Career Discovery Tool
Your email has not been verified. Verify email now ›

Ethical Hacker

Overview and Key Facts

Woman typing
Education
Education
Bachelor's degree
Median Pay
Median Pay
$108,970
Job Growth
Job Growth
8.20%
(Above US Average)
Jobs in 2034
Jobs in 2034
510,500

What Do They Do?

An ethical hacker could...

Overview Listen to this section

In movies and in the media, computer hackers are often portrayed as the bad guys—criminals who steal money or important information. What if you could be a good hacker? Somebody whose job is to find security flaws in computer systems; but rather than exploiting them for personal gain, you help fix the problems before criminals can find them? That is what ethical hackers—also called "white hat" hackers—do. Companies pay them to intentionally try to break into their systems to expose vulnerabilities. It is a bit like paying somebody to try and break into your house so you can fix a broken lock or loose window if they find their way inside. If you have always dreamed of being a hacker, but do not want to break the law, this could be the career for you!
Watch this video to see interviews with multiple experts in the field of information security.

Do You Have the Skills and Characteristics of an Ethical Hacker?


  1. Critical Thinking: ?
  2. Original Thinking: ?
  3. Complex Problem Solving: ?
  4. Judgment and Decision Making: ?
  5. Systems Evaluation: ?

Core Tasks

Think about if you'd like the typical tasks an Ethical Hacker might do:
  • Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
  • Collect stakeholder data to evaluate risk and to develop mitigation strategies.
  • Conduct network and security system audits, using established criteria.
  • Configure information systems to incorporate principles of least functionality and least access.
  • Design security solutions to address known device vulnerabilities.
  • Develop and execute tests that simulate the techniques of known cyber threat actors.
  • Develop infiltration tests that exploit device vulnerabilities.
  • Develop presentations on threat intelligence.
  • Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
  • Discuss security solutions with information technology teams or management.
  • Document penetration test findings.
  • Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.
  • Gather cyber intelligence to identify vulnerabilities.
  • Identify new threat tactics, techniques, or procedures used by cyber threat actors.
  • Identify security system weaknesses, using penetration tests.
  • Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.
  • Keep up with new penetration testing tools and methods.
  • Maintain up-to-date knowledge of hacking trends.
  • Prepare and submit reports describing the results of security fixes.
  • Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.
  • Update corporate policies to improve cyber security.
  • Write audit reports to communicate technical and procedural findings and recommend solutions.

Salary & Job Openings

Median Salary (Yearly Pay)

Tap or scroll over map to see median salaries for each state

Future Jobs

Blast-Off:

How Will Ethical Hacker Jobs Grow by 2034?
Projected % Growth
Rapid growth
(10% or higher)
Much faster than average
(7% - 10%)
Faster than average
(5% - 7%)
About as fast as average
(3% - 5%)
Slower than average
(0% - 3%)
Decreasing
Average of all U.S. jobs (5.3%)
Ethical Hacker jobs (8.20%)

Steps to Get There: Becoming an Ethical Hacker

High School Subjects to Study

Aim to study the yellow-shaded subjects.
Math
Algebra 1
Geometry
Algebra 2
Pre-Calculus
Calculus
Statistics
Science
Biology
Chemistry
Physics
Environmental Science
Physiology
Bio-Medical / Biotech
IT &
Engineering
Computer Science
Applied Technology
Drafting & CAD Training
Core
English
Foreign Language
Business
Psychology / Sociology

Education- Typical Degree Needed After High School Listen to this section

Degree
Post
high school credential
AA
Bachelor's
Master's
Doctoral or Professional Degree

Typical degree for an entry-level position: Bachelor's degree ? Types of Degrees and Credentials

Ethical hackers typically have a bachelor's degree in information technology, computer science, or a related field. However, sufficient work experience will sometimes be accepted instead of a degree. As the demand for cybersecurity professionals continues to grow, some schools are starting to offer more specific cybersecurity-related degrees. Additional professional certifications, like Certified Ethical Hacker (CEH), may be preferred. Since the field of information security changes rapidly as computer technology advances, ethical hackers must stay up-to-date on the latest advances in their industry, including the latest attacks by malicious or "black hat" hackers and the attempts by "white hat" hackers to prevent them. It is important to avoid any illegal black hat hacking activities of your own, as many ethical hacker jobs require background checks or security clearances, or even a polygraph test. A history of criminal behavior or illegal hacking, even if it was "just for fun," could ruin your prospects of a white hat hacking career.

Companies That Hire Ethical Hackers

Try it Out with an Activity or Project

STEM Activities

STEM activities are fun hands-on explorations that usually take from 10 minutes to one hour and use readily available household or classroom materials while introducing you to STEM concepts common in this career.

Science Project Ideas

Project Ideas are in-depth STEM explorations that have a strong focus on controlling variables, taking accurate measurements, and analyzing data suitable for investigating the scientific method or the engineering design process.

On the Job

Role Models

Watch this video to see multiple short interviews with security professionals at BlackHat and DEFCON, two major security conferences held in Las Vegas.

Nature of the Work

Ethical hackers are hired by companies and government agencies to expose vulnerabilities in their web and computer systems by intentionally trying to hack into those systems. However, rather than stealing information for personal gain (for example, customer credit card numbers or sensitive trade secrets), the ethical hackers tell their clients about the vulnerabilities they have found so they can be fixed. Ethical hackers could work for a large company who has internal employees to test its own systems, but many times they work for third-party consulting agencies that may be hired by many other organizations.

An ethical hacker's job may take different forms. For example, first an ethical hacker might be hired by an outside company to perform penetration testing. The company could hire the tester to do cooperative testing (where the company's employees are aware that the penetration test will take place), or they could do secretive or "blind" testing where the company's employees do not know the ethical hacker has been hired. This means they cannot tell the difference between the penetration test and a "real" attack, so it tests how the company's employees will respond. Depending on the level of cooperation versus secrecy, the ethical hackers may be given information about and access to the company's systems, or they might have to do their own research and reconnaissance (simulating the situation a real attacker would be in).

An ethical hacker may run a variety of tests to test a company's systems. Some of them may be industry-standard tests and some may be unique and developed on a case-by-case basis. For example, one standard test involves testing websites that allow users to upload files to see if they will allow the user to upload a file containing malicious code or a virus (however, the "virus" will be designed not to do any real damage to the company's systems). However, not all tests are electronic in nature. Some tests may involve "social engineering," or exploiting people to gain access to a company's systems. This could range from simply checking to see if employees keep their passwords written on sticky notes near their desks to sneaky actions intended to gain unauthorized access—like convincing a security guard to let you into a building because you forgot your ID card, or leaving a USB drive with a virus on it in the company parking lot, and hoping somebody will connect it to their computer to find out what is on it.

After completing a test or series of tests, ethical hackers will usually prepare a report on the results and any vulnerabilities that they found. They may present this report to a manager or company executives to detail the vulnerabilities they exposed, what could happen if a real criminal exploited them, and how they can be fixed to prevent future attacks.

Work Environment

Ethical hackers typically spend the majority of their time working in an office environment, usually in front of a computer. They may have meetings with other people in the office during the day, and occasionally travel for conferences and professional meetings. Most analysts work full-time (40 hours per week). Since most of the penetration tests are performed online, they may work remotely. Sometimes they might be hired to do on-site penetration testing for a client, which could require travel.

Like other workers who spend long periods of time typing on a computer, ethical hackers are susceptible to eyestrain, back discomfort, and hand and wrist problems, such as carpal tunnel syndrome or cumulative trauma disorder, but preventative measures can be taken.

More Information

Ask Questions

Do you have a specific question about a career as an Ethical Hacker that isn't answered on this page? Post your question on the Science Buddies Ask an Expert Forum.

Additional Resources

Sources

Top
Free science fair projects.