Offensive Security (OffSec)

2 certifications across 2 levels.

vendor rollup

Offensive Security (OffSec)

Professional · 1Expert · 1
View Offensive Security (OffSec) certification path →
L3

Professional

1 cert

Vendor overview

Offensive Security (OffSec) — Vendor Overview

V019 · Penetration Testing, Exploit Development, Offensive Security · 1 active certification · SA presence: Minimal

Quick pitch: OffSec is the gold standard for elite penetration testers globally; OSCP (Offensive Security Certified Professional) is increasingly preferred over other certifications (CEH, GIAC) due to its practical, hands-on assessment methodology. OSCP is the most respected penetration testing credential among top-tier security firms.


Company Snapshot

FieldDetail
Full nameOffensive Security, Inc.
Founded2006 — pioneered practical penetration testing training
HeadquartersNew York, NY, USA (distributed team)
Employees~100 globally (2026)
RevenuePrivate company; estimated ~$30–50M annually
ListedPrivate
Core businessDelivers hands-on penetration testing training (Penetration Testing with Kali Linux – OSCP pathway) and operates OSCP certification exam platform. 100% training and certification revenue.
SA officeNo direct office; global online access only

What Offensive Security Does

Offensive Security is a boutique cybersecurity training and certification company focused exclusively on practical penetration testing and exploit development. The company operates a unique certification model: candidates do not take traditional exams but instead complete a 24-hour hands-on penetration testing assessment in a controlled lab environment. The assessment is exceptionally challenging; pass rates are estimated at 40–60%, making OSCP highly selective.

Offensive Security maintains approximately 60,000+ OSCP holders globally, significantly fewer than CEH (200,000+) or GIAC (100,000+), making OSCP more exclusive and respected. The organization is vendor-neutral and highly respected by elite security firms, government agencies, and defence contractors. The unique hands-on assessment methodology ensures that OSCP holders possess genuine penetration testing skills, not just exam knowledge.


Certification Portfolio

Active certifications (1 total)

LevelCert NameCodeDomainCost (USD)Valid
ExpertOSCP – Offensive Security Certified ProfessionalOSCPPenetration Testing$999Lifetime

Additional pathway: OffSec provides PWK (Penetration Testing with Kali Linux) course prerequisite (~$800–$1,000) before OSCP exam eligibility.

Recommended starting cert

OSCP (Offensive Security Certified Professional) — Elite penetration testing credential requiring hands-on 24-hour practical assessment in a live lab environment against real machines. Candidates must exploit vulnerabilities, escalate privileges, and prove exploitation across multiple target systems. Suitable only for experienced penetration testers and security professionals. 24-hour live exam. Lifetime validity (no expiry). Prerequisites: ~6 months penetration testing experience or equivalent. Study time varies widely (2–12 months) depending on experience.


Why Offensive Security Matters in 2026

OSCP is increasingly preferred over CEH and other certifications by elite security firms, government agencies, and defence contractors due to its practical, hands-on assessment. LinkedIn shows 3,800+ open OSCP-related job postings, predominantly at top-tier security consultancies and government agencies. OSCP is the gold standard credential for penetration testers; employers view OSCP holders as the most skilled and competent penetration testers.

OffSec's certification model is unique: there is no multiple-choice exam, no study materials beyond the PWK course, and no dumps or brain dumps. Candidates must demonstrate genuine hacking skills in a real lab environment. This ensures that OSCP is the most respected and difficult penetration testing certification globally.

The certification ecosystem is exceptionally vibrant; OffSec maintains an active community, hosts HackTheBox and other challenge platforms, and publishes cutting-edge research. OSCP salaries are premium; OSCP holders command higher salaries than CEH or GIAC penetration testers due to demonstrated skills.


Job Market Data

Global demand

MetricValueSourceDate
Active job postings mentioning OSCP3,800+LinkedIn JobsMay 2026
Growth YoY+18%LinkedIn Salary Insights2025–2026
Top job title hiringPenetration TesterLinkedInMay 2026
Top hiring countriesUSA, Canada, UK, Australia, IsraelLinkedInMay 2026

Common job titles requiring OffSec skills

Job TitleSeniorityMedian USD SalaryMedian ZAR Salary
Penetration Tester (OSCP)Senior$125,000R115,000/month
Senior Penetration Tester / OSCPExpert$155,000R142,600/month
Penetration Testing LeadExpert$175,000+R160,800+/month
Security Research Lead / OSCPExecutive$200,000+R184,000+/month

South Africa Presence

Direct presence

Offensive Security has no direct presence in South Africa. All training and certification is conducted online globally via the HackTheBox platform and Offensive Security labs.

SA job market

South African domestic market has minimal OSCP demand. However, SA penetration testers pursuing global careers (remote work for US/UK security firms) increasingly pursue OSCP as the gold standard credential. Global remote opportunities are the primary SA employment path.

Median salary for OSCP-certified Penetration Testers globally is among the highest for technical certifications ($155,000–$200,000 USD), reflecting elite skill level and market demand.

SA training providers

ProviderCert(s) offeredURL
Offensive Security (global)OSCP, PWK courseoffensive-security.com
HackTheBox (platform)Lab access/traininghackthebox.com
Without.co.zaOSCP course bundleswithout.co.za

Vendor Ecosystem

Key technologies and platforms

  • HackTheBox (hacking challenge platform)
  • Kali Linux (penetration testing OS)
  • Metasploit (exploit framework)
  • Burp Suite (web penetration testing)
  • Wireshark (network analysis)
  • Python and Bash scripting
  • Windows and Linux exploitation techniques
  • Web application security (OWASP Top 10)

Complementary vendors and certs

Complementary VendorWhy they pair well
GIAC (GPEN)GPEN and OSCP are complementary for elite penetration testers
EC-Council (CEH, ECSA)CEH entry-level, OSCP advanced specialisation
SANS (incident response)Some penetration testers transition to incident response
Kubernetes/cloud securityCloud penetration testing increasingly important

Community and resources

ResourceTypeURL
Offensive Security TrainingOfficialoffensive-security.com
HackTheBoxLab/Challenge Platformhackthebox.com
r/oscpCommunityreddit.com/r/oscp
OffSec Proof ConceptsLearningoffensive-security.com/proof-of-concept/

Vendor History & Roadmap

Key milestones

YearEvent
2006Founded by Ofir Arkin and others; pioneered practical penetration testing
2010Launched OSCP as hands-on certification (no traditional exam)
2015Introduced PWK (Penetration Testing with Kali Linux) course
2020Acquired HackTheBox; expanded lab infrastructure
2021Briefly acquired by Evernote; spun back out as independent company
2023Introduced OSEE (Exploitation Expert) advanced course/cert
2024Expanded cloud and container security modules
2025–2026Focus on cloud-native penetration testing, AI/ML security
2026OSCP remains gold standard; cloud security specialisations growing

Outlook

Offensive Security is firmly positioned as the elite penetration testing credential authority. The company's unique hands-on assessment methodology and commitment to practical skills ensure continued prestige and market leadership. For certification professionals, OSCP remains secure and in growing demand, particularly among top-tier security firms and government agencies. The barrier to entry (cost, time, difficulty) ensures that OSCP remains exclusive and highly valued. Advanced certifications (OSEE, cloud security specialisations) are emerging as career progression paths.


Frequently Asked Questions

Q: Is OSCP worth investing in for my career? Yes, if you're serious about penetration testing. OSCP is the gold standard and is increasingly preferred over CEH for elite security careers.

Q: How often do OffSec certs expire? OSCP has LIFETIME validity – it never expires. This is unique among certifications and reflects the permanent value of demonstrated skills.

Q: Are OffSec certs recognised in South Africa? Extremely limited domestic recognition. Primarily valued for SA penetration testers pursuing global remote security careers.

Q: What's the best cert to start with from OffSec? OSCP is the only certification. Prerequisite is PWK (Penetration Testing with Kali Linux) course (~$800–$1,000). Expect 4–12 months study and significant hands-on lab time.


Related Content


Sources

#SourceURLUsed for
1OffSec Certificationsoffensive-security.com/certificationsCompany data, cert portfolio
2OffSec Aboutoffensive-security.com/aboutHistory, mission
3LinkedIn Jobs – OSCPlinkedin.com/jobsJob market data
4HackTheBoxhackthebox.comLab platform, learning resources

Template version: 2026-05-03 | Maintained by IT Career Roadmap

Rate Offensive Security (OffSec)
Was this helpful?
Comments ()
0/2000