# Synack Red Team **Pathways**

Tips on how to improve your Synack Red Team application experience.

### **What are SRT Pathways?**

SRT Pathways are predefined third-party certifications/achievements that can be used to expedite an applicant’s onboarding experience into the Synack Red Team. There are two types of pathways available to applicants: [Priority](/content/red-team/pathways/#priority/index.html) and [Preferred](/content/red-team/pathways/#preferred/index.html).

### **Priority Pathways**

To qualify as an SRT Priority Pathway, an organization must:

- demonstrate a strong commitment to quality training and curriculum
- exceptional student reviews and knowledge retention
- uphold high standards in hands-on expertise and ethics
- strong program representation by high-performing researchers in the Synack Red Team

The following are the most current Priority SRT Pathways (in alphabetical order):

#### Offensive Security – [offsec.com](https://www.offsec.com/?ref=srt-pathways)

Empowering individuals and organizations to fight cyber threats with indispensable cybersecurity skills and resources.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [EXP-401](https://www.offsec.com/courses/exp-401/?ref=srt-pathways) (OSEE) | **Yes** | **Yes** | Yes, Web + Host |
| [OSCE³](https://www.offsec.com/guides/osce3-certification-2/?ref=srt-pathways) (OSCE³) _includes OSCE_ | **Yes** | **Yes** | Yes, Web + Host |
| [WEB-300](https://www.offsec.com/courses/web-300/?ref=srt-pathways) (OSWE) | **Yes** | **Yes** | Yes, Web Only |
| [PEN-300](https://www.offsec.com/courses/pen-300/?ref=srt-pathways) (OSEP) | **Yes** | **Yes** | Yes, Web + Host |
| [WEB-200](https://www.offsec.com/courses/web-200/?ref=srt-pathways) (OSWA) | **Yes** | No, but Priority | Yes, Web Only |
| [PEN-200](https://www.offsec.com/courses/pen-200/?ref=srt-pathways) (OSCP) | **Yes** | No, but Priority | Yes, Web + Host |
| [OSAI](https://www.offsec.com/courses/osai/?ref=srt-pathways) | **No** | No | Yes. AI Only<br> (must complement Web or Host) |

#### CREST – [crest-approved.org](https://www.crest-approved.org/?ref=srt-pathways)

CREST builds capability, capacity, consistency and collaboration in the global cyber security industry through services that nurture, measure and enhance the performance of individuals and organizations.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [CREST Certified Tester – Infrastructure](https://www.crest-approved.org/skills-certifications-careers/crest-certified-infrastructure-tester/?ref=srt-pathways) (CCT INF) | **Yes** | Yes | Yes, Host Only |
| [CREST Certified Tester – Application](https://www.crest-approved.org/skills-certifications-careers/crest-certified-web-application-tester/?ref=srt-pathways) (CCT APP) | **Yes** | Yes | Yes, Web Only |
| [CREST Registered Penetration Tester](https://www.crest-approved.org/skills-certifications-careers/crest-registered-penetration-tester/?ref=srt-pathways) (CRT) | **Yes** | No | Yes, Web Only |

#### HackTheBox – [hackthebox.com](https://www.hackthebox.com/?ref=srt-pathways)

Hack The Box gives individuals, businesses and universities the tools they need to continuously improve their cybersecurity capabilities — all in one place.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [HTB Certified Web Exploitation Expert](https://academy.hackthebox.com/preview/certifications/htb-certified-web-exploitation-expert/?ref=srt-pathways) (CWEE) | **Yes** | No, but Priority | Yes, Web Only |
| [HTB Certified Penetration Testing Specialist](https://academy.hackthebox.com/preview/certifications/htb-certified-penetration-testing-specialist/?ref=srt-pathways) (CPTS) | **Yes** | No, but Priority | Yes, Web + Host Only |
| [HTB Web Penetration Testing Certification](https://academy.hackthebox.com/preview/certifications/htb-certified-web-exploitation-specialist/?ref=srt-pathways) (CWES) | **Yes** | No, but Priority | Yes, Web + Host Only |
| [HTB Certified Offensive AI Expert](https://academy.hackthebox.com/preview/certifications/htb-certified-offensive-ai-expert??ref=srt-pathways) (COAE) | **No** | No | Yes. AI Only<br> (must complement Web or Host) |

#### PortSwigger – [portswigger.net](https://portswigger.net/?ref=srt-pathways)

PortSwigger, the maker of Burp Suite, helps more than 70,000 professionals – at over 16,000 organizations – to secure the web and speed up software delivery.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [Burp Suite Certified Practitioner](https://portswigger.net/web-security/certification?ref=srt-pathways) (BSCP) | **Yes** | No, but Priority | Yes, Web Only |

#### SANS Technology Institute – [sans.edu](https://www.sans.edu/?ref=srt-pathways)

Whether you’re just getting started in cybersecurity or you’re a seasoned InfoSec professional, SANS.edu gives you the skills you need to advance and the GIAC certifications to prove it.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [SEC 660](https://www.sans.org/cyber-security-courses/advanced-penetration-testing-exploits-ethical-hacking/?ref=srt-pathways) w/GXPN | **Yes** | **Yes** | Yes, Web + Host |
| [GX-PT](https://www.giac.org/certifications/experienced-penetration-tester-gxpt/?ref=srt-pathways) | **Yes** | **Yes** | Yes, Web + Host |
| [SEC 542](https://www.sans.org/cyber-security-courses/web-app-penetration-testing-ethical-hacking/?ref=srt-pathways) w/GWAPT | **Yes** | No, but Priority | Yes, Web Only |
| [SEC 565](https://www.giac.org/certifications/red-team-professional-grtp/?ref=srt-pathways) w/GRTP | **Yes** | No, but Priority | Yes, Host Only |
| [SEC 560](https://www.sans.org/cyber-security-courses/enterprise-penetration-testing/?ref=srt-pathways) w/GPEN | **Yes** | No, but Priority | Yes, Host Only |
| [GOAA](https://www.giac.org/certifications/offensive-ai-analyst-goaa/?ref=srt-pathways) | **No** | No | Yes. AI Only<br> (must complement Web or Host) |
| [SEC 575](https://www.sans.org/cyber-security-courses/mobile-device-security-ethical-hacking/?ref=srt-pathways) w/GMOB | No | No | Yes, Mobile Only<br> (must complement Web or Host) |

**_Note:_** _Additional consideration is given to applicants from SANS Cyber Immersion Academies that align with Synack’s own Veterans initiatives._

**_Note:_** [_GIAC_](https://www.giac.org/?ref=srt-pathways) _certifications outside of SANS also qualify for this SRT Pathway. Certifications must be digitally verifiable during the application process._

#### SRT Referrals – [acropolis.synack.com](https://acropolis.synack.com/?ref=srt-pathways)

All SRT members (Level 0x03+) can make referrals. Up to 20 SRT are honored annually as Synack Envoy for their contributions to health, growth and mentorship in the Synack Red Team community.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [Envoy](https://acropolis.synack.com/envoy?ref=srt-pathways) SRT Referral | **Yes** | No, but Priority | (Conditional on Resume / Experience) |
| Standard SRT Referral | No, but Priority | No | None |

### Preferred Pathways

Preferred pathways are additional achievements applicants can pursue to improve their chances for acceptance and onboarding experience.

The following are the most current Preferred SRT Pathways:

#### APIsec University – [apisecuniversity.com](https://www.apisecuniversity.com/?ref=srt-pathways)

APIsec University courses provide actionable, hands-on training to help you keep APIs secure.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [API Security Certified Professional (ASCP)](https://www.apisecuniversity.com/courses/ascp-exam?ref=srt-pathways) | Yes | No | Yes, API Only<br> (must complement Web or Host) |

_Note: This pathway requires that both courses be complete and paired with successful Web or Host assessment criteria._

#### TCM Security – [tcm-sec.com](https://tcm-sec.com/?ref=srt-pathways)

Hands-On Training Designed, Developed, and Tested to Teach You the Practical Skills and Knowledge from Real Penetration Testers.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [Practical Web Pentest Expert](https://certifications.tcm-sec.com/pwpe/?ref=srt-pathways) (PWPE) | **Yes** | No | Yes, Web Only |
| [Practical Web Pentest Professional](https://certifications.tcm-sec.com/pwpp/?ref=srt-pathways) (PWPP) +<br>[Practical Network Penetration Tester](https://certifications.tcm-sec.com/pnpt/?ref=srt-pathways) (PNPT) | **Yes** | No | Yes, Web + Host Only |

_Note: All listed certifications must be active to be eligible for an SRT Pathway._

#### Barracks – [barracks.army](https://barracks.army/for-practitioners#warzones?ref=srt-pathways)

Built by trusted Synack Red Team researchers, Barracks is where operators sharpen their craft and prove it, held to a standard of trust, honor, and excellence.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| Barracks Army Referral | **Yes** | No | Yes, Web Only |

#### Blackhat University – [blackhat.com](https://www.blackhat.com/us-23/certified-pentester.html?ref=srt-pathways)

The Black Hat Certified Pentester (BCPen) is an intermediate level exam, intended to be taken by professional pentesters, bug-bounty hunters, red and blue team experts, and anyone wanting to get involved with hands-on pentesting.

| **Pathway** | **Resume Review Bypass** | **Wait List Review Bypass** | **Technical Review Bypass** |
| --- | --- | --- | --- |
| [Black Hat Certified Pentester](https://www.blackhat.com/us-23/certified-pentester.html?ref=srt-pathways) (BCPen) | **Yes** | No | Yes, Web + Host Only |

_**Note:** Applicants with the equivalent [CAPen](https://pentestingexams.com/certifications/professional/certified-appsec-pentester/) and [CNPen](https://pentestingexams.com/certifications/professional/certified-network-pentester/) certifications from [The SecOps Group](https://secops.group/?ref=srt-pathways) are also eligible for this pathway. Certifications must be digitally verifiable during the application process._

###### What is the Synack Red Team Onboarding Process?

###### Resume Review

Verifies industry and high-level eligibility for Synack Red Team consideration.

###### Wait List Review

Ensures proportional researcher growth by prioritizing skill and regional positions to customer opportunities.

###### Technical Review

Confirms the applicant has the required level of hands-on technical skill to deliver value to customers. This is done through a private CTF on the HackTheBox platform.

###### Personal Interview

Assesses team fit and addresses required declarations and questions from the applicant.

###### Background & ID Verification

Checks to ensure that the applicant has a clear background and identification, which is required by customers for participation on their targets.

###### Platform Training

Onboarding lessons to understand platform, tooling and rules of engagement.
