What the work involves, what it pays, and real lines you can start from. Answer a few small questions and leave with a resume.
Also called application security tester, certified tester, consulting advisory tester and cyber assessment tester.
$116,580
Median pay a year
435,370
People do this work
6
Resume lines ready for you
Pay and headcount are from the Bureau of Labor Statistics. The lines are written from what the US Department of Labor records about this work.
An example
A Penetration Tester resume, filled in
Every line below comes from the same public record as the rest of this page. The greyed parts are the ones only you can answer.
Penetration Tester
Summary
Penetration tester evaluating network system security by conducting simulated cyberattacks, assessing vulnerabilities, and investigating security incidents to enhance protection against threats
Experience
Penetration Tester
Where you worked
Month Year to Month Year
Assessed the physical security of servers, systems, and network devices to identify vulnerabilities
Conducted network and security system audits using established criteria
Developed and executed tests that simulated the techniques of known cyber threat actors
Tested the security of systems by attempting to gain access to networks and Web-based applications
Investigated security incidents using computer forensics and root cause analysis
Maintained up-to-date knowledge of hacking trends and new penetration testing tools
Skills
Core Skills
Developing testing procedures, Analyzing data, Staying informed about developments, Preparing scientific reports, Examining records or other types, Investigating suspicious activities, Searching files, Testing computer operations, Testing systems or equipment, Evaluating equipment characteristics, Amazon Web Services AWS software
Tools and software
Bash, C, C#, C++, Firewall software
Open to
On site, Remote · Active Active Secret clearance clearance
Education
Bachelor's Degree Your college, Year
Yours will not say this. It will say what you did, in your own words, and Rung writes it with you one question at a time.
Nothing to write from scratch
What to put on a Penetration Tester resume
Real duties for this job, already written the way a resume reads. Inside Rung you choose the ones that were yours.
What did you do each day?
Choose what fits, or say your own.
Assessed physical security of servers and systemsCollected stakeholder data to evaluate riskConducted network and security system auditsConfigured information systems for least accessDeveloped and executed tests simulating cyber threatsDocumented penetration test findings
becomes
On your resume
Assessed physical security of servers and systems to identify vulnerabilities and improve defenses
Conducted network and security system audits using established criteria to ensure compliance and security integrity
These are written the way a resume line reads. Rung asks which ones are actually yours, keeps your own words, and never claims work you did not do.
Then it asks for one more thing
The line that could show more, and the fact that lands it.
Make it stronger
A few lines could show more. Each one is asked, and answered by choosing.
Add what got better because you did this assessment
The line
Assessed physical security of servers and systems to reduce the risk of unauthorized access
Add what got better because you did this assessment
Pick one that fits
Reduced risk of unauthorized accessEnhanced overall security postureImproved response to potential threats
Or add your own.
In your wordsAdd it
Adding it to the line…
Added to your resume
Show what improved once the audits were completed
The line
Conducted network and security system audits using established criteria to ensure compliance and security integrity
Show what improved once the audits were completed
Pick one that fits
Streamlined security processesIdentified critical vulnerabilities fasterIncreased compliance with security standards
Or add your own.
In your wordsAdd it
Adding it to the line…
Added to your resume
Every ready answer is in plain words, never a figure. Nothing is invented to fill a gap.
What it is made of
Skills for a Penetration Tester resume
What this work is made of. Rung offers these and keeps the ones you claim.
What are you good at?
Developing testing procedures
Analyzing data
Staying informed about developments
Preparing scientific reports
Examining records or other types
Investigating suspicious activities
Searching files
Testing computer operations
Testing systems or equipment
Evaluating equipment characteristics
Analyzing risks
Interpreting test results
The work itself
What a Penetration Tester does
The public record of what this job is, in one paragraph.
Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.
What it pays
How much does a Penetration Tester make?
Annual pay across the United States. The middle figure is the median: half earn less than that, and half earn more.
25th percentile
$79,370
Median
$116,580
75th percentile
$157,500
About 435,370 people do this work in the United States.
This page is about the occupation Penetration Testers. What this job involves and what it is made of come from O*NET 30.3, the US Department of Labor's occupation database, refreshed July 2026; Rung writes those records into the plain sentences you see. Pay comes from the Bureau of Labor Statistics OEWS release for 2025. Rung is an independent service and is not affiliated with or endorsed by either agency. How Rung handles accuracy is on the accuracy page, and the full data credits are on the credits page.