Offensive Security (OffSec) — Vendor Overview
V019 · Penetration Testing, Exploit Development, Offensive Security · 1 active certification · SA presence: Minimal
Quick pitch: OffSec is the gold standard for elite penetration testers globally; OSCP (Offensive Security Certified Professional) is increasingly preferred over other certifications (CEH, GIAC) due to its practical, hands-on assessment methodology. OSCP is the most respected penetration testing credential among top-tier security firms.
Company Snapshot
| Field | Detail |
|---|---|
| Full name | Offensive Security, Inc. |
| Founded | 2006 — pioneered practical penetration testing training |
| Headquarters | New York, NY, USA (distributed team) |
| Employees | ~100 globally (2026) |
| Revenue | Private company; estimated ~$30–50M annually |
| Listed | Private |
| Core business | Delivers hands-on penetration testing training (Penetration Testing with Kali Linux – OSCP pathway) and operates OSCP certification exam platform. 100% training and certification revenue. |
| SA office | No direct office; global online access only |
What Offensive Security Does
Offensive Security is a boutique cybersecurity training and certification company focused exclusively on practical penetration testing and exploit development. The company operates a unique certification model: candidates do not take traditional exams but instead complete a 24-hour hands-on penetration testing assessment in a controlled lab environment. The assessment is exceptionally challenging; pass rates are estimated at 40–60%, making OSCP highly selective.
Offensive Security maintains approximately 60,000+ OSCP holders globally, significantly fewer than CEH (200,000+) or GIAC (100,000+), making OSCP more exclusive and respected. The organization is vendor-neutral and highly respected by elite security firms, government agencies, and defence contractors. The unique hands-on assessment methodology ensures that OSCP holders possess genuine penetration testing skills, not just exam knowledge.
Certification Portfolio
Active certifications (1 total)
| Level | Cert Name | Code | Domain | Cost (USD) | Valid |
|---|---|---|---|---|---|
| Expert | OSCP – Offensive Security Certified Professional | OSCP | Penetration Testing | $999 | Lifetime |
Additional pathway: OffSec provides PWK (Penetration Testing with Kali Linux) course prerequisite (~$800–$1,000) before OSCP exam eligibility.
Recommended starting cert
OSCP (Offensive Security Certified Professional) — Elite penetration testing credential requiring hands-on 24-hour practical assessment in a live lab environment against real machines. Candidates must exploit vulnerabilities, escalate privileges, and prove exploitation across multiple target systems. Suitable only for experienced penetration testers and security professionals. 24-hour live exam. Lifetime validity (no expiry). Prerequisites: ~6 months penetration testing experience or equivalent. Study time varies widely (2–12 months) depending on experience.
Why Offensive Security Matters in 2026
OSCP is increasingly preferred over CEH and other certifications by elite security firms, government agencies, and defence contractors due to its practical, hands-on assessment. LinkedIn shows 3,800+ open OSCP-related job postings, predominantly at top-tier security consultancies and government agencies. OSCP is the gold standard credential for penetration testers; employers view OSCP holders as the most skilled and competent penetration testers.
OffSec's certification model is unique: there is no multiple-choice exam, no study materials beyond the PWK course, and no dumps or brain dumps. Candidates must demonstrate genuine hacking skills in a real lab environment. This ensures that OSCP is the most respected and difficult penetration testing certification globally.
The certification ecosystem is exceptionally vibrant; OffSec maintains an active community, hosts HackTheBox and other challenge platforms, and publishes cutting-edge research. OSCP salaries are premium; OSCP holders command higher salaries than CEH or GIAC penetration testers due to demonstrated skills.
Job Market Data
Global demand
| Metric | Value | Source | Date |
|---|---|---|---|
| Active job postings mentioning OSCP | 3,800+ | LinkedIn Jobs | May 2026 |
| Growth YoY | +18% | LinkedIn Salary Insights | 2025–2026 |
| Top job title hiring | Penetration Tester | May 2026 | |
| Top hiring countries | USA, Canada, UK, Australia, Israel | May 2026 |
Common job titles requiring OffSec skills
| Job Title | Seniority | Median USD Salary | Median ZAR Salary |
|---|---|---|---|
| Penetration Tester (OSCP) | Senior | $125,000 | R115,000/month |
| Senior Penetration Tester / OSCP | Expert | $155,000 | R142,600/month |
| Penetration Testing Lead | Expert | $175,000+ | R160,800+/month |
| Security Research Lead / OSCP | Executive | $200,000+ | R184,000+/month |
South Africa Presence
Direct presence
Offensive Security has no direct presence in South Africa. All training and certification is conducted online globally via the HackTheBox platform and Offensive Security labs.
SA job market
South African domestic market has minimal OSCP demand. However, SA penetration testers pursuing global careers (remote work for US/UK security firms) increasingly pursue OSCP as the gold standard credential. Global remote opportunities are the primary SA employment path.
Median salary for OSCP-certified Penetration Testers globally is among the highest for technical certifications ($155,000–$200,000 USD), reflecting elite skill level and market demand.
SA training providers
| Provider | Cert(s) offered | URL |
|---|---|---|
| Offensive Security (global) | OSCP, PWK course | offensive-security.com |
| HackTheBox (platform) | Lab access/training | hackthebox.com |
| Without.co.za | OSCP course bundles | without.co.za |
Vendor Ecosystem
Key technologies and platforms
- HackTheBox (hacking challenge platform)
- Kali Linux (penetration testing OS)
- Metasploit (exploit framework)
- Burp Suite (web penetration testing)
- Wireshark (network analysis)
- Python and Bash scripting
- Windows and Linux exploitation techniques
- Web application security (OWASP Top 10)
Complementary vendors and certs
| Complementary Vendor | Why they pair well |
|---|---|
| GIAC (GPEN) | GPEN and OSCP are complementary for elite penetration testers |
| EC-Council (CEH, ECSA) | CEH entry-level, OSCP advanced specialisation |
| SANS (incident response) | Some penetration testers transition to incident response |
| Kubernetes/cloud security | Cloud penetration testing increasingly important |
Community and resources
| Resource | Type | URL |
|---|---|---|
| Offensive Security Training | Official | offensive-security.com |
| HackTheBox | Lab/Challenge Platform | hackthebox.com |
| r/oscp | Community | reddit.com/r/oscp |
| OffSec Proof Concepts | Learning | offensive-security.com/proof-of-concept/ |
Vendor History & Roadmap
Key milestones
| Year | Event |
|---|---|
| 2006 | Founded by Ofir Arkin and others; pioneered practical penetration testing |
| 2010 | Launched OSCP as hands-on certification (no traditional exam) |
| 2015 | Introduced PWK (Penetration Testing with Kali Linux) course |
| 2020 | Acquired HackTheBox; expanded lab infrastructure |
| 2021 | Briefly acquired by Evernote; spun back out as independent company |
| 2023 | Introduced OSEE (Exploitation Expert) advanced course/cert |
| 2024 | Expanded cloud and container security modules |
| 2025–2026 | Focus on cloud-native penetration testing, AI/ML security |
| 2026 | OSCP remains gold standard; cloud security specialisations growing |
Outlook
Offensive Security is firmly positioned as the elite penetration testing credential authority. The company's unique hands-on assessment methodology and commitment to practical skills ensure continued prestige and market leadership. For certification professionals, OSCP remains secure and in growing demand, particularly among top-tier security firms and government agencies. The barrier to entry (cost, time, difficulty) ensures that OSCP remains exclusive and highly valued. Advanced certifications (OSEE, cloud security specialisations) are emerging as career progression paths.
Frequently Asked Questions
Q: Is OSCP worth investing in for my career? Yes, if you're serious about penetration testing. OSCP is the gold standard and is increasingly preferred over CEH for elite security careers.
Q: How often do OffSec certs expire? OSCP has LIFETIME validity – it never expires. This is unique among certifications and reflects the permanent value of demonstrated skills.
Q: Are OffSec certs recognised in South Africa? Extremely limited domestic recognition. Primarily valued for SA penetration testers pursuing global remote security careers.
Q: What's the best cert to start with from OffSec? OSCP is the only certification. Prerequisite is PWK (Penetration Testing with Kali Linux) course (~$800–$1,000). Expect 4–12 months study and significant hands-on lab time.
Related Content
- Cert Roadmap → — Full progression diagram
- Ecosystem Deep Dive → — Technology landscape, tools, job market
- Individual Cert Files → — Per-exam breakdowns
Sources
| # | Source | URL | Used for |
|---|---|---|---|
| 1 | OffSec Certifications | offensive-security.com/certifications | Company data, cert portfolio |
| 2 | OffSec About | offensive-security.com/about | History, mission |
| 3 | LinkedIn Jobs – OSCP | linkedin.com/jobs | Job market data |
| 4 | HackTheBox | hackthebox.com | Lab platform, learning resources |
Template version: 2026-05-03 | Maintained by IT Career Roadmap