiring for offensive roles therefore read OSCP as evidence of job-ready mechanics, not just knowledge. That signal is what powers everything in the career map below. Whether the credential justifies its cost for your situation is a different question, answered in our verdict piece on whether OSCP is worth it.
The core OSCP job. Penetration testers work either in consultancies — testing a different client network, web application or cloud estate every few weeks — or on internal security teams testing their own employer's systems. Consultancy work offers variety and rapid skill growth at the cost of report-heavy weeks and utilisation targets; internal roles trade breadth for depth in one environment and usually gentler travel. OSCP is most frequently cited in consultancy adverts, because client-facing firms need credentials that reassure customers.
Entry is realistic at two levels. Career changers and juniors typically land "junior/associate penetration tester" roles where OSCP substitutes for a track record. Experienced IT or security professionals — a system administrator strong in Active Directory, say, or a SOC analyst who understands attacker behaviour — often step directly into mid-level testing roles, because their infrastructure knowledge compounds with the certification.
Red teams run longer, stealthier engagements that simulate a real adversary against a mature defence — objective-driven, evasion-focused, often weeks per operation. OSCP alone rarely gets you hired straight into a red team: the role expects evasion tradecraft, C2 frameworks and defence-aware operations that PEN-200 does not cover. The normal route is one to three years of penetration testing after OSCP, plus an advanced credential such as OffSec's OSEP (covered below). Think of red teaming as the second rung, with OSCP as the first.
A broader consultancy role blending penetration testing with advisory work — scoping engagements, presenting findings to executives, recommending remediation programmes. OSCP provides the technical credibility; progression here depends increasingly on communication, scoping and client management. This path suits people who enjoy the testing but also want a route towards leading engagements and, eventually, practice management.
OSCP includes web attack fundamentals, and some holders specialise towards application security — code-assisted testing, secure development review, bug bounty work. This lane eventually points at OffSec's OSWE (WEB-300), the source-code-review-oriented web exploitation certification, rather than the infrastructure-focused OSEP.
Not every OSCP holder ends up on the attack side. The certification also strengthens candidacies for vulnerability management engineers, detection engineers and threat hunters (attacker knowledge makes better defenders), purple team roles, and security engineering positions that harden the systems testers break. If you are mid-career in defence and not committed to switching, OSCP can deepen your current track instead of replacing it.
The most directly relevant figure available: ZipRecruiter (accessed August 2026) reports average US pay for OSCP-tagged roles of $119,895 per year ($57.64/hour) as of July 2026.
Read that number with care:
For context against the adjacent EC-Council credential: US sources report widely varying averages for Certified Ethical Hacker holders — Payscale (2026) lists $96,490, Infosec Institute (June 2025) about $126,547, and ZipRecruiter (February 2026) $161,013 with a 25th–75th percentile band of $122,000–$214,000. The spread across sources is the real lesson: certification salary averages describe different job mixes, not different pay for the same person. Deeper CEH pay breakdowns belong to our separate CEH salary guide.
What you can bank on is the shape of progression rather than a specific figure: pay in offensive security rises steeply with proven engagement experience in the first three to five years, then with specialisation (red team, cloud, application security) and with client-facing seniority. The certification's financial payoff is concentrated at the entry point — it is the difference between being interviewed and not.
A realistic ladder, with the caveat that timelines vary enormously by prior background:
OffSec's own progression is the most common certification route for OSCP holders:
A note on maintenance: the OSCP+ designation earned alongside OSCP since November 2024 expires after three years, and one way to maintain it is passing another qualifying OffSec exam such as OSEP or OSWE — so the career-driven next certification also keeps your "+" current. The lifetime plain OSCP remains yours regardless.
The ladder is not OffSec-exclusive. Testers heading for exploit development sometimes take GIAC's advanced exploit-research track — see the GIAC GXPN exam overview — while those broadening into architecture and senior generalist roles look at advanced practitioner certifications like CompTIA's CASP/SecurityX line. EC-Council's portfolio also runs parallel; its analyst- and specialist-level exams are listed on the EC-Council exams hub.
A realistic composite, to make the ladder concrete. A Windows system administrator with four years' experience earns OSCP at 29, leveraging deep Active Directory knowledge that maps directly onto the exam's 40-point AD set. She joins a mid-sized consultancy as a penetration tester — not junior, because her infrastructure background counts. Two years of engagements later she has a specialism (AD and internal network testing), takes PEN-300 through a Learn One subscription her employer funds, and earns OSEP at 32. That combination gets her a red team operator interview at a financial services firm — where the interview panel cares less about either certificate than about her engagement stories, which the certificates got her into the room to tell. By 34 she is a senior operator mentoring the team's next OSCP candidates.
Swap the starting point — developer, SOC analyst, network engineer — and the pattern holds: prior expertise chooses your specialism, OSCP opens the first offensive door, experience plus one advanced certification opens the second.
OSCP's career value is front-loaded and structural: it converts background and lab hours into a first offensive security role — most often penetration testing, at an average US pay level ZipRecruiter puts near $120,000 across all seniorities as of mid-2026 — and from there progression runs on engagement experience, specialisation and, at the red-team and senior-consultant rung, an advanced credential such as OSEP or OSWE. Plan the certification as the start of a ladder rather than the summit, decide early whether your branch is infrastructure, applications or leadership, and let each subsequent certificate answer a specific job requirement. If you are still at the beginning of that ladder, the practical build-up to exam day is mapped in our OSCP preparation roadmap.
Yes, at junior level — that is the certification's core function. Expect junior/associate titles and pay below the averages quoted above, with rapid progression once you have client engagements on your CV. Adjacent IT experience (sysadmin, networking, development) often lets you skip the junior tier.
The plain OSCP is lifetime. The OSCP+ earned alongside it (since November 2024) expires after three years, maintainable via recertification, OffSec's CPE programme or passing another qualifying OffSec exam — which conveniently aligns with taking OSEP or OSWE as a career step anyway.
Follow your engagement mix: OSEP (PEN-300) for internal/infrastructure testing and red team ambitions; OSWE (WEB-300) for application security specialisation. Both are $1,749 bundles with 48-hour hands-on exams and non-expiring certifications, so the deciding factor is direction, not cost.
Usually not on its own. Red teams expect evasion and adversary-simulation tradecraft beyond PEN-200's scope; the common profile is OSCP plus one to three years of testing experience plus OSEP or equivalent evidence.
They exist, but income is volatile and reputation-driven; most successful independents built several years of consultancy experience first. Treat freelancing as a mid-career branch, not an entry point.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading