SA-APEX · prerequisites
What you need to walk in with.
Who this is for
A working practitioner, not a career changer.
The intended candidate is a working penetration tester, red-team operator, application security engineer, exploit developer or senior security engineer — employed by Security Arsenal, an internal corporate team, a consultancy, or a firm that competes with us — who has already run authorized engagements and built software or offensive tooling.
| Area | Minimum evidence before training or exam |
|---|---|
| Experience | Documented professional red-team, penetration-testing, application-security or equivalent offensive work. Recommended baseline is three or more years, with an experience-review route for candidates who do not fit that shape. |
| Programming | Demonstrated ability in at least three languages spanning scripting, systems and application development — for example Python plus PowerShell or Bash plus one of JavaScript/TypeScript, Go, Rust, C/C++, Java, C#, Ruby or PHP. We evaluate substance, not the labels on a CV. |
| Infrastructure | Hands-on administration of the estate you expect to attack: virtualisation, routing, VPN, firewall, directory services and a mixed operating-system fleet. The exam has you build it. |
| Engagement ownership | Examples of scoping, safe execution, evidence collection, reporting, remediation guidance and retesting. |
| Code reasoning | Ability to trace untrusted input, trust boundaries, state, authorization, concurrency and unsafe composition through unfamiliar code. |
| Professional conduct | Agreement to the authorization, confidentiality, disclosure, acceptable-use and exam-integrity requirements. |
On the three-year baseline
It is a recommendation, not a gate. Three years is where most people have owned enough engagements to have been wrong in public and learned from it. If your experience is unusual — deep and narrow, research-heavy, or accumulated somewhere that does not produce a conventional CV — say so in the application and make the case. We review the substance.
The one people underestimate
You have to be able to build the estate.
The exam has you design, deploy and configure a full enterprise environment — cloud and on-premise virtualisation, a routed core with BGP and OSPF, VPN, firewall, a Windows, Linux and macOS fleet, managed Apple and Android devices, and a working voice platform.
Then it takes that away and hands you somebody else’s. This is the phase that catches otherwise strong candidates, and it is not something you can revise for in a fortnight.
If you are a pure exploitation specialist
An active OSEE waives the manual foundation gate. It does not waive the build phase, the voice requirement, the development requirement or any AI phase — and those are exactly the areas a pure exploitation background tends to be thinnest in.
Readiness gates
Objective conditions before an exam is scheduled.
Self-attestation alone does not schedule an exam. These gates are evidenced in the practice range, and each one is recorded against your candidate record with the date and the approver.
Gate
Privacy
Gate
Engineering
Gate
Build
Gate
Evidence
Gate
Novel discovery
Gate
Reporting
Immediate fail conditions
Know these before you apply, not after.
- Excluded:Using AI to explain code the candidate cannot independently explain during oral defense.
- Excluded:Uploading protected exam or client-like data to an unapproved endpoint or a public model.
- Excluded:Acting outside scope, disabling safety controls, attacking shared infrastructure, or reaching another candidate’s work.
- Excluded:Claiming scanner output, a version match or a model assertion as an exploitable finding without proof.
- Excluded:Fabricating evidence, hiding a failed validation attempt, altering timestamps, or misrepresenting model or tool actions.
- Excluded:Failing to identify or report a planted critical issue that the approved coverage map makes reasonably discoverable.
- Excluded:Producing a materially unsafe exploit or remediation recommendation that would predictably harm the controlled target.
What this is not
If you are looking for any of these, this is the wrong program.
- Excluded:Not beginner penetration-testing instruction, and not a "become a hacker" program.
- Excluded:Not a certification for running a scanner, pasting the output into a model, or matching software versions to CVEs.
- Excluded:No pass based on multiple-choice questions, attendance, course completion, or an AI-generated report.
- Excluded:No uncontrolled use of consumer or public AI services with client code, credentials, screenshots, logs or findings.
- Excluded:No finding accepted without a reproducible attack path, evidence, impact analysis and source or runtime reasoning.
None of that is a judgement about anyone’s career stage. There are excellent programs that teach penetration testing from the ground up, and someone who takes one is doing the right thing. This is simply not one of them, and pretending otherwise would waste your money.