Skip to content
STRATUSWORKFORCE SCAN
Menu

Penetration Testers

Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.

$116,580 a year (for the broader BLS group this job sits in).

now
15%

of the working time. Estimate.

Kinds of work
  • 97%
  • 1%
  • 3%
31%

Measured, from Anthropic's usage data (2025). Counts help on part of a task.

Half the desk work within reach
August 2027

On the chosen pace and reliability. Estimate.

Share of the working time within reach, now to 2030

0%25%50%75%100%2027202820292030NowDesk work: 97% of the time
Chosen to Ceiling: the share
DateNow
NowEnd of 2030

What each choice means: , , , , . Every pace starts from .

At this date and pace, models finish tasks up to 4.4 h long four times in five.

How far this has come

With GPT-4, measured in March 2023, 0% of this job's working time was within reach at . With Claude 3.7 Sonnet, measured in February 2025, 0%. With Claude Mythos Preview (early), measured in April 2026, 8%. Today's estimate: 15%.

0%5%10%15%20%2023202420252026GPT-4, March 2023: 0% within reachGPT-4 Turbo (Nov 2023), November 2023: 0% within reachGPT-4o, May 2024: 0% within reachClaude 3.5 Sonnet (June 2024), June 2024: 0% within reacho1-preview, September 2024: 0% within reachClaude 3.5 Sonnet (Oct 2024), October 2024: 0% within reacho1, December 2024: 0% within reachClaude 3.7 Sonnet, February 2025: 0% within reacho3, April 2025: 0% within reachGPT-5, August 2025: 0% within reachGemini 3 Pro, November 2025: 0% within reachClaude Opus 4.5, November 2025: 0% within reachGPT-5.2, December 2025: 1% within reachClaude Opus 4.6, February 2026: 1% within reachClaude Mythos Preview (early), April 2026: 8% within reachToday (estimate), September 2026: 15% within reach
Each step is a new best model measured by METR, four in five; the dashed end is today's estimate. Point at a dot for the model.

A backcast: today's task data with the best model METR had measured by each date. It shows how fast the models have moved, not what anyone forecast at the time.

The tasks

Sorted by . 22 tasks from .

TaskKind
Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.Done more than monthly by most who do it. 7%6.7 h1.7 h to 1.7 work days9%Half by Jul 2027
Write audit reports to communicate technical and procedural findings and recommend solutions.Done more than monthly by most who do it. 7%1 work day3.3 h to 2.5 work days5%Half by Jul 2027
Identify security system weaknesses, using penetration tests.Done more than yearly by most who do it. 7%1.7 work days6.7 h to 2.5 work days0%Half by Sep 2027
Conduct network and security system audits, using established criteria.Done more than monthly by most who do it. 7%1.7 work days6.7 h to 2.5 work days0%Half by Sep 2027
Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.Done more than yearly by most who do it. 7%1.7 work days6.7 h to 1 work week1%Half by Dec 2027
Develop and execute tests that simulate the techniques of known cyber threat actors.Done more than yearly by most who do it. 7%1.7 work days6.7 h to 1 work week1%Half by Dec 2027
Develop infiltration tests that exploit device vulnerabilities.Done more than yearly by most who do it. 7%1.7 work days3.3 h to 1 work week2%Half by Apr 2028
Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.Done more than yearly by most who do it. 7%2.5 work days6.7 h to 1.3 work weeks0%Half by Apr 2028
Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.Done more than monthly by most who do it. 7%2.5 work days6.7 h to 1.7 work weeks0%Half by Jun 2028
Document penetration test findings.Done more than yearly by most who do it. 6%3.3 h1.7 h to 6.7 h49%Half by now
Identify new threat tactics, techniques, or procedures used by cyber threat actors.Done daily by most who do it. 6%3.3 h1.7 h to 1.3 work days38%Half by Nov 2026
Gather cyber intelligence to identify vulnerabilities.Done more than weekly by most who do it. 5%3.3 h1.7 h to 6.7 h49%Half by now

Within reach, per task: the share of the task's time whose instances are short enough for a model to finish at the chosen date, pace and reliability. Half by: the date half of that time comes within reach.

Jobs that share skills with this one

From O*NET's related occupations. Within reach now and by the end of 2028, long-run pace, four in five.

Where this job works

The industry groups that employ the most of it (BLS, May 2025). Counts are for the broader BLS group this job sits in.

Where the most of these jobs are

The metro areas with the most people in it (BLS, May 2025). Counts are for the broader BLS group this job sits in.