The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior ISMS Specialist / Lead GRC Analyst
3-5 years in a senior individual contributor role.Skills to master
- You'd need to have mastered programme management, strategic planning, team mentorship, and significant stakeholder influence. It's about moving from 'doing' to 'leading' and 'designing'.
You're ready to move on when
- Successfully led multiple complex internal audits or compliance projects end-to-end.
- Consistently provided mentorship and guidance to junior team members, with demonstrable impact on their development.
- Proactively identified and proposed strategic improvements to the ISMS, which were subsequently adopted.
- Demonstrated strong communication skills by presenting to senior management or external parties.
- 2
From Information Security Consultant (Specialising in ISO 27001)
5-7 years as a consultant, with experience leading client engagements.Skills to master
- Translating consulting experience into building and running an internal programme. This means developing internal stakeholder management, team leadership, and long-term programme ownership skills.
You're ready to move on when
- Managed full ISO 27001 implementation projects for multiple clients, from gap analysis to certification.
- Developed strong client relationship management skills, which translate well to internal stakeholder engagement.
- Demonstrated ability to build and deliver complex project plans and manage project teams (even if matrixed).