United Kingdom · Technical roles · Mid-Level (2-5 years)

IT Security Manager

Here is the whole job, in plain words. What it is, a real day, what you decide, how you're judged, how people get here and where they go next. Then the part no course gives you: twelve AI tutors who learn your work.

  • Experience bandMid-Level (2-5 years)
  • Direct reportsNo direct reports
  • Reports toSenior IT Security Manager
  • UK framework levelUsually a coordinator, or early in a professional job

Also advertised as Security Engineer · Information Security Specialist · Cyber Security Analyst (Mid-level)

Built on an analysis of 43,079 real UK job descriptions · grounded in qualifications employers recognise

Start with a free Future Fluency check, tuned to IT Security Manager

Ten quick questions, one per Future Fluency, asked against this role rather than a generic one. About five minutes, and no card.

Start the check, free

1What this role really is

This role is all about getting your hands dirty with our security tech. You'll be the one making sure our security tools actually work, day in, day out. It's less about high-level strategy and more about the practical application of security controls to keep our systems safe. Think of yourself as a crucial gear in the machine, keeping everything turning smoothly and securely.

2What you'd actually use

The tools this job runs on, and how well you'd need to know each one.

Splunk Enterprise SecurityIntermediate

Investigating security alerts, running pre-built queries to hunt for specific threats, creating basic dashboards for daily monitoring of key security metrics. You'll be tuning event sources to reduce noise, too.

CrowdStrike FalconIntermediate

Responding to endpoint detections, performing host isolation when a device is compromised, pulling forensic data using the console, and deploying/troubleshooting sensor policies. You'll be our resident expert here.

Tenable.io / Qualys VMDRIntermediate

Running credentialed and uncredentialed vulnerability scans, validating findings to ensure they're real, and assigning patching tickets to the relevant teams based on severity and business impact. You'll be chasing up remediation, too.

Okta / Azure Active Directory (Entra ID)Intermediate

Managing user access requests, troubleshooting multi-factor authentication (MFA) issues, deprovisioning accounts, and configuring basic single sign-on (SSO) integrations for new applications. You're the gatekeeper for identity.

Wiz / Palo Alto Prisma CloudBasic

Reviewing dashboards for high-priority cloud misconfigurations (e.g., publicly exposed S3 buckets, overly permissive IAM roles) and triaging alerts. You'll be learning the ropes of cloud security here.

Palo Alto Networks (Panorama)Intermediate

Reviewing firewall logs for suspicious traffic patterns, making minor rule changes under supervision, and understanding security profiles like Threat Prevention. You'll be helping to keep our network perimeter secure.

3What you get to decide, and how that grows

Power in a job isn't your title. It's what you're allowed to decide. Here's how it grows as you move up.

The choiceComing inWhere you are nowThe step above
Security Tool Configuration ChangesPropose changes to supervisor, execute under direct supervision.Independently configure and implement changes within established policies; escalate complex or impactful changes (e.g., affecting multiple departments) for approval.Design and implement complex configurations, define best practices for junior staff, approve changes for significant systems.
Incident Response ActionsFollow defined playbooks, escalate immediately upon identification of an incident.Lead initial investigation and containment actions for low-to-medium severity incidents following playbooks; escalate high-severity incidents and any deviation from playbooks.Lead the response for high-severity incidents, make real-time containment decisions, coordinate across teams, define new playbooks.
Vulnerability Remediation PrioritisationAssign tickets based on CVSS score and existing guidelines.Prioritise remediation based on CVSS, business context, and asset criticality; propose exceptions for approval.Define the overall vulnerability management strategy and prioritisation framework, approve major remediation plans.
Access Control Policy UpdatesProcess routine user access requests following predefined roles.Configure SSO/MFA policies and conditional access rules within established frameworks; propose new policies for specific applications.Design and implement enterprise-wide IAM policies, architect lifecycle management workflows, approve significant access changes.

4How you'll be judged

The scoreboard, honestly: the hard targets, how often each one is actually looked at, and the quiet human signals that never make it onto a dashboard.

Mean Time to Acknowledge (MTTA) for Critical Alerts
How quickly you acknowledge and begin investigating high-severity security alerts generated by our SIEM or EDR.
Target · < 15 minutes

If a critical alert comes in at 10:00, you should have acknowledged it and started initial investigation by 10:14 at the latest. We track this automatically.

Vulnerability Remediation SLA Compliance
The percentage of assigned critical and high-severity vulnerability tickets that are closed within their agreed service level agreement (SLA).
Target · 90% or higher

If you're assigned 20 critical vulnerabilities with a 7-day SLA, you should get at least 18 of them closed within that timeframe. We know some are tricky, but that's the goal.

Security Tool Configuration Accuracy
The error rate in configuring new security policies, rules, or integrations within tools like Splunk, CrowdStrike, or Okta.
Target · < 5% error rate

When you implement a new conditional access policy in Azure AD, we'll check it. If you accidentally lock out half the finance team, that's an error. We aim for very few of those.

Endpoint Protection Coverage
The percentage of managed endpoints (laptops, servers) that have our EDR solution (e.g., CrowdStrike Falcon) correctly installed, configured, and reporting.
Target · 98% or higher

If we have 1,000 devices, we expect at least 980 of them to be fully protected and reporting. You'll be chasing up the stragglers with IT Ops.

Proactive Threat Identification
How well you identify potential security gaps or emerging threats before they become major issues, and propose practical solutions.
  • You're regularly flagging new attack vectors you've read about and suggesting how we might be vulnerable. You might spot a misconfiguration during a routine check that no one else noticed. This shows up in your weekly catch-ups with your manager, or in the suggestions you put forward for new detection rules.
Documentation Quality & Completeness
The clarity, accuracy, and completeness of the documentation you create for security tool configurations, incident response playbooks, and standard operating procedures.
  • Someone else on the team should be able to pick up your documentation and follow it without needing to ask you a dozen questions. It's about keeping our Confluence up-to-date and making sure our runbooks are actually useful during an incident. We'll check this during peer reviews and when new team members are onboarded.
Collaboration & Knowledge Sharing
Your willingness to share your technical knowledge with colleagues, help unstick junior team members, and contribute to a positive team environment.
  • You're actively participating in team discussions, offering to help out when someone's stuck on a tricky config, and contributing to our internal knowledge base. Your manager will notice if you're a good team player, and frankly, so will your colleagues. We're a small team, so everyone's contribution matters.

5Would you like it

The honest version. What people enjoy, and what grinds them down.

What people enjoy
Protecting the Organisation

You'll find satisfaction in closing vulnerability tickets, tuning SIEM alerts to catch real threats, and knowing your work directly contributes to keeping our data and systems safe. It's about being the digital guardian.

You'll get a real kick out of seeing a dashboard showing zero critical vulnerabilities, or successfully blocking a phishing attempt before it reaches users. That's your win.

Technical Problem Solving

You love digging into logs, troubleshooting why a security tool isn't working as expected, or figuring out the root cause of a suspicious alert. You enjoy the puzzle of cyber security.

Spending an afternoon deep-diving into Splunk logs to trace an anomalous network connection, or trying to understand why a specific EDR policy isn't applying correctly, sounds like a good day to you.

Continuous Learning & Growth

The cyber security landscape changes constantly, and you're genuinely excited by that. You're always reading up on new threats, tools, and techniques, and you're keen to apply what you learn.

You're the first to sign up for a webinar on a new cloud security feature, or you're spending your lunch break reading a blog post about the latest ransomware variant. You see it as an opportunity, not a chore.

What frustrates people
  • Patching Politics: The endless cycle of identifying a critical vulnerability and then having to chase system owners to actually fix it, often hearing 'we can't, it might break something'.
  • Alert Tsunami: Drowning in thousands of low-fidelity alerts from a poorly tuned SIEM, making it incredibly hard to spot the one alert that actually matters.
  • User Apathy: Spending time on phishing training, only to see someone click a dodgy link five minutes later.
  • The 'Department of No' Perception: Constantly battling the idea that security is a blocker, rather than an enabler, for the business.
What this role does not give you
  • A quiet, predictable routine – expect urgent requests and shifting priorities.
  • Complete autonomy over strategic direction – you'll be implementing, not defining, the overall security strategy.
  • A role where every single piece of your work makes it to 'production' – some fixes will be deprioritised or deferred.
  • A job where you're always popular – sometimes you'll have to deliver bad news or enforce unpopular policies.

6Who you work with

Your work directly influences our ability to detect, prevent, and respond to cyber threats. A well-maintained security infrastructure means fewer incidents, less downtime, and better protection of company and customer data. Get it wrong, and we're looking at potential breaches, reputational damage, and hefty fines. It's a big deal, honestly.

Inside the business
  • Senior IT Security Manager (for guidance and approvals)
  • IT Operations Team (for patching and system changes)
  • Development Teams (for secure coding practices)
  • Helpdesk (for user access and incident triage)
  • Other Security Engineers (for collaboration on projects)
Outside the business
  • Security tool vendors (for support and troubleshooting)
  • Managed Security Service Providers (MSSPs, if applicable)

7What you need before you start

Not a wish list. The things you would be expected to already have.

  • At least 2 years of hands-on experience in an IT security role, such as a Security Analyst or Junior Security Engineer, where you were actively involved in alert monitoring, vulnerability management, or access control.
  • Proven experience configuring and troubleshooting at least two of the following: SIEM platforms (Splunk, Sentinel), EDR solutions (CrowdStrike, SentinelOne), or vulnerability scanners (Tenable, Qualys).
  • A solid understanding of networking fundamentals (TCP/IP, firewalls, routing) and operating system security (Windows and Linux).
  • Demonstrable experience with incident response procedures, even if it was following a playbook for low-severity alerts.
  • A genuine curiosity for cyber security and a commitment to continuous learning in a rapidly evolving field.

8What to practise next

Where the job is going, and what to do about it starting this week.

Advanced Cloud Security Architecture & Policy

Our reliance on cloud platforms (AWS, Azure) is only growing. You'll need to move beyond just triaging alerts to understanding how to design secure cloud environments, write custom CSPM policies, and integrate security into cloud-native development pipelines. This means thinking about security from the ground up in the cloud, not just as an add-on.

Cloud Security Posture Management (CSPM) policy wr · Cloud Workload Protection Platform (CWPP) integrat · Serverless function security (Lambda, Azure Functi · Container security (Docker, Kubernetes) · Cloud identity and access management (IAM) best pr

  • This week: Deep-dive into the security features of one specific cloud service we use (e.g., AWS S3 or Azure Storage Accounts).
  • This month: Complete an advanced cloud security course (e.g., AWS Certified Security - Specialty or Azure Security Engineer Associate).
  • Month 2: Propose and implement a custom security policy within Wiz or Prisma Cloud to address a specific risk.
  • Month 3: Work with a development team to integrate security scanning into their CI/CD pipeline for a cloud application.

Quick win: Review our current cloud security policies and identify any gaps based on recent industry best practices. Start a conversation with our cloud architects.

Advanced Threat Hunting & Forensics

Attackers are getting stealthier. Relying solely on automated alerts isn't enough anymore. You'll need to develop the skills to proactively search for adversaries in our network and endpoints (threat hunting) and conduct deeper forensic analysis when an incident occurs. This is about being a detective, not just a guard.

MITRE ATT&CK framework for adversary emulation · Advanced SIEM query languages (e.g., Splunk SPL, K · Endpoint Detection and Response (EDR) telemetry an · Network traffic analysis (packet capture, flow dat · Memory forensics and disk image analysis

  • This week: Study the MITRE ATT&CK framework and map some of our existing detections to it.
  • This month: Practice writing complex queries in Splunk or Sentinel to hunt for specific TTPs (Tactics, Techniques, and Procedures).
  • Month 2: Participate in a 'purple teaming' exercise, working with ethical hackers to improve our detection capabilities.
  • Month 3: Take an online course or certification in advanced incident response or digital forensics.

Quick win: Start a personal project to analyse open-source threat intelligence and translate it into potential hunting queries for our SIEM. Share your findings with the team.

9Staying current once you are in

What people here do to keep up
  • Actively participate in local cyber security meetups or online communities (e.g., OWASP, BSides).
  • Follow leading security researchers and blogs (e.g., KrebsOnSecurity, SANS Internet Storm Centre).
  • Experiment with home lab setups to test new security tools or practice incident response scenarios.
  • Contribute to open-source security projects or bug bounty programmes (if you're feeling brave!).
  • Attend relevant industry webinars or virtual conferences to stay up-to-date on emerging threats and technologies.

10How the AI economy is changing work like this

Before we ask anything of you, here's what we can already say about AI and work of this kind:

The new skill this role is being asked for: Prompt Engineering for Security Operations

AI is already integrated into many of our security tools, and its use is only going to grow. Being able to effectively 'talk' to these AI models – asking the right questions, refining your prompts – will dramatically boost your productivity in tasks like alert triage, threat intelligence summarisation, and even drafting incident reports. Analysts who figure this out will outproduce their peers.

We'll only ever tell you what we can actually back up. No hype, no scare tactics.

Your PlanIllustration

Built for IT Security Manager

5 units that map to this job, from the qualifications that cover it.

  1. Incident Response, Investigations and ForensicsQualifi Ltd · covers 3 of 7 standardsLevel 4
  2. Carrying out Information Security Incident Management activitiesPearson Education Ltd · covers 2 of 7 standardsLevel 3
  3. Incident Response and ManagementSFJ Awards · covers 2 of 7 standardsLevel 4
  4. Investigations and Incident ResponseQualifi Ltd · covers 2 of 7 standardsLevel 3
  5. Incident response and disaster recoveryNCFE · covers 1 of 7 standardsLevel 3
These are the real units behind this job, in the order they rank for it. Nothing here is marked done, because this plan has not been started by anyone yet. Yours would fill in as you go.

The rising capability

Zavmo analysis

What's rising in its place

This is where the work is heading, and the higher pay with it. Get fluent here and the shift stops being a threat and starts being your edge.

Prompt Engineering for Security Operations

AI is already integrated into many of our security tools, and its use is only going to grow. Being able to effectively 'talk' to these AI models – asking the right questions, refining your prompts – will dramatically boost your productivity in tasks like alert triage, threat intelligence summarisation, and even drafting incident reports. Analysts who figure this out will outproduce their peers.

  • Context windows and token limits for different LLM
  • Temperature settings for creative vs. factual outp
  • RAG (Retrieval Augmented Generation) for internal
  • Output validation and hallucination detection stra
  • Prompt chaining for complex security investigation

Security as Code (IaC for Security)

As more of our infrastructure moves to the cloud and we embrace DevOps, managing security configurations manually just won't scale. Being able to define and deploy security policies, firewall rules, and cloud security guardrails through code (Infrastructure as Code) ensures consistency, reduces human error, and speeds up deployment. It's the future of managing security at scale.

  • Terraform or CloudFormation for cloud resource dep
  • Ansible or Puppet for configuration management
  • Git for version control of security policies
  • CI/CD pipeline integration for security policy dep
  • Automated testing of security configurations

What you’ll use

Skills this role draws on

Technical

  • NIST Cybersecurity Framework (CSF) Application
  • Incident Response (IR) Lifecycle Execution
  • Basic Threat Modelling (STRIDE/DREAD)
  • Risk Management Fundamentals
  • Zero Trust Principles Application

The pathway

How you actually get there, here

How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.

  1. 1

    Security Analyst (Level 1)

    2-3 years

    Skills to master

    • Alert monitoring and triage, basic vulnerability scanning, incident response playbook execution, foundational networking and OS security. You're learning the ropes and getting hands-on with the tools.

    You're ready to move on when

    • Consistently meets MTTA targets for critical alerts.
    • Can independently perform vulnerability scans and assign tickets accurately.
    • Successfully participates in incident response activities following defined playbooks.
    • Demonstrates a solid understanding of core security concepts and our tech stack.
  2. 2

    IT Support / Network Engineer (with security focus)

    3-4 years

    Skills to master

    • Deep understanding of network infrastructure, system administration (Windows/Linux), troubleshooting complex IT issues, and a growing interest in security. You've seen the vulnerabilities from the other side.

    You're ready to move on when

    • Has taken on security-related projects or responsibilities in their previous role.
    • Completed relevant security certifications (e.g., Security+).
    • Can articulate how their previous experience translates to security operations.
    • Shows a proactive interest in security best practices and emerging threats.
  3. 3

    Graduate Cyber Security Programme

    1-2 years

    Skills to master

    • Intensive training across various security domains, mentored rotations, exposure to enterprise-level security tools and processes. This is a fast track if you've got the aptitude.

    You're ready to move on when

    • Successfully completed all programme modules and projects.
    • Received strong performance reviews from mentors and managers.
    • Demonstrates a broad understanding of security principles and practical application.
    • Eager to take on more responsibility and tool ownership.

11Where this role leads

The long view:Your journey as an IT Security Manager here is just the beginning. We're committed to helping you grow, learn, and achieve your career ambitions. If you're passionate about security and ready to make a real impact, we're excited to see where you'll go.

Pay & demand

The figure is the median for full-time employees in the ONS occupation this job title codes to (Cyber security professionals), from the April 2025 survey — about six months old when published, as ASHE always is. It is that occupation's middle, not this role's. Half earn more.

The ten Future Fluencies

Zavmo analysis

The credential is what you can do today. These are what keep you valuable.

A qualification proves you can do the job as it's defined today. These ten are what decide whether you're still the obvious person for it in five years. They're the capabilities employers are now writing into senior roles faster than people are learning them. Zavmo weaves them through whatever you study, so you come out with both: the credential and the fluency.

The highlighted ones are the Fluencies your role leans on hardest, from how IT Security Manager is actually changing. In about two minutes, the free confidence check asks where you stand on each of the ten. That's the whole check, and it's what makes the plan yours rather than generic.

12The team that's yours

No two people are taught the same way. This is one-to-one, not one-to-many.

Zavmo is a hyper-personalised AI learning platform. Twelve virtual tutors, each with a different way of teaching, and one orchestration agent that picks the right one for the moment. So every single lesson is shaped around you, your role, and the way you learn. Not a course everyone sits through. A conversation built for you, and no one else.

…and nine more, matched to you after your first chat. Meet all twelve

13What it feels like

A conversation, not a course

Because your tutor knows your role, your projects and your last session, learning sounds like this. And it's different for every single person:

Incident Response, Investigations and ForensicsLevel 4

Applied to your work in IT Security Manager

This unit aims to equip learners with an understanding of incident response as a business function, including the operation of Computer Emergency Response Teams (CERTs) and aligned task forces for business continuity, disaster recovery, and crisis management. Learners will also understand how major computer incidents are formally investigated, including evidence gathering and analysis, and the relevant legal and ethical considerations.

How the thinking builds
  1. Remember
  2. Understand
  3. Apply
  4. Analyse
  5. Evaluate
  6. Create
An illustration of a Zavmo lesson, built from this role’s own route. The unit, its objective and every criterion above are the awarding body’s own words, not an example.

One to one, not one to many

No two people run this the same way

A course is written once and handed to everyone. This is assembled around you, and keeps changing as it learns you. Five things it reads, and what each one changes.

  1. Your actual work Every lesson is taught against a live piece of your own work, not a worked example from a textbook.
  2. What you already know The first conversation finds your starting point, so you skip what you can already do and spend the time on what you cannot.
  3. The conditions you learn under Not a learning-styles quiz. The evidence does not support those. The dimensions the research does back, read once and used to shape the plan.
  4. How far you got last time It picks up mid-thought. The tutor knows what you said, what you struggled with, and what it asked you to try.
  5. Which tutor suits the moment Twelve of them, each for a different kind of thinking. The one who walks you through a first idea is not the one who stress-tests it.

See how you learn, free. Eight questions, no sign-up. A directional taster; the diagnostic inside Zavmo goes deeper and keeps adapting.

DemonstrateIllustration

Evidenced on your work in IT Security Manager

You do not finish by watching something. You finish by showing it on the work you already do, against the measures this job is judged on.

  • Mean Time to Acknowledge (MTTA) for Critical AlertsHow quickly you acknowledge and begin investigating high-severity security alerts generated by our SIEM or EDR.If a critical alert comes in at 10:00, you should have acknowledged it and started initial investigation by 10:14 at the latest. We track this automatically.< 15 minutes
  • Vulnerability Remediation SLA ComplianceThe percentage of assigned critical and high-severity vulnerability tickets that are closed within their agreed service level agreement (SLA).If you're assigned 20 critical vulnerabilities with a 7-day SLA, you should get at least 18 of them closed within that timeframe. We know some are tricky, but that's the goal.90% or higher
  • Security Tool Configuration AccuracyThe error rate in configuring new security policies, rules, or integrations within tools like Splunk, CrowdStrike, or Okta.When you implement a new conditional access policy in Azure AD, we'll check it. If you accidentally lock out half the finance team, that's an error. We aim for very few of those.< 5% error rate
  • Endpoint Protection CoverageThe percentage of managed endpoints (laptops, servers) that have our EDR solution (e.g., CrowdStrike Falcon) correctly installed, configured, and reporting.If we have 1,000 devices, we expect at least 980 of them to be fully protected and reporting. You'll be chasing up the stragglers with IT Ops.98% or higher
These are this job's own measures, with its own targets. Nothing is marked evidenced, because nobody has started this yet. Yours would fill in from the work you bring.

Your passport

This isn't a certificate you file away. It's a passport to the life you're designing.

Every credit you earn and every fluency you build adds up: evidence where it counts, carried with you. Zavmo keeps the map: where you are, where you're heading, and the next step, at your pace, around your life. From IT Security Manager to Senior IT Security Manager (Level 3), and whatever you decide comes after.

Level 3 · in progressAI Fluency→ Senior IT Security Manager (Level 3)→ your design
Where this takes you

Your journey as an IT Security Manager here is just the beginning. We're committed to helping you grow, learn, and achieve your career ambitions. If you're passionate about security and ready to make a real impact, we're excited to see where you'll go.

See Your Progress GrowIllustration
IT Security Manager
  • NIST Cybersecurity Framework (CSF) Application
  • Incident Response (IR) Lifecycle Execution
  • Basic Threat Modelling (STRIDE/DREAD)
  • Risk Management Fundamentals
  • Zero Trust Principles Application
This is your Mind Palace on learn.zavmo.ai. Every skill above comes from this role's own record, not an example borrowed from another job. A node lights up when you evidence it, and what you build stays yours between jobs. That is the part a course cannot do.

14The detail, folded away

Everything else the record holds

The career branches in full, how AI is already showing up in the day-to-day, and the questions people ask about this job. Here when you want them, out of the way while you decide.

Where it leads next, rung by rung

Where it leads

The career path, and where it branches

IT Security Manager is a start, not a ceiling. Each step below asks for new skills and hands back more autonomy.

  1. You'll move from owning specific tools and tasks to leading entire security workstreams and projects. You'll mentor junior staff and make significant technical decisions.

    • Security Architecture Design: Designing new security controls and solutions, not just implementing them.
    • Advanced Threat Hunting: Proactively searching for threats, developing new detection rules and methodologies.
    • Security Programme Maturity: Contributing to the overall maturity of our security programme (e.g., NIST CSF).
    • Vendor Management: Evaluating and managing relationships with security vendors.
Working with AI on the job

Working with AI

Where AI is starting to help

Let's be real, security work can be a bit of a grind sometimes. Sifting through logs, triaging alerts, drafting reports – it all takes time. But here's the thing: AI isn't just for the big strategic stuff anymore. It's already here, helping security engineers like you get more done, quicker, and with less headache.

For an IT Security Manager, AI is becoming your best mate. It's not about replacing you; it's about giving you superpowers. Think of it as having an ultra-fast, tireless assistant who can spot patterns, summarise reams of data, and even draft documents for you. This frees you up to focus on the truly interesting, complex, and human-centric security challenges.

Alert Triage Automation

Use AI-powered SOAR (Security Orchestration, Automation, and Response) platforms to automatically investigate, enrich, and even close low-level security alerts. For example, if we get an 'impossible travel' alert, the AI can automatically check login history, geo-location, and user behaviour, then either close it as a false positive or escalate it with all the relevant context. This means you're only looking at the alerts that genuinely need your human brain.

Anomaly Detection Acceleration

Leverage AI/ML models built into our SIEM (Splunk Enterprise Security) or UEBA (User and Entity Behaviour Analytics) tools. These can spot subtle patterns of malicious behaviour – like slow data exfiltration or lateral movement across the network – that would be practically invisible to traditional rule-based detection. It's like having a super-sniffer for the truly sneaky stuff, reducing detection time from days to mere minutes.

Threat Intel Summarisation

Ever feel like you're drowning in threat intelligence feeds, new CVE disclosures, and security research blogs? Use AI assistants to ingest all that information and provide a concise, relevant brief of what's actually important to our specific tech stack and threat landscape. You'll get the gist in minutes, saving you hours of reading and filtering.

Policy & Report Drafting

Utilise generative AI to create first drafts of security policies (e.g., a new password policy), incident post-mortem reports, or even internal communications about security best practices. You provide the key points, and the AI handles the structure, tone, and grammar. This means less time staring at a blank page and more time refining the message.

Common questions

Common questions

How do you become an IT Security Manager?

Common routes in include Security Analyst (Level 1) (2-3 years), IT Support / Network Engineer (with security focus) (3-4 years) and Graduate Cyber Security Programme (1-2 years). Times vary with prior experience.

Where can an IT Security Manager progress to?

This role can lead on to Senior IT Security Manager (Level 3) (3-5 years in role), depending on the skills you build.

What level is an IT Security Manager in the UK?

This role aligns to RQF Level 3 on the UK framework, a guide to the depth of qualification it maps to, not a hard entry bar.

What new skills matter most for an IT Security Manager?

Increasingly, Prompt Engineering for Security Operations and Security as Code (IaC for Security). These are the areas where the higher-paid, future-proof work is heading.

The honest bit

You’ve started things before

Most of them were built for a room full of people who aren’t you. A cohort moves on whether or not your week allowed it, and by the third week the thing you’re behind on becomes the reason you stop opening it.

There’s no cohort here, and no timetable to fall behind. Before anything starts, Zavmo asks when you’re sharpest and how long you can realistically sit down for, then builds the sessions around those answers. A bad fortnight changes your pace. It doesn’t put you behind.

And you only pay once you start learning. Searching and planning are free, and you can cancel any time — so the cost of finding out is an afternoon, not a year.

What it costs

Less than one coaching session. Every month.

A single career-coaching hour costs more than a month of this, and it ends when the hour does. Zavmo doesn't. It's £70 a month, about £2.30 a day, for a companion that knows an IT Security Manager, works on the job you actually do, and keeps going at your pace rather than a timetable's.

  • Searching and planning stay free. You only pay when you start learning.
  • Your credits are yours. Regulated, and they don't vanish when a subscription ends.
  • Cancel any time and billing stops. No notice period, no minimum term.

Your path, personalised

You have the map. Walking it is the part we do together.

This route runs to 7 national skill standards. That is a real journey.

Zavmo shapes a learning experience as unique as you are. It fits how you learn, your pace and the work you already do. Every step stays benchmarked to recognised national standards. That’s the plan for becoming an IT Security Manager: personal to you, and it still counts. The first steps are free.

Independent research finds well-designed intelligent tutoring performs nearly as well as one-to-one human tutoring: VanLehn (2011), Educational Psychologist.

A private tutor in the UK averages £35–40 an hour . Zavmo is £70/month.

A real plan on learn.zavmo.ai: Ofqual-regulated units, credits, and a three-month run at your own pace.
Start free No commitment. See your first steps free.

15Where to go from here

Other roles at Level 3

Same depth of qualification, different job. Useful if the work appeals but this particular role does not.

Other roles in Technical roles

Stay in the field you know and move sideways rather than up.

If you leave this industry

The skills you'll gain as an IT Security Manager are highly transferable across almost any industry. Every company needs strong security. You could move into finance, healthcare, tech, or even government, applying your expertise to different challenges. The core principles remain the same, but the context changes, which keeps things interesting.

Not sure this is the right direction?

Work out what you actually want from work first, then come back and see which roles fit it. Takes about ten minutes.

This role profile is © 2026Growth Engineering Technologies Ltd. Built from UK occupational standards and regulated qualification data, and written for Zavmo.

You're not behind. You're right on time. The shift is only just beginning. Your role won't look the same in two years. Be the one who leads the change, not the one it happens to. Build my plan, free Here's the first ten minutes: a 2-minute confidence check → your personalised roadmap → meet the tutors matched to you. No card, cancel any time. No card. Build your plan, see your roadmap and meet the twelve tutors matched to you. All free. When you're ready to start learning, it's £70 a month, billed monthly. Cancel any time and billing stops.