Skip to content
Security / Technical Security

Lead Penetration Testing Manager.

Lead Penetration Testing Professional training allows you to develop the knowledge and skills necessary to plan, conduct and manage penetration testing. This training provides an understanding of methodologies and techniques for testing the security of systems, networks and applications. You will learn how to think like an attacker, use a variety of tools and techniques to identify and exploit vulnerabilities, and how to professionally report results to improve the overall security status of an organization.

Issues

  • Penetration tests

  • Security testing methodologies

  • Penetration test planning

  • Reconnaissance and information gathering

  • Vulnerability scanning

  • Exploitation of vulnerabilities

  • Maintaining access

  • Hacking tools

  • Reporting of results

  • Security recommendations

  • Ethical aspects of testing

  • Test process management

Benefits

  • Mastery of penetration testing methodology
  • They will gain practical skills in the use of hacking tools and techniques
  • They will learn how to plan and manage the entire penetration testing process
  • Development of skills to analyze results and create effective reports with recommendations

Who is this training for?

Ethical hackers and penetration testers
Security managers and cyber security specialists
IT security auditors
Network and systems administrators

Prerequisites

  • Basic knowledge of computer networks and systems
  • Knowledge of the basics of IT security
  • Experience in systems administration (preferred)
  • Technical and analytical skills

Training program

01

Day 1: Introduction to Penetration Testing and Planning

  • Introduction to penetration testing — objectives, types (black box, grey box, white box), ethics, legal aspects
  • Penetration testing methodologies — PTES, OWASP Testing Guide, NIST SP 800-115, OSSTMM
  • Planning and scoping — scope definition, rules of engagement, authorization, scheduling, communication
  • Passive reconnaissance — OSINT, DNS, WHOIS, Google Dorking, Shodan, social media, metadata analysis
  • Active reconnaissance — port scanning (Nmap), fingerprinting, service and OS identification
  • Exercises: penetration test planning, OSINT reconnaissance
02

Day 2: Vulnerability Scanning and Exploitation

  • Vulnerability scanning — tools (Nessus, OpenVAS, Qualys), results interpretation, false positives, prioritization
  • Exploitation — Metasploit Framework, exploiting known vulnerabilities (CVE), exploit development basics
  • Password attacks — brute force, dictionary, rainbow tables, pass-the-hash, credential stuffing
  • Network security testing — protocol attacks (ARP, DNS, DHCP), MITM, sniffing, relay attacks
  • Post-exploitation — privilege escalation, lateral movement, persistence, data exfiltration
  • Exercises: vulnerability scanning, exploitation in a controlled environment, post-exploitation
03

Day 3: Web Application Testing and Infrastructure Security

  • Web application testing — OWASP Top 10, injection (SQL, XSS, SSRF), broken authentication, IDOR
  • Application testing tools — Burp Suite, OWASP ZAP, SQLmap, automation vs manual testing
  • API testing — REST, GraphQL, API authentication, authorization, rate limiting, injection
  • Wi-Fi security testing — WPA2/WPA3, evil twin, deauthentication, cracking, rogue AP
  • Active Directory security testing — Kerberoasting, AS-REP roasting, DCSync, Golden Ticket
  • Exercises: web application testing (OWASP Top 10), API testing, results analysis
04

Day 4: Reporting and Test Program Management

  • Results reporting — pentest report structure, vulnerability classification (CVSS), evidence, recommendations
  • Results communication — presentation for executives vs technical team, remediation prioritization
  • Penetration testing program management — frequency, scope rotation, retesting, continuous testing
  • Red Team vs Penetration Testing — differences, purple teaming, adversary simulation
  • Vulnerability management — remediation tracking, SLA, risk acceptance, vulnerability management lifecycle
  • Exercises: preparing a pentest report, presenting findings, remediation plan
05

Day 5: PECB Exam Preparation

  • Penetration testing methodology summary — review of key techniques and tools
  • Trends in penetration testing — cloud pentesting, container security, IoT, social engineering
  • Case studies — penetration testing analysis in organizations of various scales
  • PECB certification preparation — exam format, question types, passing strategies
  • Practice exam — PECB Certified Lead Penetration Testing Professional exam simulation
  • PECB certification exam (optional) — written exam leading to PECB Certified Lead Penetration Testing Professional certificate

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

What are the prerequisites for this training?

For Lead Penetration Testing Manager. we recommend: Basic knowledge of computer networks and systems; Knowledge of the basics of IT security; Experience in systems administration (preferred).

What is the format and duration of this training?

The training lasts 5 days and is available in online and on-site format. Sessions run from 9:00 AM to 4:00 PM. We can also customize the schedule to fit your team's needs.

Who is this training designed for?

This training is designed for: Ethical hackers and penetration testers; Security managers and cyber security specialists; IT security auditors.

Patrycja Petkowska
Patrycja Petkowska Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90