Career: A 90-Day Pentest Learning Roadmap
Ninety days won't make you senior. It can make you employable-ish for junior roles if you're deliberate.
Pick web or network—not both—for the sprint. Depth beats dabbling when interviewers ask for stories.

Ninety days is enough to build habits, not mastery—exit the sprint with routines you'll keep, not a burnout trophy.
Days 1–30: foundations
HTTP, DNS, TLS, Linux CLI comfort, and one scripting language for glue. Finish a beginner lab track with notes, not speedruns.
Read one web testing primer cover to cover.
Days 31–60: guided offense
Run an intentionally vulnerable app locally. Practice recon, proxy workflow, and writing a mock report weekly.
Set up Burp or equivalent properly
Learn one scanner's limits by comparing to manual checks
Join one community and lurk less, ask once a week
Days 61–90: ship proof
Document a capstone: lab write-up, CTF series, or responsible disclosure with redactions. Tailor resume bullets to tasks you actually did.
Consistency beats hero weekends. Show up four days a week.
Practice only on legal lab targets and platforms that grant permission.
At day ninety, schedule day one hundred one—learning plans fail when the calendar ends without a next milestone.
Small habits compound—what feels like overhead early becomes speed when deadlines hit.
Share weekly progress with one person who'll notice if you ghost the plan.
Weekly review habit
Every Sunday, write five bullets: what broke, what confused you, what to repeat. That log becomes interview stories without extra prep.
Sleep and exercise aren't optional—burned-out testers miss obvious IDORs.
Accountability
Find one accountability partner checking in weekly—solo learners stall silently.
Publish one small blog or gist per month; teaching forces structure.
Track sleep and screen time; exhaustion mimics 'I'm bad at hacking.'
Worth reading next
Start Here: SapiensHack Learning Path
Career: Building a Pentest Portfolio the Right Way
Essential Recon Tools for Web App Pentesting




Comments