Career PathsCEH v13EC-Council · Security

Jobs You Can Get With the CEH (Certified Ethical Hacker)

The CEH is one of the most recognised offensive-security credentials on the market — it shows up across pentest, analyst, and government security postings. Here are the roles it actually opens, realistic US salary ranges by level, and the ladder from SOC analyst to offensive security lead.

6+ rolesJob titles it fits
~$90–110KTypical base (US)
$170K+Senior reaches
HighSecurity demand
DoD 8140Approved baseline
Jobs and career paths with the CEH Certified Ethical Hacker certification

01 The short answer

The CEH is aimed at offensive-security work, but it pays off across the whole security job family. Because it proves you understand attacker tools, methodology, and the phases of a hack, it strengthens applications for Penetration Tester and Ethical Hacker roles — but also for SOC Analyst, Security Analyst, Vulnerability Analyst, and Cybersecurity Consultant positions. It is also approved under the US DoD 8140 framework, which puts it on a large share of government and defence-contractor job descriptions.

It is worth being realistic, though. The CEH is best understood as a door-opener and a résumé keyword rather than a substitute for hands-on skill. It teaches breadth across the attack lifecycle, but offensive-security teams also want to see practical proof — a home lab, boxes you have rooted, and often a hands-on cert such as the OSCP alongside it. Many people enter through a SOC or security analyst role first, then pivot into pentesting within a year or two. The CEH gets you past the résumé screen; demonstrable hacking gets you the offer.

Salaries below are typical US ranges drawn from public aggregators (Glassdoor, PayScale, ZipRecruiter, Indeed) and vendor salary guides. They vary widely by city, employer, clearance, and experience, and security clearances or specialisations can push them considerably higher. Treat them as a guide, not a quote.

02 Jobs you can target

These are the roles where the CEH most directly moves the needle. The seniority tag shows where each typically sits.

Penetration Tester

Mid
~$90K–$135K

Run authorised attacks against networks, apps, and infrastructure, then report the findings. The role the CEH is built around.

Ethical Hacker

Mid
~$95K–$140K

Probe systems the way an attacker would to expose weaknesses before criminals do. The job title the certification is named for.

SOC Analyst

Entry
~$70K–$100K

Monitor alerts, triage incidents, and investigate threats in a security operations centre. The most common entry point for CEH holders.

Vulnerability Analyst

Mid
~$85K–$120K

Scan, prioritise, and track remediation of weaknesses across the estate. The CEH attacker mindset helps you rank real risk.

Security Analyst

Entry–Mid
~$80K–$115K

Defend networks, harden systems, and respond to incidents. A broad role where the CEH signals you understand the attacker.

Cybersecurity Consultant

Senior
~$110K–$160K

Advise clients on testing, risk, and security strategy at consultancies and assessment firms. Heavy on communication.

The hidden value: the CEH reportedly appears on thousands of US security job listings even where the title is not “hacker.” Because it is a DoD 8140 baseline, it works as a recognised credential that gets a wide range of security applications taken seriously — especially in government and defence.

03 The career ladder

Security careers progress fast for people who keep getting hands on. Here is a typical offensive-leaning path with the CEH as your foundation — salary bands are US guides.

1

Entry — SOC Analyst / Security Analyst + CEH

Learn how real attacks look from the defensive side, build incident-response instincts, and earn the experience the CEH implies. Many enter here from an IT, help-desk, or networking background.

~$70K–$100K
2

Mid — Penetration Tester / Vulnerability Analyst

Move to the offensive side: run authorised tests, exploit findings safely, and write the reports clients act on. This is where the CEH most clearly pays for itself.

~$90K–$135K
3

Senior — Senior Pentester / Red Team Operator

Lead engagements, simulate advanced adversaries, and develop custom tooling. Often the point where people add a hands-on cert such as the OSCP to back up the CEH.

~$130K–$170K
4

Lead — Offensive Security Lead / Security Consultant

Own the testing practice or consultancy book, set methodology, and shape security strategy for the whole organisation. Compensation here leans heavily on total package and clearances.

~$160K–$210K+

04 Who is hiring

Offensive-security skills are in demand almost everywhere, because almost every organisation now needs its defences tested. The biggest employers of CEH holders cluster into a few groups.

Employer typeWhy they want the CEH
Government & defence contractorsThe CEH is a DoD 8140 approved baseline, so it is named directly on cleared and federal security job requisitions
Security consultancies & pentest firmsBill clients for assessments; recognised certifications are a credibility and procurement requirement
Banks & financial servicesHeavily regulated and a prime target, so they staff strong testing, SOC, and vulnerability teams
Big tech security teamsRun internal red teams and product-security functions and need people who think like an attacker
Managed security service providersRun SOCs and testing for many customers; certified staff are a selling point and an SLA backstop

05 How to actually land the job

The certificate gets you noticed; these four moves get you hired.

Build a hacking lab and rack up boxes: spin up a home lab and work through Hack The Box and TryHackMe. Rooted machines, write-ups, and a GitHub of tooling prove you can actually do the work the CEH only describes.
Pair the CEH with hands-on proof: in interviews, the CEH frames the methodology — but be ready to walk through how you would enumerate, exploit, and pivot. Recruiters value the cert; hiring managers value the demonstration.
Enter where the door is open: if you are breaking in, target SOC analyst and security analyst roles first, not senior pentest postings. The CEH plus a year of hands-on defensive experience makes the pivot to pentesting far easier.
Don't stop at the CEH: for serious offensive roles, consider following it with a hands-on certification like the OSCP. The CEH opens the door and clears DoD reqs; a practical, exploit-heavy cert is what unlocks the senior testing salary bands.

06 FAQ

What jobs can you get with the CEH (Certified Ethical Hacker)?

It is most directly aimed at offensive-security roles such as Penetration Tester and Ethical Hacker, but it is valued across SOC Analyst, Security Analyst, Vulnerability Analyst, and Cybersecurity Consultant positions too. It appears on a large share of security job postings and is approved under the US DoD 8140 framework, so it strengthens applications well beyond the pentest title itself.

Is the CEH enough to get a penetration testing job?

The CEH is a strong door-opener and a recognised résumé keyword, but pentest roles also reward hands-on proof. The candidates who land offensive roles fastest pair the CEH with a home lab and practical platforms like Hack The Box or TryHackMe, and many add a hands-on certification such as the OSCP. Plenty of people enter through a SOC or security analyst role first, then move into pentesting within a year or two.

How much do CEH-certified professionals make?

In the US, CEH holders commonly earn a base in the region of $90K–$110K, with penetration testers typically landing around $90K–$135K and senior pentesters or red teamers reaching $170K or more. Figures vary widely by location, employer, clearance, and experience, and reported certification salary lifts of roughly 15–25% are commonly cited.

Is the CEH approved for US government and DoD jobs?

Yes. The CEH is an approved baseline certification under the US Department of Defense 8140 framework (the successor to the older 8570 directive), which makes it a common requirement on government and defence-contractor security job listings. That government recognition is one of the main reasons the CEH appears so often on US security job descriptions.

ExamCert
ExamCert TeamCertified cloud & security pros helping you pass faster.