The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Security Engineer (L2)
2-3 yearsSkills to master
- Deep technical expertise in specific security domains (e.g., EDR, SIEM, Cloud Security), strong scripting and automation skills, independent problem-solving for routine issues, and effective collaboration within the security team.
You're ready to move on when
- Consistently delivers high-quality security implementations and configurations.
- Proactively identifies and proposes solutions for security issues.
- Can troubleshoot complex technical problems with minimal guidance.
- Has informally mentored new joiners or shared technical knowledge effectively.
- 2
Security Operations Centre (SOC) Analyst (L2)
3-4 yearsSkills to master
- Advanced incident response and threat hunting, deep understanding of adversary tactics (MITRE ATT&CK), SIEM content development, forensic analysis, and strong communication during incidents.
You're ready to move on when
- Has led multiple complex incident investigations from detection to remediation.
- Developed and tuned effective SIEM detection rules or SOAR playbooks.
- Demonstrates a proactive threat hunting mindset, not just alert response.
- Can clearly articulate incident details and impact to technical and non-technical audiences.
- 3
DevSecOps Engineer (L2)
2-3 yearsSkills to master
- Integrating security into CI/CD pipelines, IaC security, application security testing (SAST/DAST), container security, and strong collaboration with development teams.
You're ready to move on when
- Successfully embedded security controls into development workflows.
- Has experience with automated security testing tools and processes.
- Can effectively communicate security requirements to developers.
- Understands the trade-offs between security and development velocity.