The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior Security Analyst / Incident Responder (L3)
5-8 years to L3, then 4-7 years to L5Skills to master
- Moving from purely technical execution to leading major incidents, mentoring juniors, and starting to manage small projects or workstreams. You'll need to prove you can lead under pressure and translate technical issues into actionable plans.
You're ready to move on when
- Successfully led multiple major incidents from start to finish.
- Consistently acted as a technical escalation point for junior analysts.
- Designed and implemented new detection rules or SOAR playbooks.
- Demonstrated strong communication skills with non-technical stakeholders.
- 2
From SOC Team Lead (L4)
8-12 years to L4, then 3-5 years to L5Skills to master
- This is a very common path. You'll have already managed a shift or a small team, so the focus here is on scaling that leadership, taking on budget responsibilities, and defining strategic direction for a larger part of the SOC. You're moving from managing a segment to managing the whole operation.
You're ready to move on when
- Effectively managed a team of 3-8 analysts, including performance and scheduling.
- Contributed significantly to the design and refinement of detection rules and SOAR playbooks.
- Successfully managed small projects (e.g., new tool integration) end-to-end.
- Presented operational metrics and insights to senior management.
- 3
From Security Consultant (with Ops focus)
Varies, typically 10-15 years total experienceSkills to master
- If you're coming from consulting, you'll have a broad view of security programmes. You'll need to demonstrate deep operational experience, not just advisory. This means showing you can build and run a SOC, manage people directly, and own the day-to-day grind, not just provide recommendations.
You're ready to move on when
- Led security operations engagements for multiple clients.
- Designed and implemented SOC processes or technologies.
- Managed project teams, even if not direct reports.
- Strong understanding of various industry best practices and frameworks.