The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From IT Security Manager (Large Organisation)
3-5 years as a ManagerSkills to master
- Moving from managing a specific security function (e.g., SOC, GRC) to overseeing multiple functions, developing a broader strategic perspective, and significantly increasing your executive communication and influence skills.
You're ready to move on when
- Successfully led a major security transformation project across multiple teams.
- Consistently exceeded targets for your managed security function.
- Demonstrated strong mentorship and development of your direct reports.
- Regularly contributed to broader IT strategy discussions beyond your immediate remit.
- 2
From Lead Security Architect (Enterprise Level)
4-6 years as a Lead ArchitectSkills to master
- Transitioning from designing solutions to leading people and programmes. This means developing strong people management skills, budget ownership, and the ability to translate technical architecture into business risk and strategy for senior leaders.
You're ready to move on when
- Successfully designed and overseen the implementation of multiple complex security architectures.
- Consistently influenced engineering and product teams on secure design principles.
- Acted as an informal mentor to junior architects or engineers.
- Presented architectural decisions and their risk implications to senior leadership.
- 3
From Senior Security Consultant (Big 4 / Specialist Firm)
5-7 years at Senior/Principal Consultant levelSkills to master
- Moving from project-based client work to owning an ongoing, internal security programme. This requires developing long-term strategic vision, building and managing internal teams, and navigating internal politics rather than external client relationships. You'll need to 'own the problem' rather than just advise on it.
You're ready to move on when
- Successfully led large-scale security transformation programmes for multiple clients.
- Developed strong client relationship management skills at the executive level.
- Demonstrated ability to build and lead project teams (even if matrixed).
- Deep understanding of various industry security frameworks and best practices.