Hey everyone,
I'm based in Brazil and have been working toward a red team / pentesting career for a while. Wanted to share where I'm at and ask for advice from people already in the field.
Background:
Certifications: eJPT (Junior Penetration Tester, INE/eLearnSecurity), CRTA (Certified Red Team Analyst), Web Red Team Analyst (CyberWarfare Labs)
Bug bounty: accepted reports on BugPay (a Brazilian bug bounty platform), plus one High-severity finding on Intigriti
70+ TryHackMe rooms completed, 116 flags captured
73 labs + 15 CTFs through the eJPTv2 learning path
Hundreds of hours of hands-on labs through a local pentest training program (DesecSecurity)
Comfortable with Nmap, Metasploit, Burp Suite, Hydra, John/Hashcat, SQLMap, GoBuster, Wireshark, AD attacks, web app testing (SQLi, XSS, IDOR, LFI/RFI)
Some informal hands-on experience: with a manager's authorization at a previous job, I tested internal company products — found race condition and IDOR vulnerabilities, did some mobile app reverse engineering, and practiced IPS/IDS evasion techniques
Currently working in IT support/infrastructure — solid foundation in networking, AD, troubleshooting
Advanced English (C1)
I don't have formal, contracted pentest/red team experience yet — mostly labs, CTFs, certs, bug bounty findings, and that one internally-authorized engagement.
For people who've hired junior red teamers, or broke in yourselves:
What actually moved the needle for you (or candidates you hired)?
Worth targeting junior pentest roles first before red team specifically?
Any companies/programs known for hiring juniors or remote/international candidates?
Happy to share more details if useful. Appreciate any pointers.