Ethical Hacker
Overview and Key Facts

Education
Median Pay
Job Growth
Jobs in 2034
What Do They Do?
An ethical hacker could...Overview Listen to this section
In movies and in the media, computer hackers are often portrayed as the bad guys—criminals who steal money or important information. What if you could be a good hacker? Somebody whose job is to find security flaws in computer systems; but rather than exploiting them for personal gain, you help fix the problems before criminals can find them? That is what ethical hackers—also called "white hat" hackers—do. Companies pay them to intentionally try to break into their systems to expose vulnerabilities. It is a bit like paying somebody to try and break into your house so you can fix a broken lock or loose window if they find their way inside. If you have always dreamed of being a hacker, but do not want to break the law, this could be the career for you!Do You Have the Skills and Characteristics of an Ethical Hacker?

- Critical Thinking ?
- Original Thinking ?
- Complex Problem Solving ?
- Judgment and Decision Making ?
- Systems Evaluation ?
Core Tasks
Think about if you'd like the typical tasks an Ethical Hacker might do:Salary & Job Openings
Median Salary (Yearly Pay)
Future Jobs
Blast-Off:
(10% or higher)
(7% - 10%)
(5% - 7%)
(3% - 5%)
(0% - 3%)
Steps to Get There: Becoming an Ethical Hacker
High School Subjects to Study
Engineering
Education- Typical Degree Needed After High School Listen to this section
high school credential
Typical degree for an entry-level position: Bachelor's degree ?
Ethical hackers typically have a bachelor's degree in information technology, computer science, or a related field. However, sufficient work experience will sometimes be accepted instead of a degree. As the demand for cybersecurity professionals continues to grow, some schools are starting to offer more specific cybersecurity-related degrees. Additional professional certifications, like Certified Ethical Hacker (CEH), may be preferred. Since the field of information security changes rapidly as computer technology advances, ethical hackers must stay up-to-date on the latest advances in their industry, including the latest attacks by malicious or "black hat" hackers and the attempts by "white hat" hackers to prevent them. It is important to avoid any illegal black hat hacking activities of your own, as many ethical hacker jobs require background checks or security clearances, or even a polygraph test. A history of criminal behavior or illegal hacking, even if it was "just for fun," could ruin your prospects of a white hat hacking career.
Try it Out with an Activity or Project
STEM Activities
STEM activities are fun hands-on explorations that usually take from 10 minutes to one hour and use readily available household or classroom materials while introducing you to STEM concepts common in this career.
Science Project Ideas
Project Ideas are in-depth STEM explorations that have a strong focus on controlling variables, taking accurate measurements, and analyzing data suitable for investigating the scientific method or the engineering design process.
On the Job
Role Models
Nature of the Work
Ethical hackers are hired by companies and government agencies to expose vulnerabilities in their web and computer systems by intentionally trying to hack into those systems. However, rather than stealing information for personal gain (for example, customer credit card numbers or sensitive trade secrets), the ethical hackers tell their clients about the vulnerabilities they have found so they can be fixed. Ethical hackers could work for a large company who has internal employees to test its own systems, but many times they work for third-party consulting agencies that may be hired by many other organizations.
An ethical hacker's job may take different forms. For example, first an ethical hacker might be hired by an outside company to perform penetration testing. The company could hire the tester to do cooperative testing (where the company's employees are aware that the penetration test will take place), or they could do secretive or "blind" testing where the company's employees do not know the ethical hacker has been hired. This means they cannot tell the difference between the penetration test and a "real" attack, so it tests how the company's employees will respond. Depending on the level of cooperation versus secrecy, the ethical hackers may be given information about and access to the company's systems, or they might have to do their own research and reconnaissance (simulating the situation a real attacker would be in).
An ethical hacker may run a variety of tests to test a company's systems. Some of them may be industry-standard tests and some may be unique and developed on a case-by-case basis. For example, one standard test involves testing websites that allow users to upload files to see if they will allow the user to upload a file containing malicious code or a virus (however, the "virus" will be designed not to do any real damage to the company's systems). However, not all tests are electronic in nature. Some tests may involve "social engineering," or exploiting people to gain access to a company's systems. This could range from simply checking to see if employees keep their passwords written on sticky notes near their desks to sneaky actions intended to gain unauthorized access—like convincing a security guard to let you into a building because you forgot your ID card, or leaving a USB drive with a virus on it in the company parking lot, and hoping somebody will connect it to their computer to find out what is on it.
After completing a test or series of tests, ethical hackers will usually prepare a report on the results and any vulnerabilities that they found. They may present this report to a manager or company executives to detail the vulnerabilities they exposed, what could happen if a real criminal exploited them, and how they can be fixed to prevent future attacks.
Work Environment
Ethical hackers typically spend the majority of their time working in an office environment, usually in front of a computer. They may have meetings with other people in the office during the day, and occasionally travel for conferences and professional meetings. Most analysts work full-time (40 hours per week). Since most of the penetration tests are performed online, they may work remotely. Sometimes they might be hired to do on-site penetration testing for a client, which could require travel.
Like other workers who spend long periods of time typing on a computer, ethical hackers are susceptible to eyestrain, back discomfort, and hand and wrist problems, such as carpal tunnel syndrome or cumulative trauma disorder, but preventative measures can be taken.
More Information
Ask Questions
Do you have a specific question about a career as an Ethical Hacker that isn't answered on this page? Post your question on the Science Buddies Ask an Expert Forum.
Additional Resources
Sources
- U.S. Bureau of Labor Statistics BLS (2024). Occupational Outlook Handbook (OOH), 2024 Edition, Bureau of Labor Statistics. Retrieved August 25, 2025.
- National Center for O*NET Development O*Net Online (2024). National Center for O*Net Development. Retrieved August 25, 2025
- InfoSec Institute (n.d.). Penetration Tester. Retrieved Jan. 19, 2016.
- Symantec (October 2005). Symantec™ Application Penetration Tests. Retrieved April 25, 2016.
- Payscale (n.d.). Penetration Tester Salary. Retrieved April 25, 2016.
- Geier, E. (2012, February 15). How to Become an Ethical Hacker PCWorld. Retrieved April 25, 2016.
- SecureNinjaTV. (2014, October 17). Careers in Cybersecurity - Expert Advice from BlackHat & DEFCON. Retrieved May 16, 2016.
- Titania. (2014, May 23). A Day In The Life Of A Penetration Tester - Ian Whiting, CEO, Titania (CREST Interview). Retrieved May 16, 2016.















