Pathways | Synack
Synack Red Team Pathways
Tips on how to improve your Synack Red Team application experience.
What are SRT Pathways?
SRT Pathways are predefined third-party certifications/achievements that can be used to expedite an applicant’s onboarding experience into the Synack Red Team. There are two types of pathways available to applicants: Priority and Preferred.
Priority Pathways
To qualify as an SRT Priority Pathway, an organization must:
- demonstrate a strong commitment to quality training and curriculum
- exceptional student reviews and knowledge retention
- uphold high standards in hands-on expertise and ethics
- strong program representation by high-performing researchers in the Synack Red Team
The following are the most current Priority SRT Pathways (in alphabetical order):
Offensive Security – offsec.com
Empowering individuals and organizations to fight cyber threats with indispensable cybersecurity skills and resources.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| EXP-401 (OSEE) | Yes | Yes | Yes, Web + Host |
| OSCE³ (OSCE³) includes OSCE | Yes | Yes | Yes, Web + Host |
| WEB-300 (OSWE) | Yes | Yes | Yes, Web Only |
| PEN-300 (OSEP) | Yes | Yes | Yes, Web + Host |
| WEB-200 (OSWA) | Yes | No, but Priority | Yes, Web Only |
| PEN-200 (OSCP) | Yes | No, but Priority | Yes, Web + Host |
| OSAI | No | No | Yes. AI Only (must complement Web or Host) |
CREST – crest-approved.org
CREST builds capability, capacity, consistency and collaboration in the global cyber security industry through services that nurture, measure and enhance the performance of individuals and organizations.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| CREST Certified Tester – Infrastructure (CCT INF) | Yes | Yes | Yes, Host Only |
| CREST Certified Tester – Application (CCT APP) | Yes | Yes | Yes, Web Only |
| CREST Registered Penetration Tester (CRT) | Yes | No | Yes, Web Only |
HackTheBox – hackthebox.com
Hack The Box gives individuals, businesses and universities the tools they need to continuously improve their cybersecurity capabilities — all in one place.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| HTB Certified Web Exploitation Expert (CWEE) | Yes | No, but Priority | Yes, Web Only |
| HTB Certified Penetration Testing Specialist (CPTS) | Yes | No, but Priority | Yes, Web + Host Only |
| HTB Web Penetration Testing Certification (CWES) | Yes | No, but Priority | Yes, Web + Host Only |
| HTB Certified Offensive AI Expert (COAE) | No | No | Yes. AI Only (must complement Web or Host) |
PortSwigger – portswigger.net
PortSwigger, the maker of Burp Suite, helps more than 70,000 professionals – at over 16,000 organizations – to secure the web and speed up software delivery.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| Burp Suite Certified Practitioner (BSCP) | Yes | No, but Priority | Yes, Web Only |
SANS Technology Institute – sans.edu
Whether you’re just getting started in cybersecurity or you’re a seasoned InfoSec professional, SANS.edu gives you the skills you need to advance and the GIAC certifications to prove it.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| SEC 660 w/GXPN | Yes | Yes | Yes, Web + Host |
| GX-PT | Yes | Yes | Yes, Web + Host |
| SEC 542 w/GWAPT | Yes | No, but Priority | Yes, Web Only |
| SEC 565 w/GRTP | Yes | No, but Priority | Yes, Host Only |
| SEC 560 w/GPEN | Yes | No, but Priority | Yes, Host Only |
| GOAA | No | No | Yes. AI Only (must complement Web or Host) |
| SEC 575 w/GMOB | No | No | Yes, Mobile Only (must complement Web or Host) |
Note: Additional consideration is given to applicants from SANS Cyber Immersion Academies that align with Synack’s own Veterans initiatives.
Note: GIAC certifications outside of SANS also qualify for this SRT Pathway. Certifications must be digitally verifiable during the application process.
SRT Referrals – acropolis.synack.com
All SRT members (Level 0x03+) can make referrals. Up to 20 SRT are honored annually as Synack Envoy for their contributions to health, growth and mentorship in the Synack Red Team community.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| Envoy SRT Referral | Yes | No, but Priority | (Conditional on Resume / Experience) |
| Standard SRT Referral | No, but Priority | No | None |
Preferred Pathways
Preferred pathways are additional achievements applicants can pursue to improve their chances for acceptance and onboarding experience.
The following are the most current Preferred SRT Pathways:
APIsec University – apisecuniversity.com
APIsec University courses provide actionable, hands-on training to help you keep APIs secure.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| API Security Certified Professional (ASCP) | Yes | No | Yes, API Only (must complement Web or Host) |
Note: This pathway requires that both courses be complete and paired with successful Web or Host assessment criteria.
TCM Security – tcm-sec.com
Hands-On Training Designed, Developed, and Tested to Teach You the Practical Skills and Knowledge from Real Penetration Testers.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| Practical Web Pentest Expert (PWPE) | Yes | No | Yes, Web Only |
| Practical Web Pentest Professional (PWPP) + Practical Network Penetration Tester (PNPT) |
Yes | No | Yes, Web + Host Only |
Note: All listed certifications must be active to be eligible for an SRT Pathway.
Barracks – barracks.army
Built by trusted Synack Red Team researchers, Barracks is where operators sharpen their craft and prove it, held to a standard of trust, honor, and excellence.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| Barracks Army Referral | Yes | No | Yes, Web Only |
Blackhat University – blackhat.com
The Black Hat Certified Pentester (BCPen) is an intermediate level exam, intended to be taken by professional pentesters, bug-bounty hunters, red and blue team experts, and anyone wanting to get involved with hands-on pentesting.
| Pathway | Resume Review Bypass | Wait List Review Bypass | Technical Review Bypass |
|---|---|---|---|
| Black Hat Certified Pentester (BCPen) | Yes | No | Yes, Web + Host Only |
Note: Applicants with the equivalent CAPen and CNPen certifications from The SecOps Group are also eligible for this pathway. Certifications must be digitally verifiable during the application process.
What is the Synack Red Team Onboarding Process?
Resume Review
Verifies industry and high-level eligibility for Synack Red Team consideration.
Wait List Review
Ensures proportional researcher growth by prioritizing skill and regional positions to customer opportunities.
Technical Review
Confirms the applicant has the required level of hands-on technical skill to deliver value to customers. This is done through a private CTF on the HackTheBox platform.
Personal Interview
Assesses team fit and addresses required declarations and questions from the applicant.
Background & ID Verification
Checks to ensure that the applicant has a clear background and identification, which is required by customers for participation on their targets.
Platform Training
Onboarding lessons to understand platform, tooling and rules of engagement.