Penetration Tester CV: Example and Template
A complete Swiss CV example for penetration testers with offensive security certifications, project evidence and measurable results.
Currently 1 open Penetration Tester positions in Switzerland, across 1 cantons. Deloitte advertises the most.
CV example — two-page template
This template is editable straight away — or upload your existing CV and it is carried into this layout automatically.
What qualifications do I need to become a penetration tester in Switzerland?
A computer science qualification at EFZ, HF or FH level is the most common foundation, but hands-on offensive security certifications such as OSCP are what really count.
Most Swiss job postings require a BSc in Computer Science or Business Information Technology from a university of applied sciences such as ZHAW, FHNW, HSLU or OST, or a degree from ETH or EPFL. Equally recognised is the path via an ICT Specialist EFZ followed by a Dipl. Techniker HF Informatik or the federal Cyber Security Specialist diploma of higher education. Always state your qualification in your CV using its official Swiss title and the year you completed it, so HR can correctly assess the level.
Practical certifications carry considerably more weight in the hiring process. OSCP is regarded as the de facto entry credential, and OSEP, OSWE, GIAC GPEN or GXPN, CREST CRT and Burp Suite Certified Practitioner are also well regarded. List these certificates with the year obtained and avoid mere attendance confirmations without an exam, as experienced hiring managers will spot the difference immediately.
If you want to work in the financial sector, mention experience with FINMA Circular 2023/1, ISO/IEC 27001 and the revised Federal Act on Data Protection (revFADP). For industrial and energy clients, IEC 62443 and OT knowledge are relevant, while federal and cantonal mandates call for familiarity with the NCSC and experience with security assessments in eCH-compliant environments. Such details show that you understand the regulatory framework, not just the tools.
As a beginner, how do I build professional experience in penetration testing?
Document verifiable, hands-on experience from labs, bug bounty programmes, home lab projects, and a stepping-stone role in IT operations or a SOC.
Certificates alone, without practical proof, rarely convince Swiss employers. A well-proven route is via system or network administration, application support, or a SOC analyst role: anyone who knows Active Directory, firewalls and log sources from the operational side will later identify realistic attack paths much faster. Frame these roles in your CV in security-relevant terms, for example hardening 210 servers according to CIS Benchmarks or handling 40 incidents per month.
Also include a small but verifiable portfolio section: the number of machines solved on platforms such as Hack The Box or TryHackMe, accepted bug bounty reports with severity ratings, published CVEs, your own tools on GitHub, or talks given at a meetup such as a local OWASP chapter. Numbers and links carry far more weight here than adjectives.
Expect to start as a Junior Penetration Tester on around CHF 85'000 to CHF 100'000; with three to five years of experience and OSCP, CHF 110'000 to CHF 135'000 is typical, and senior or red team lead roles can pay even more. Explicitly state in your CV that you are willing to provide a criminal record extract, undergo a personnel security clearance, and sign NDAs, as this is a requirement for bank and federal government mandates.
How long should the CV be, and is a photo necessary?
Two pages is the standard length; a professional photo is still customary in Switzerland and expected by most employers.
Keep your CV to two pages, or three at most if you have a long list of projects. Start with a brief profile, followed by work experience in reverse chronological order with month and year, then certifications, education, languages and technical focus areas. Long lists of individual engagements belong in a separate reference sheet, which you can provide on request.
A professional portrait photo, place of residence, nationality or residence permit category, and language levels according to the CEFR are all Swiss conventions. You must not name confidential clients: instead, state the industry and size, for example a retail bank with 1'200 employees, and back up your performance with figures such as the number of assessments, findings or the remediation rate.
Adapt your wording and emphasis to the job posting: if the employer requires web and API testing, put your OWASP WSTG, ASVS and Burp experience front and centre; for red teaming roles, emphasise C2 infrastructure, MITRE ATT&CK and EDR evasion. A PDF with a clear file name, an up-to-date LinkedIn profile and a short, specific cover letter round off the application.
Where Penetration Tester are hired in Switzerland
How the 1 open positions are spread across the cantons.
Figures as a table
| Canton | postings |
|---|---|
| Basel-Stadt | 1 |
Which languages the postings require
Of 1 postings that state a language — in brackets, those requiring professional level.
Figures as a table
| Language | postings |
|---|---|
| English | 1 (1) |
| German | 1 (1) |
Who hires Penetration Tester in Switzerland
Employers with the most open positions. Staffing agencies are excluded.
Figures as a table
| Employer | postings |
|---|---|
| Deloitte | 1 |
Full-time or part-time?
How the positions are advertised.
Figures as a table
| Workload | postings |
|---|---|
| Vollzeit / plein temps | 1 |
The CV in full
To read through and reuse.
Nino Brunschwiler
Senior Penetration Tester (OSCP, OSEP) · BSc Computer Science ZHAW
Senior Penetration Tester with 8 years of experience in web, infrastructure and Active Directory assessments for banks, insurers and industrial companies in Switzerland. Conducts testing in line with OWASP WSTG, PTES and NIST SP 800-115, and translates findings into prioritised, actionable measures for development and operations teams. Experienced in FINMA-relevant audits, red team simulations based on TIBER-EU logic, and in tracking remediation through to retest.
What sets me apart
Demonstrable exploit depth: Develops custom proof-of-concepts and EDR control bypasses; achieved Domain Admin in under 48 hours without triggering a SOC alert in 14 of 22 red team engagements.
Reports that get read: Two-tier report structure (management summary in German, technical section in English) with CVSS 4.0 scoring; increased the 90-day remediation rate for high findings from 54 to 88 percent.
Regulatory understanding: Familiar with the expectations of FINMA Circular 2023/1 on operational risks and ISO/IEC 27001 A.8.8, and delivers audit evidence that Internal Audit and external auditors can use directly.
Secure coding bridge: Conducts debriefings for development teams after every web assessment; after 18 sessions, recurring OWASP Top 10 findings dropped by 61 percent for one client.
Key achievements
Critical vulnerability in e-banking portal. Found a chained IDOR and JWT signature weakness that would have allowed access to 42'000 customer accounts; fix deployed to production within 6 days, retest confirmed no residual risk.
Building an in-house pentest team. Built a team of 4 testers at an insurer, cutting external engagement costs by CHF 240'000 per year and increasing tested application coverage from 31 to 79 percent.
OT assessment in production. Led a Purdue Level 2 assessment across 6 plants, identified 23 unsegmented connections, and supported the implementation of a zone-conduit architecture in line with IEC 62443.
Experience
Senior Penetration Tester — Nordwall Security AG, Zurich, since 03/2021
Offensive security boutique with 28 employees, focused on the financial sector and critical infrastructure in German-speaking Switzerland.
- Carrying out 45 to 55 engagements per year (web, API, mobile, internal infrastructure, Wi-Fi) with an average client rating of 4.8 out of 5.
- Responsible for 22 red team and assumed-breach engagements; achieved domain dominance in under 48 hours in 14 cases and documented 9 SOC detection gaps.
- Built a reusable testing toolchain (Nuclei templates, Burp extensions, Impacket wrappers) that cut the effort per infrastructure test by 1.5 days.
- Technical mentoring of 3 junior testers, including review of 130 reports and support through successful OSCP exams.
Penetration Tester / Security Analyst — Helvetica Assurance Gruppe, Basel, 08/2018 - 02/2021
In-house security testing team at an insurer with around 3'800 employees and 260 business applications.
- Built the in-house pentest programme from 0 to 60 assessments per year; increased test coverage of critical applications from 31 to 79 percent.
- Introduced threat-led testing based on MITRE ATT&CK; identified 118 findings with CVSS 7.0 or higher, 91 percent remediated within SLA.
- Integrated authenticated DAST scans into 14 Azure DevOps pipelines, catching 38 percent of findings before go-live.
- Reduced external engagement costs by CHF 240'000 per year while increasing testing frequency.
Junior Security Consultant — Bergblick IT Services GmbH, St. Gallen, 09/2016 - 07/2018
IT service provider for SMEs and municipalities, focused on networking, Microsoft environments and vulnerability management.
- Carried out 74 vulnerability assessments and 19 supervised pentests for 40 SME clients, covering 1'200 to 9'000 assets tested per engagement.
- Built a Nessus-based scanning service for 26 clients with monthly reporting; reduced recurring critical findings by 47 percent.
- Created 30 phishing simulations; reduced click rate from 24 to 9 percent over 12 months.
- Developed hardening guidelines for Windows servers based on CIS Benchmarks Level 1, rolled out to 210 systems.
Education
BSc FH, Computer Science, Information Security major — ZHAW School of Engineering, Winterthur · 2016
Federal Certificate of Proficiency (EFZ), ICT Specialist EFZ, Systems Engineering — Berufsfachschule Uzwil · 2012
OSCP - Offensive Security Certified Professional (2018) · OSEP - Offensive Security Experienced Penetrator (2022) · GIAC GPEN - Penetration Tester (2020) · Burp Suite Certified Practitioner (2023)