Here’s one approach:
1) Find several local security meet-ups and get involved. Volunteer, talk, make friends. Network early and often, ask questions and learn.
2) Using the contacts and exposure developed above, find either an internship or contract role doing whatever security-related work you can find. You will (most likely) need to pay your dues, meaning it might be pretty basic security work to start with, but you’re looking for experience and further opportunity to grow your skills.
3) On the pentesting side, you’ll want to learn the target systems well (e.g., use them in practice), learn the common types of vulnerabilities and how to exploit them, and immerse yourself in opportunities to use your nascent skills (online challenges, capture-the-flag events, etc.). Read vulnerability reports published by other researchers, watch relevant videos, experiment on your own setups, and so forth.
4) As you feel more comfortable with your assessment skills, you might consider entering bug bounty programs.
Again, this is just one approach, there are many options depending on what works for you. Best of luck!
Edit: Line breaks.