The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
IT Helpdesk / Service Desk Technician
1-3 years in the role before moving to security.Skills to master
- Troubleshooting IT issues, understanding user behaviour, basic networking, customer service, ticket management, and escalating problems effectively. You'd have picked up an understanding of common user-facing security issues.
You're ready to move on when
- You're the go-to person for phishing questions on the helpdesk.
- You've shown initiative in learning about security tools used in the organisation.
- You've taken on basic security tasks or projects in your current role.
- You've completed a foundational security certification like CompTIA Security+.
- 2
Junior SOC Analyst / Associate Security Analyst
1-2 years in a junior security role.Skills to master
- Following incident response playbooks, basic log analysis, using SIEM/EDR tools, understanding common attack vectors, and contributing to security documentation. This is a direct step up, building on foundational security skills.
You're ready to move on when
- You can independently triage low-severity alerts.
- You've contributed to updating runbooks or knowledge base articles.
- You're actively participating in team discussions and asking insightful questions.
- You've taken ownership of small, well-defined security tasks.
- 3
Network Administrator / Systems Administrator
2-4 years in an admin role.Skills to master
- Deep understanding of network infrastructure, operating systems (Windows/Linux), server management, and system hardening. You'd know how systems are supposed to work, which helps you spot when they're not.
You're ready to move on when
- You've implemented security configurations on servers or network devices.
- You've actively monitored system logs for security events.
- You've taken the lead on patching and vulnerability management in your admin role.
- You've expressed a strong interest in specialising in security.