OSCA 271137: Penetration Tester
Creates test cases using in-depth technical analysis of risks and typical vulnerabilities, and produces test scripts, materials and packs to test new and existing software or services. Plans, coordinates and conducts cyber threat emulation activities in support of certification, accreditation and operational priorities to verify deficiencies in technical security controls. This record sits in Cyber Security Professionals. Related ANZSIC industry links are included for faster classification cross-checking. Skill level 1 is attached to this occupation record.
Should you use OSCA or ANZSCO?
OSCA 2024 is the current Australian occupation classification for storing, organising and reporting occupation information. Use this OSCA record for current Australian statistical and analytical classification work.
Some migration and administrative programs still specify ANZSCO 2022. Check the exact system named by the agency or form rather than replacing the code automatically.
Official ANZSCO correspondence
Role overview
Creates test cases using in-depth technical analysis of risks and typical vulnerabilities, and produces test scripts, materials and packs to test new and existing software or services. Plans, coordinates and conducts cyber threat emulation activities in support of certification, accreditation and operational priorities to verify deficiencies in technical security controls.
Use this page to confirm the official title, the parent unit group, the task list and the related ANZSIC industry context before using the occupation in classification, reporting or migration-adjacent workflows.
Occupation facts
- Skill level
- 1
- Major group
- 2 Professionals
- Sub-major group
- 27 ICT Professionals
- Minor group
- 271 Cyber Security Professionals and Database and Systems Administrators
- Unit group
- 2711 Cyber Security Professionals
Tasks
- Develops and executes penetration testing methodologies and strategies to identify weaknesses in security controls
- Creates test cases using in-depth technical analysis of risks and typical vulnerabilities
- Produces test scripts, materials and packs to test new and existing software or services for vulnerabilities
- Plans, coordinates and conducts cyber threat emulation activities to verify deficiencies in technical security controls, and provides recommendations for remediation
- Identifies vulnerability exploitations and potential attack vectors into a system, and analyses vulnerability scan results to assess security loopholes and threats
- May conduct phishing attacks or other tests to evaluate the effectiveness of security awareness training
Skill level guidance
Skill level helps place the occupation inside the ABS hierarchy. Use it as a classification cue, then check the actual task list and occupational context before making a decision for HR, visa or reporting work.
How to use this occupation page
Start with the official OSCA title and task list. Then confirm the parent unit group and compare the related occupations on this page if the job title is broad, overlapping or used differently across employers.
The ANZSIC links are there to help when the same occupation appears across several industries and you need the business-side classification as well.
Related occupations
Industry context
Alternative titles
- Ethical Hacker
Compare before choosing
Compare OSCA 271137 with related occupations
Compare roles in the same OSCA unit group by their official definition, skill level, tasks and recognised alternative titles.
| Comparison point | Current code271137 Penetration Tester | 271131 Cyber Governance Risk and Compliance Specialist | 271132 Cyber Security Advice and Assessment Specialist |
|---|---|---|---|
| Official role definition | Creates test cases using in-depth technical analysis of risks and typical vulnerabilities, and produces test scripts, materials and packs to test new and existing software or services. Plans, coordinates and conducts cyber threat emulation activities in support of certification, accreditation and operational priorities to verify deficiencies in technical security controls. | Leads the governance, risk and compliance for cyber security. | Conducts risk and security control assessments, interprets security policies, contributes to the development of standards and guidelines, reviews information system designs, provides guidance on security strategies to manage identified risks, provides specialist advice and explains systems security, strengths and weaknesses. |
| Skill level | Skill Level 1 | Skill Level 1 | Skill Level 1 |
| Key tasks |
|
|
|
| Alternative titles |
| Not stated |
|
Comparison uses occupation definitions, skill levels, tasks and title variants from the ABS OSCA data files.
Compliance risk score
4 of 4 factors passing
In this section
Frequently asked questions
What does OSCA 271137 do?
Penetration Tester is the current ABS occupation record used to describe a specific occupation. It sits in the OSCA hierarchy and carries skill-level context plus related titles and tasks.
How should I read the skill level?
The skill level tells you the educational or training depth that the ABS associates with the occupation. It is a classification signal, not a salary band or a qualification checklist on its own.
Why is industry context shown on an occupation page?
Industry context helps when the title is common or ambiguous. It shows where the occupation is typically employed so you can compare it with the right ANZSIC family.
Source and trust
- Official source
- ABS OSCA 2024 release and correspondence tables
- Last reviewed
- 2026-04-17
This site is an independent reference resource. It is not affiliated with, endorsed by, or connected to the ABS, ATO or any Australian Government agency.
Please verify critical classification decisions with the official authority before using them for tax, payroll, licensing, immigration or compliance work.