▲ 1 r/cybersecurityindia+1 crossposts

0 YOE, OSCP certified – What salary should I ask for Red Team roles in Delhi NCR?

Hey everyone,

I’m preparing to apply for entry-level Red Team / Offensive Security roles in Delhi NCR (Noida, Gurgaon, Delhi). I’d love some guidance on what salary I should ask for and what’s realistic so I don’t get lowballed—or price myself out.

My profile:

· Experience: 0 years (fresher). No prior full-time job.

· Certifications: OSCP

· Skills: AD attacks, web pentesting, basic priv esc, Python scripting, comfortable with Kali, C2 basics, report writing.

· Education: bca 5th Semester currently

· Location: Strictly Delhi NCR only.

My main questions:

  1. What fixed CTC should I quote when HR asks? I was thinking 7–9 LPA – is that fair or delusional for NCR with just OSCP and no experience?

  2. What kind of companies in NCR actually hire freshers for offensive security (not SOC)?

  3. Anyone who landed a Red Team role as a fresher with OSCP – what was your first offer, and how did you negotiate?

Brutal honesty appreciated. Tear it apart if needed. Thanks!

reddit.com
u/Comfortable-Joke7970 — 13 days ago
▲ 4 r/offensive_security+1 crossposts

19, BCA student, cleared OSCP after 3 years of prep. Now I'm burnt out and don't know if I should stay in pentesting or shift to defensive security. Need honest advice.

I need genuine career advice from people working in the industry. Not "follow your passion" or generic motivation. I want real talk about what makes sense practically and financially.

My background:

· 19 years old

· BCA, currently 5th semester (degree not complete yet)

· Spent roughly 3 years heavily preparing for cybersecurity/pentesting

· Cleared OSCP

· Hands-on experience with Linux, Windows, Active Directory, networking, enumeration, privilege escalation, web attacks

· Done HTB/OffSec labs and technical write-ups/documentation

· No full-time work experience

· No other certifications

· No SIEM/SOC experience

What I enjoy:

· Working with computers

· Technical documentation — taking complex technical information and organizing/documenting it

· Independent work

· Structured, process-oriented work

What I don't enjoy / am unsure about:

· I don't know if I want hardcore programming/development

· I have very little customer-facing experience and don't particularly want a client-facing role

· I don't know if I want to stay in pentesting long-term

The core problem:

I'm not sure I actually like pentesting enough to do it as a career for years.

After 3 years of grinding for OSCP, I'm exhausted. I don't necessarily hate cybersecurity — I can probably work in it. But I genuinely don't know if pentesting is what I want, or if I'm just attached to it because of sunk cost.

I'm scared that if I leave pentesting, the 3 years, the money spent on OSCP, and everything I built becomes useless. That fear is keeping me stuck.

At the same time, the idea of having to constantly chase new tools, techniques, and certs just to stay employable in pentesting sounds exhausting long-term. I'm already tired and I haven't even started my career yet.

What I want from my career (in order of priority):

  1. High income / strong earning potential

  2. Career growth

  3. Status/respect in the industry

  4. Possibility of remote work

  5. Financial stability — I don't want to constantly worry about money

  6. Quick employment — I don't want to spend several more years preparing

  7. Work that involves computers and technical thinking

  8. Documentation and structured work

  9. NOT a career that requires me to constantly learn every new technology just to stay relevant

  10. Low customer-facing interaction

If money wasn't a concern, I'd want freedom, the ability to grow my money, and to never worry about finances again. That's it. I don't have a "passion" that I'd do for free.

My question to this community:

Given my situation:

  1. Should I push through the burnout and stay in pentesting because OSCP gives me a head start, or should I shift to defensive security (SOC, detection engineering, etc.) where I might be happier long-term?

  2. Does OSCP actually hold significant value for SOC/defensive roles, or am I coping by telling myself it transfers? I need the unfiltered truth.

  3. Practically speaking, which path has better income potential, stability, and quality of life in the long run — offensive or defensive — for someone with my personality (likes documentation, structured work, low client interaction, doesn't want constant learning pressure)?

  4. Am I making a mistake by considering leaving pentesting before I've even tried working in it, or is my hesitation itself a sign that I already know it's not for me?

  5. If I choose defensive — SOC L1 as entry point — what are my realistic chances of getting hired in India within 6 months with BCA + OSCP + some SIEM self-study? And what salary range is realistic?

  6. Most importantly: if you were 19, with an OSCP, burnt out from pentesting prep, and cared primarily about money, stability, and remote work — what would you do over the next 6–12 months?

Additional context that might matter:

· I'm in India. Willing to work remotely for international employers.

· I've been told my OSCP is an advantage for SOC because I understand attacks. But I don't know if that's actually true in the real hiring market or just something people say.

· I care about money and status. I'm not going to pretend otherwise. I want to know which path pays better and is more respected.

I'm not asking for emotional reassurance. I'm asking for a practical decision framework from people who've been in this industry longer than I have.

What would you do?

---

TL;DR: 19, BCA student, OSCP certified, 3 years of pentesting prep. Burnt out and unsure if I actually want pentesting as a career. Considering shifting to SOC/defensive security. Scared of wasting OSCP. Want high income, stability, remote work, low client interaction. Should I stay offensive or go defensive? What's the realistic best move for the next 12 months?

reddit.com
u/Comfortable-Joke7970 — 13 days ago
▲ 1 r/cybersecurityindia+1 crossposts

Cleared OSCP at 19. Can I realistically get a pentesting job now?

Hi everyone,

I'm 19 years old from India and currently in the 5th semester of my BCA.

I recently cleared the OSCP and I'm looking for my first penetration testing job right now, not after graduation.

My experience is mainly in:

Active Directory attacks

Windows/Linux privilege escalation

Web application enumeration and exploitation

Network penetration testing

Pivoting and lateral movement

Strong enumeration methodology

I don't have experience with cloud security, API security, Kubernetes, or mobile security because OSCP doesn't cover those in depth.

My question is:

Is there a realistic chance of getting hired as a junior penetration tester with just OSCP while still being a student?

Should I start applying immediately, or will most companies reject me because I haven't completed my degree yet?

If you were hiring for an entry-level pentesting role, would OSCP plus practical lab experience be enough to get an interview?

I'd really appreciate honest advice from people working in offensive security. Thanks!

reddit.com
u/Comfortable-Joke7970 — 14 days ago

Cleared OSCP at 19. Can I realistically get a pentesting job now?

Hi everyone,

I'm 19 years old from India and currently in the 5th semester of my BCA.

I recently cleared the OSCP and I'm looking for my first penetration testing job right now, not after graduation.

My experience is mainly in:

Active Directory attacks

Windows/Linux privilege escalation

Web application enumeration and exploitation

Network penetration testing

Pivoting and lateral movement

Strong enumeration methodology

I don't have experience with cloud security, API security, Kubernetes, or mobile security because OSCP doesn't cover those in depth.

My question is:

Is there a realistic chance of getting hired as a junior penetration tester with just OSCP while still being a student?

Should I start applying immediately, or will most companies reject me because I haven't completed my degree yet?

If you were hiring for an entry-level pentesting role, would OSCP plus practical lab experience be enough to get an interview?

I'd really appreciate honest advice from people working in offensive security. Thanks!

reddit.com
u/Comfortable-Joke7970 — 14 days ago