The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior Security Analyst
3-5 years as a Senior AnalystSkills to master
- Leading complex investigations, mentoring junior staff, owning specific security projects end-to-end, and presenting technical findings to non-technical audiences.
You're ready to move on when
- Successfully led multiple major incident responses.
- Mentored at least two junior analysts who then progressed in their careers.
- Designed and implemented a significant new security control or process.
- Consistently sought out opportunities to present findings to leadership.
- 2
From Lead Security Engineer / Threat Hunter
2-4 years as a Lead EngineerSkills to master
- Architecting new security solutions, proactively hunting for threats, acting as a technical escalation point, and influencing security strategy at a technical level.
You're ready to move on when
- Architected and deployed a major security system (e.g., new EDR, SIEM module).
- Led successful threat hunting operations that identified previously unknown threats.
- Consistently provided technical guidance and unblocked other engineers.
- Demonstrated ability to balance technical excellence with business requirements.
- 3
From GRC Specialist / Auditor
4-6 years in GRC/Audit rolesSkills to master
- Deep understanding of regulatory compliance, risk frameworks, audit processes, and the ability to translate these into actionable security controls and policies. This path requires a stronger technical foundation to manage a technical team.
You're ready to move on when
- Successfully managed multiple compliance audits (e.g., ISO 27001, GDPR).
- Developed and implemented risk assessment methodologies.
- Demonstrated strong technical understanding of security controls, not just audit checks.
- Proven ability to influence technical teams to adopt compliance requirements.