There are a number of reasons why your business might be looking to hire a penetration tester. For many businesses, their first penetration tests come at the request of a potential business partner. To close a big deal, the partner asks you to hire a penetration tester to verify the security of software . As part of the contract, you’ll categorize the vulnerabilities they uncover and fix any significant issues. Other companies want to do penetration testing as part of their process to increase their security. Perhaps your company is trying to secure a major investment, take on larger clients, or is on the verge of an acquisition.

Whatever the reason, choosing who to do your penetration testing is a process you’ve never done before. Typically, you need to find someone on short notice. However, you don’t want to find someone who will do a poor job, and you don’t want to pay more than their skills are worth. A penetration test is an opportunity for your business to improve your security posture. Many businesses make the mistake of paying for a real penetration test, then promptly ignoring all the results.
So how do you choose the right pentester, quickly and at a price that fits your budget? In this article, we will look at some tips on how to find the right person.
Use your professional network
This tip seems obvious, which is why it’s the first on the list. It’s also a tip that business. Many business leaders will pass on the research for a penetration tester. Assigning a task like this may not seem like a lot to you, but if you do the evaluation of potential testers yourself, you will definitely make the best choice, especially if you also get recommendations for specific people or companies that do penetration testing from your professional circle.
Using your network to find a pentester is more than just asking who is good. Instead, you can use your network to get a feel for the skills of the person you are likely to hire. For example: the most critical skill for a penetration tester is communication. At the end of a contract, your pentester will create a report. This report will outline the vulnerabilities they found, how they found them, and their relative severity. A key aspect of this report is that it is designed to be understandable by both technical staff and business leadership. This means you need to find someone who is an excellent communicator.
Beyond understanding the basic skills and communication styles, another thing your professional network can guide you on is the testing methodology. Like professionals in all fields, penetration testers have their own working style. Some tend to keep it to themselves, while others share their work style with the teams they work with. Some simply document every vulnerability, while others will sit down with your technical staff and explain where a vulnerability came from and how to avoid it in the future.
By talking to people in your professional network, you can ensure that the tester you hire meets the needs of your team.
Check their certifications
In most of the tech world, certifications don’t play a huge role. Not so in the world of penetration testing. There are some penetration testing certifications that are very important. If your pentester has one (or more) of these certifications, you can be sure that they know the basic level of skills. The best security certifications also come with an ethics component, which certifies that the tester will not use the knowledge they have gained about your system to later break in. You don’t want to hire a pentester to find vulnerabilities in your system, only to end up stealing your customers’ data.
In the world of penetration testing, three certifications are considered pretty good:
- The Certified Ethical Hacker certification
- GIAC Penetration Tester Certification
- The Offensive Security Certified Professional certification
Any tester with one of these certified certifications is likely to serve your business well.

Make sure they have experience
Penetration testing is a tough field. As a rule, you don’t want to hire someone who is just starting out. Your company pays good money to hire someone to find vulnerabilities in your software. They really have to do this. Unfortunately, it can be difficult to know if your pentester is very skilled. The fear is doubly so if they don’t have any certifications. Sure, if they’ve participated in a dozen penetration tests, for example, but haven’t had someone you trust verify it for you, you don’t know how well they did. It’s just as likely that all of their previous work is covered by an NDA (non-disclosure agreement).
Many larger companies (like Google) will run bug bounty programs, where they pay security researchers to find bugs in software . This is not a true penetration test, but it is very close. Finding a pentester who has been through a vulnerability bounty program with one or more companies is likely to be a good choice. Knowing how to identify and describe bugs means they have many of the required skills necessary to be a good penetration tester. Bug bounties also serve as a good test of someone's ethics. A tester who finds a vulnerability and responsibly discloses it to the responsible company is likely to be someone you can trust.
An even better test of ethics is public vulnerability disclosure. This is a process in which security researchers publicly disclose vulnerabilities in various software without being paid. Perhaps software has appeared in a database. Finding publicly disclosed vulnerabilities is not fun, but it is better than learning about them because someone exploited them.
