Offensive security careers in South Africa: a field guide
Somebody has to break in before criminals do — and companies pay well for it. South Africa's offensive security market has matured from a niche into a career path with defined entry points.
Penetration testers are the core role: scoped, authorised assessments of networks and applications, ending in reports boards actually read. Consultancies hire continuously and certification (CEH and beyond) is the standard screening filter.
Red teams sit a tier deeper, emulating real adversaries over weeks against mature defences — usually a second job in security, not a first. Bug bounty work rounds out the field: global platforms pay per finding, and several local hunters earn serious side income legally.
The entry pattern is consistent: fundamentals (networking, Linux, scripting), then an ethical hacking certification, then relentless lab practice on deliberately vulnerable systems.
What separates hired candidates is evidence of process — enumerate, exploit, document — because clients buy the report, not the hack. Training that drills methodology delivers exactly that.