A few years ago I was literally googling “what is an IP address.”

Yesterday, August 24, 2026, was my first day as a Cyber Field Engineer at Pentera.

I’ve written two posts about this road: the night shift where I decided to get out of the SOC, and the day OSCP+ finally landed. This is the post those two were pointing at the whole time. The plan worked.

How it happened

When I passed OSCP+ in June I wrote that the cert “isn’t the finish line, it’s the entry fee.” That turned out to be more literal than I knew. The weeks after were interviews, reference calls, and the longest wait of my life. In early August the offer came. I signed it. And on August 24, I walked in the door.

What a Cyber Field Engineer actually does

Pentera builds an automated security validation platform. In plain English: software that safely runs real attack techniques against a company’s actual environment (credential attacks, lateral movement, privilege escalation, the same chains I’ve been grinding in labs) to prove which defenses hold and which ones just look good on a dashboard.

My job is the human side of that: working with customers, running the platform in real environments, walking security teams through what the attacks found, and explaining offense in plain English. If you’ve read this blog, you know that last part is exactly what this whole site exists to practice.

Is it the classic consultancy pentester seat? No, and I won’t pretend it is. It’s something that fits me better: offense as a discipline, every day, in real environments, with a defender’s eye from my SOC years and a mandate to make the attacks understandable. The SOC taught me what the alerts look like. OSCP taught me how to cause them. This job is where both halves finally work together.

What actually got me here

No secret. The same boring list from every other post on this site:

  • The boxes. 49+ rooted machines, and every single one that humiliated me along the way.
  • The cert. OSCP+ was the proof that I could do it, not just say it.
  • The SOC. Defense wasn’t a detour. It was training.
  • This blog. Every writeup was practice at explaining an attack path in plain English, which is exactly the skill this job runs on.

To whoever is mid-grind right now

When I started, the idea of getting paid to do offensive security sounded like something that happens to other people. People with CS degrees, people who started at 15. Not a SOC analyst googling the basics between alerts.

Discipline beats talent that quits. I keep saying it because it keeps being true. If you’re on this path right now, mid-grind, not sure it’s working: it’s working. You just can’t see it yet.

And when the door finally opens, walk in like you belong there. You built the key yourself.

The blog isn’t going anywhere

New chapter, same mission. Writeups, methodology, cheatsheets, all of it continues. I still break boxes every hour I’m not at work, and now work itself is offense too. The Journey section just got its best entry so far.

Try harder. Try smarter. And if it still isn’t working… you’re not enumerating enough.