How I Got into the Cybersecurity Industry
From chef to penetration tester
My route into cybersecurity started well before I got my first job in the industry.
By the time I began my Cyber Security degree at Manchester Metropolitan University, I already knew cybersecurity was the career I wanted to pursue. What I didn’t have was much practical experience. Over the next few years, I set out to change that.
Alongside university, and often while working around 50 hours a week as an Italian chef during the holidays, I spent as much time as I could learning web security, completing labs, hunting for real vulnerabilities and gradually building the skills I would eventually use professionally.
Today, I work as a cybersecurity consultant specialising in penetration testing. Looking back, there wasn’t one defining moment that got me here. Instead, it was a series of small steps: courses, labs, rejected reports, duplicates, certifications, conversations with people in the industry and many hours spent practising before anyone was paying me to do it.
One vulnerability eventually gave me the breakthrough I had been working towards, but the work that made it possible had started years earlier.
Where it started
My interest in cybersecurity started when I was still at school. Between 2020 and 2022, I took part in GCHQ CyberFirst summer programmes, which introduced me to security, attack techniques and practical exploitation.
I then studied Computer Science and IT at Blackpool Sixth Form before starting my Cyber Security degree at Manchester Metropolitan University in 2023.
By that point, I knew cybersecurity was something I wanted to pursue as a career. What I hadn’t yet worked out was exactly which area of cybersecurity suited me, or how to turn what I was learning academically into practical skills. The field also felt vast.
There seemed to be an endless amount to understand, and at first I felt as though I needed to know all of it before I could properly start. I soon realised that wasn’t going to happen.
Discovering offensive security
Things started to click during the second year of my degree, when I took an ethical hacking module taught by Dr Katie Paxton-Fear, better known in the security community as InsiderPhD. That module gave me a solid introduction to web application security and bug bounty hunting.
I started working through PortSwigger Web Security Academy labs, learning how HTTP requests and responses work in practice and seeing how common web vulnerabilities could be exploited. I quickly became hooked.
Bug bounty hunting particularly appealed to me. Companies were effectively giving security researchers permission to test their systems, report vulnerabilities and potentially get paid for doing it. The idea sounded amazing. In practice, doing it was much harder.
One piece of advice from Katie made a significant difference. Instead of trying to learn every vulnerability type at once, she suggested focusing on one. For me, that was access control. Suddenly, the problem felt much smaller. Instead of jumping between dozens of techniques, I could concentrate on understanding one area properly and start developing a methodology around it.
Chef by day, hacker by night
Once I felt more confident with labs, I started testing real bug bounty programmes and submitting reports, but most of them went nowhere. Some were marked as informative. Some weren’t considered security vulnerabilities. Occasionally, I found something genuinely interesting, only to discover that another researcher had already reported it.
At the same time, I was working around 50 hours a week as a chef during university breaks. Cybersecurity was what I wanted to do long term, so outside those shifts I spent as much spare time as I could learning and hunting. Some evenings, I would read bug bounty write-ups. On others, I would listen to the Critical Thinking Bug Bounty Podcast, work through PortSwigger labs or spend hours testing a target and find absolutely nothing. I was effectively a chef by day and a hacker by night. It was tiring, and there were definitely times when it felt as though there weren’t enough hours in the day.
But bug bounty hunting gave me something I couldn’t get from studying alone: hands-on experience. I realised that you don’t necessarily have to wait for someone to give you a cybersecurity job before you can start building practical skills. By staying within each bug bounty programme’s scope and rules, I could start developing that experience myself.
Learning to see failure differently
For quite a long time, though, my total bug bounty earnings remained at exactly $0. As a student, the idea that you could make money from hacking was a significant motivation, so after putting hundreds of hours into learning and testing, that $0 became difficult to ignore.
I began questioning whether I was wasting my time. Was bug bounty hunting too saturated? Was I actually good enough? Should I just stop? The problem was that I was judging all of my progress using one metric: money.
Then I started getting duplicates more consistently. By that point, I had missed out on around $3,000 in potential bounty payouts. Initially, that was incredibly frustrating. Then I realised what a duplicate actually meant.
I was finding real vulnerabilities. Someone else had just found them first. That completely changed how I looked at my progress. A duplicate wasn’t necessarily a failure. In some ways, it was evidence that my methodology was starting to work. I hadn’t had the payout yet, but I was clearly getting closer.
The first breakthrough
Eventually, it happened: I received the email I had been waiting months for. I had been awarded a $400 bounty after finding an access control vulnerability on Audible. It wasn’t an incredibly complicated exploit chain or an obscure vulnerability. It was access control – the exact vulnerability class I had been told to focus on when I started. That made it even better.
All the labs, rejected reports, duplicates and late nights had finally resulted in a valid, paid vulnerability. It wasn’t a payout that would clear my student loan, but it would certainly pay for a certification and perhaps a Greggs sausage roll.
I shared the achievement on LinkedIn and Twitter, mainly because I was proud to have received my first bounty. I had no idea that what happened next would be worth much more to me than the $400.
Turning a hobby into a career
Around two weeks later, after being contacted on LinkedIn and completing an interview, I was offered a junior penetration testing placement with a global fintech company. Suddenly, the hours I had spent bug bounty hunting weren’t just something I did in my spare time. They were evidence of the value I could bring to an employer.
They showed that I understood web applications and could identify vulnerabilities on real systems, investigate their impact and explain what I had found. Bug bounty hunting had given me practical experience before I had ever worked professionally as a penetration tester. The placement meant I could finally move away from working in kitchens and start building experience in the cybersecurity industry.
I went on to spend a year at a global payments company, working alongside senior penetration testers. That year was a huge step for me because I could finally apply what I had been learning to real professional engagements.
Building on it
I didn’t stop learning once I got the placement. Alongside work and university, I continued bug bounty hunting and other practical training, including Hack The Box. I completed certifications including the HTB Certified Web Exploitation Specialist and HTB Certified Penetration Testing Specialist, while continuing to find and responsibly report vulnerabilities affecting major organisations across the automotive, retail and technology sectors.
I also completed my Cyber Security degree with first-class honours.
Then, in December 2025, I had the chance to stand on stage at BSides London and tell the story of how chasing my first bug bounty payout had ultimately helped me secure my first penetration testing role.
It was a little surreal to be standing on stage talking about something I had spent so long trying to achieve. What surprised me even more was the response afterwards. Several experienced cybersecurity professionals from well-known companies approached me with questions. They were genuinely interested in my approach, what I had learned through bug bounty hunting and how I had developed my methodology.
For someone who had spent so much time wondering whether I was actually good enough, that was a significant moment. It made me realise that the experience I had built along the way had value, even to people who were much further along in their careers than I was.
Where I am now
Today, I work as a cybersecurity consultant at Cyberis Reply, carrying out penetration testing and vulnerability research on live client engagements. It’s still strange to think that not so long ago I was finishing a shift in a kitchen, going home and spending my free time looking through HTTP requests.
From the outside, it would be easy to say that finding my first paid vulnerability got me into cybersecurity. I don’t think that’s completely true. The vulnerability was simply the result people could see. The things that actually got me there happened long before that report was accepted: completing another lab when I didn’t fully understand what I was doing; submitting reports and learning from the feedback when they were rejected; finding duplicates and eventually realising they represented progress; asking people with more experience for help and getting involved with the security community; and continuing to learn even when I had very little evidence that any of it was going to work.
What I would tell someone starting now
One of the biggest misconceptions I had when I started was that I needed to become an expert before I could do anything useful. I didn’t.
If I were giving advice to someone starting out, I would say: break big problems into smaller ones, learn the fundamentals and actively practise what you are learning. For web security, use resources such as PortSwigger Web Security Academy. Pick one vulnerability class, understand it properly and then apply that knowledge. Read write-ups, listen to other researchers and speak to people in the community. Ask lots of questions. And get things wrong, because you will.
Most importantly, don’t judge your progress purely by payouts, certifications or job titles. Progress isn’t always obvious while it is happening. Sometimes the thing that feels like a setback is actually teaching you exactly what you need for the next opportunity.
Looking back on my time as a chef, when I tried to fit in learning whenever I could, becoming a penetration tester felt a long way off. I simply kept learning, practising and taking every opportunity I could, improving 1% at a time, until cybersecurity eventually became my career.
Now, working at Cyberis Reply, I am surrounded by extremely talented people I can learn from. I work on the kinds of problems that genuinely interest me and continue to build on those small improvements every day.
I am still at the beginning of my career, and there is a great deal left for me to learn. I am looking forward to seeing where the next few years take me.
Improve your security
Our experienced team will identify and address your most critical information security concerns.