When Star Health Insurance‘s breach of 31 million policyholder records surfaced in late 2024, the company’s share price dropped and its legal team got busy — but something quieter happened too: recruiters began posting for penetration testers and red-team analysts at a pace that hadn’t been seen before. Star wasn’t alone. boAt, the wearable brand, watched the personal details of 7.5 million customers get exposed through a single security lapse. Angel One saw 8 million users’ data walk out through a misconfigured AWS setup. The pattern across every one of these incidents was the same: companies that had treated cybersecurity as a compliance checkbox discovered, suddenly and expensively, that it was something else entirely.
That shift — from “nice to have” to “existential priority” — is the direct engine behind one of the most consistent hiring spikes in Indian tech right now. If you are anywhere near a career decision about whether cybersecurity is worth the investment of time and certification fees, the numbers have a clear answer for you.
The Scale of the Problem Nobody Has Solved
The ISC2 Cybersecurity Workforce Study puts the global shortage at 4.8 million unfilled positions. Read that again. Not 4.8 million roles that might open — 4.8 million positions that organizations cannot fill today. The Asia-Pacific region alone accounts for 3.4 million of that gap, which means India sits at the very center of what the World Economic Forum has described as a workforce that needs to grow by 87% just to meet current demand.
Want Instant Job Updates? 🚀
Join aspirants getting the latest sarkari naukri alerts on our official channels.
What makes 2026 different from previous years is that the shortage has become structurally stubborn. It is no longer a pipeline problem — a case of “wait a few years and universities will produce enough graduates.” According to ISC2, approximately 90% of cybersecurity teams worldwide now report active skills gaps inside their own organizations. They have people. They do not have people who can actually do the specialized work — cloud security architecture, zero-trust implementation, AI-driven threat detection, red-teaming against modern infrastructure. Those specializations take time to develop, and they cannot be manufactured on demand.
India’s own regulatory environment is adding fuel to the fire. The Digital Personal Data Protection (DPDP) Act now requires listed companies to disclose breaches within 24 hours of detection. That single compliance requirement has forced every major enterprise with Indian operations to think seriously about detection capabilities — which translates directly into security operations center (SOC) analyst and incident response roles that need to be filled.
What Ethical Hackers Actually Earn in India
Let’s set aside vague promises of “lucrative careers” and look at what the market is actually paying in 2026.
Freshers with foundational security skills are entering the field at ₹3.5 LPA to ₹6 LPA. That’s not spectacular, but it’s a starting point with unusually fast progression. Early-career professionals with one to four years of experience — particularly those who have earned a CEH or completed a few bug bounty programmes — are pulling ₹6 LPA to ₹12 LPA. The mid-level bracket (four to seven years of experience, often with specializations in cloud security or penetration testing) sits at ₹12 LPA to ₹22 LPA. Senior professionals and red-team leads with deep expertise in areas like OT/ICS security or AI red-teaming command ₹20 LPA to ₹50 LPA and beyond.
Bengaluru, unsurprisingly, pays a 15–25% premium over other Indian metros. The concentration of Global Capability Centres (GCCs) and dedicated security product companies there creates genuine competition for talent, and companies have responded by raising base packages rather than lose candidates to competitors.
There is also a parallel income stream that many people overlook: bug bounty programmes. Active researchers who participate on platforms like HackerOne or Bugcrowd can add meaningful supplementary income to their base salary — some are clearing ₹5 LPA to ₹15 LPA in bounties alone on top of regular employment. It is not a guaranteed income, but it is uniquely available to anyone who develops real offensive security skills.
The Certification Question: CEH vs. OSCP
No conversation about ethical hacking careers survives long without getting into certifications. There are two that dominate every serious hiring conversation in India: the Certified Ethical Hacker (CEH) from EC-Council and the Offensive Security Certified Professional (OSCP) from OffSec.
The CEH costs roughly $950 to $1,200 for the exam alone, with full training bundles ranging from $1,700 to $3,500. It is a 125-question multiple-choice exam taken over four hours, with an estimated pass rate of 85–90%. Industry veterans sometimes describe it as an “HR filter” — that’s slightly uncharitable but not entirely wrong. It validates that you understand the vocabulary, frameworks, and methodologies of ethical hacking. Recruiters, particularly at large IT services firms like TCS, Infosys, and Wipro, use it as a screening criterion when a role gets hundreds of applications.
The OSCP Is a Different Animal Entirely
The OSCP costs around $1,749 for the PEN-200 course bundle, which includes 90 days of lab access and one exam attempt. The exam itself is 24 hours of live, unguided penetration testing against a network of machines — followed by a 24-hour window to write and submit a professional technical report. There are no multiple-choice questions. There are no hints. You either compromise the required machines or you don’t. The estimated pass rate is 40–50%.
If that sounds brutal, it is meant to. The OSCP’s value to employers is precisely that it cannot be memorized into. Every person who holds the certification has sat alone with a target network and done the actual work. Companies running red teams or offering managed penetration testing services — firms like Palo Alto Networks and SecurityHQ, which are actively hiring in India — treat an OSCP as a marker of genuine technical capability rather than completed coursework.
Many professionals pursue both: the CEH to get past the HR screen, the OSCP to get the job they actually want.
Which Companies Are Hiring — and Why Now
The major IT services firms have been consistent cybersecurity hirers for years, but the breach cycle of 2024–2025 accelerated hiring well beyond the traditional IT sector. TCS, Wipro, Infosys, HCL Technologies, Accenture, Capgemini, and Kyndryl are all actively recruiting across SOC analyst, cloud security engineer, ethical hacker, and incident responder roles.
More telling is the uptick in hiring among companies that were directly affected by breaches. When your company’s name appears in headlines about 31 million exposed records, the board meeting that follows tends to produce a significant security budget increase. Star Health, Angel One, and companies across the financial services sector have all significantly expanded their security operations and compliance teams in the months following their incidents.
The DPDP Act’s disclosure requirements have particularly accelerated hiring in the GRC (governance, risk, and compliance) adjacent roles — people who sit at the intersection of legal obligation and technical security monitoring. That’s a newer category of ethical hacker: someone who can not only find vulnerabilities but can articulate them in a regulatory context.
Truth Box
| Key Point | Insight |
|---|---|
| Global workforce gap | ISC2 reports 4.8 million unfilled cybersecurity positions globally, with Asia-Pacific accounting for 3.4 million of them |
| India’s regulatory driver | The DPDP Act’s 24-hour breach disclosure requirement has forced enterprises to build detection and monitoring capabilities they did not previously prioritize |
| Salary ceiling for specialists | Senior red-team professionals and cloud security leads in India command ₹20 LPA to ₹50 LPA+, with Bengaluru GCCs paying a 15–25% premium |
| OSCP vs. CEH market reality | CEH clears HR filters; OSCP (with its 40–50% pass rate and 24-hour live exam) earns the technical credibility that red-team hiring managers actually respect |
| Bug bounty as real income | Active Indian ethical hackers on platforms like HackerOne supplement base salaries with significant additional income, sometimes ₹5–15 LPA annually |
Common Misconceptions
“You need a Computer Science degree to become an ethical hacker.”
This is simply not how the industry works anymore. The CEH and OSCP certifications are credentials that hiring managers actually weight during evaluation — and neither of them requires a CS degree as a prerequisite. What they require is technical fluency, hands-on practice (particularly for the OSCP), and the ability to document your findings clearly. Many of the most respected practitioners in the field came through self-taught routes, built portfolios through bug bounty programmes, and earned certifications through dedicated preparation rather than four-year programmes. Degrees help at some traditional companies, but they are far from the entry gate.
“Ethical hacking is just entry-level work that pays poorly.”
Look at the salary brackets above and reconsider. The entry level is modest, yes — but the progression speed in cybersecurity outpaces most comparable technology tracks. A developer might take seven to eight years to reach a senior-level package equivalent to what a mid-level penetration tester earns at five years. The specialization premium is real: someone who develops deep expertise in cloud security, API security, or OT/ICS environments is operating in a genuinely thin market. Companies that need that specific skill frequently have to pay well above published ranges to secure a candidate.
“AI will replace ethical hackers within the next few years.”
This misconception underestimates the nature of the work. AI has absolutely changed the threat landscape — attackers now use AI-powered phishing, deepfakes, and automated vulnerability scanning at scale. But defending against those threats still requires human judgment, contextual reasoning, and creative adversarial thinking. The ISC2 workforce data shows that organizations are increasingly using AI to augment security teams, not replace them — automating routine log analysis and alert triage so that human analysts can focus on complex investigations. The skills gap identified in cloud security, zero-trust architecture, and AI red-teaming all require practitioners who can reason about novel systems. That is not a job that current AI tools can do autonomously.
Frequently Asked Questions
Is ethical hacking a good career choice in India in 2026?
The data points in one direction. With 4.8 million unfilled positions globally and Asia-Pacific carrying the largest regional deficit, India’s position as a major technology hub means that qualified ethical hackers face a hiring market that is structurally in their favour. The DPDP Act has added regulatory urgency on top of existing demand. The salary ceiling for experienced practitioners is genuinely competitive with software engineering and data science roles. The honest caveat is that entry-level salaries are not exceptional — the career rewards people who invest in real technical skill and earn respected certifications. If you are willing to put in that work, the market conditions in 2026 are about as good as they have ever been.
Which is better for getting hired in India — CEH or OSCP?
They serve different functions in the hiring process. The CEH gets you through the initial resume filter at large IT services firms like TCS, Infosys, and Wipro, where HR departments use it as a baseline screening criterion. The OSCP gets you taken seriously in technical interviews for penetration testing, red-team, and offensive security roles. If you can only afford one right now, your target role should decide. If you want to work at a managed security services company or a product security team, the OSCP’s practical credibility is worth the harder preparation. Many practitioners eventually pursue both.
How long does it take to prepare for the OSCP?
Most people who pass it on their first attempt report preparing seriously for three to six months before the exam, in addition to their 90 days of lab access. The preparation is almost entirely practical — working through platforms like Hack The Box, TryHackMe, and OffSec’s own PEN-200 course material. The 24-hour live exam means you need to be comfortable with the actual mechanics of attacking systems under time pressure, not just familiar with the theory. People who rush the preparation and treat it like a knowledge-based exam tend to hit the 50% fail rate hard.
What specializations are paying the most right now?
Cloud security is at the top. As organizations have moved workloads to AWS, Azure, and GCP, the number of people who genuinely understand cloud-native attack surfaces — misconfigurations, IAM privilege escalation, serverless security — has not kept pace. API security is another high-demand area given the explosion of microservices architecture. OT/ICS security (operational technology for manufacturing, energy, and critical infrastructure) is a niche that pays exceptionally well because the talent pool is tiny. AI red-teaming — finding vulnerabilities in AI systems and LLM deployments — is an emerging specialization where early movers will likely command significant premiums.
Can I work as a freelance ethical hacker in India?
Yes, and a meaningful number of practitioners do. Bug bounty programmes are the most structured route — platforms like HackerOne, Bugcrowd, and India-specific initiatives from companies like Zomato, Razorpay, and PhonePe run active programmes with real payouts. There is also a legitimate freelance penetration testing market, particularly for small and mid-sized companies that need periodic security assessments but cannot afford a full-time security hire. The DPDP Act has actually expanded this market, as smaller companies now face compliance pressures that require security documentation. Freelancing requires strong documentation skills alongside technical ability — clients need reports they can understand and act on, not just a list of CVEs.