The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Associate Security Analyst (L1)
1-2 yearsSkills to master
- Independent alert investigation, basic system administration of security tools, strong understanding of incident response playbooks, initial vulnerability analysis.
You're ready to move on when
- Consistently meeting MTTA and SLA targets for alerts.
- Can troubleshoot common issues with security tools without supervision.
- Proactively identifies opportunities to improve existing processes.
- Demonstrates a solid grasp of our security architecture and controls.
- 2
From IT Operations/System Administrator with Security Focus
2-3 yearsSkills to master
- Deep dive into specific security tools (SIEM, EDR, VM), understanding of threat intelligence, incident response methodology, risk assessment principles.
You're ready to move on when
- Has taken on significant security responsibilities in previous roles (e.g., patching, access control, basic firewall management).
- Can demonstrate a strong interest and self-study in cybersecurity topics.
- Understands the 'why' behind security controls, not just the 'how' to implement them.
- Has completed relevant security certifications (e.g., Security+).
- 3
From Network Engineer with Security Responsibilities
2-3 yearsSkills to master
- Endpoint security concepts, vulnerability management, cloud security, identity and access management, incident response playbooks.
You're ready to move on when
- Deep expertise in network security devices (firewalls, IDS/IPS).
- Can articulate how network architecture impacts overall security posture.
- Has actively participated in network-related security incidents or investigations.
- Shows a desire to broaden their security expertise beyond just the network layer.