If the quest is open to all comers, I turn to page 34.
0. Learn to love programming in at least one language. The C Programming Language has the most cachet in application security, but for this step-by-step list, Java or Python or Ruby will do fine.
1. Grab a copy of The Web Application Hacker’s Handbook and The Tangled Web
2. Go to the “previous releases” archive at WordPress.org and grab very old versions of WordPress; install them at EC2.
3. Download OWASP WebScarab or Burp Suite Free Edition, both of which are free, and use them to find bugs in ancient WordPress.
If you are at step 0 now and are immediately looking for a new gig in Chicago, San Francisco, or New York, you can also email me directly and get step 1 for free.