The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior ISMS Specialist (L3)
3-5 years in previous roleSkills to master
- Leading internal audits, managing CAPAs end-to-end, effectively interfacing with external auditors, and mentoring junior team members. You should be comfortable owning significant workstreams.
You're ready to move on when
- Consistently delivers high-quality audit reports with actionable findings.
- Successfully manages and closes out complex non-conformities.
- Receives positive feedback from external auditors and internal stakeholders.
- Has demonstrated initiative in proposing process improvements for the ISMS.
- Has informally mentored junior colleagues and enjoys helping them develop.
- 2
Experienced IT Auditor / Security Consultant
5-8 years in previous roleSkills to master
- Deep understanding of IT controls and audit methodologies, ability to translate audit findings into actionable compliance requirements, and experience in client-facing roles where influencing and problem-solving were key. You'll need to adapt your audit lens to an ISMS design lens.
You're ready to move on when
- Has led multiple IT security audits or consulting engagements.
- Can clearly articulate the link between technical controls and business risks.
- Has experience presenting findings and recommendations to senior management.
- Demonstrates strong analytical and problem-solving skills in complex environments.
- Is eager to move from 'assessing' to 'building' and 'owning' a compliance programme.
- 3
Information Security Engineer / Architect with Compliance Focus
6-10 years in previous roleSkills to master
- A strong technical background in security architecture or engineering, with a keen interest in how security controls map to compliance frameworks. You'll need to develop your GRC process design and stakeholder management skills.
You're ready to move on when
- Has designed and implemented security controls for complex systems (e.g., cloud, network, application).
- Understands the technical nuances of various security technologies.
- Has contributed to compliance efforts from a technical perspective (e.g., evidence collection).
- Is keen to move into a role that balances technical understanding with process design and governance.
- Possesses strong problem-solving skills and an analytical mindset.