The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Security Engineer / Security Architect (L4)
3-5 years at L4Skills to master
- Deep technical expertise in multiple security domains, designing and implementing complex security solutions, leading technical projects, informal mentorship of junior staff, and influencing technical decisions across teams.
You're ready to move on when
- Successfully architected and delivered a major security solution (e.g., a new cloud security posture management system) end-to-end.
- Consistently sought out by other teams for your technical expertise and advice on security matters.
- Proven ability to mentor junior engineers, helping them unblock technical challenges and grow their skills.
- Demonstrated ability to translate technical risks into clear, actionable recommendations for senior technical leadership.
- 2
Senior Security Analyst / Engineer (L3)
5-8 years at L3, then 3-5 years at L4Skills to master
- Mastering incident response, threat hunting, vulnerability management, and contributing to security tool optimisation. You'd then need to gain the architectural and leadership skills of an L4.
You're ready to move on when
- Consistently leading complex incident response efforts and driving post-incident improvements.
- Developing and implementing new detection rules or security controls that significantly reduce risk.
- Taking ownership of significant security projects and seeing them through to completion.
- Proactively identifying and proposing solutions to systemic security issues.
- 3
GRC Specialist / Manager (from another organisation)
10-15 years in GRC rolesSkills to master
- Expertise in multiple compliance frameworks (ISO, SOC 2, PCI-DSS), managing audit processes, risk assessment methodologies, and translating regulatory requirements into actionable security controls. You'd need to demonstrate strong leadership and stakeholder management.
You're ready to move on when
- Successfully managed multiple external audits with zero high-risk findings.
- Developed and implemented a comprehensive risk management programme.
- Proven ability to influence business leaders on compliance and risk matters.
- Experience building and leading a GRC-focused team.