The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From ISO 27001 Security Analyst (L2)
2-3 years at L2Skills to master
- Moving from owning a subset of controls to leading the entire internal audit programme, managing external auditors, and mentoring juniors. You'll need to develop strong stakeholder influence and leadership skills.
You're ready to move on when
- Successfully managed multiple internal control audits from start to finish.
- Consistently closed corrective actions on time and effectively.
- Demonstrated ability to identify and propose improvements to ISMS processes.
- Acted as a go-to person for junior colleagues' ISO 27001 questions.
- 2
From Information Security Consultant (External)
3-5 years as a consultantSkills to master
- Adapting from project-based consulting to owning an ISMS long-term within a single organisation. This means getting deep into our specific business context, building internal relationships, and dealing with day-to-day operational challenges rather than just advising.
You're ready to move on when
- Experience leading ISO 27001 implementation projects for multiple clients.
- Strong understanding of the full ISMS lifecycle, not just initial certification.
- Demonstrated ability to manage client relationships and expectations.
- Proven track record of delivering practical, implementable security solutions.
- 3
From IT Audit Specialist
4-6 years in IT AuditSkills to master
- Shifting from purely auditing to both auditing and *managing* the ISMS. This means you'll need to move beyond identifying issues to designing and implementing solutions, and influencing control owners to adopt them. It's about being a builder, not just a checker.
You're ready to move on when
- Deep understanding of IT controls and audit methodologies.
- Experience identifying control weaknesses and recommending improvements.
- Strong analytical and documentation skills.
- A desire to move into a more 'hands-on' (from a management perspective) security and compliance role.