The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Security Analyst (Level 1)
2-3 yearsSkills to master
- Alert monitoring and triage, basic vulnerability scanning, incident response playbook execution, foundational networking and OS security. You're learning the ropes and getting hands-on with the tools.
You're ready to move on when
- Consistently meets MTTA targets for critical alerts.
- Can independently perform vulnerability scans and assign tickets accurately.
- Successfully participates in incident response activities following defined playbooks.
- Demonstrates a solid understanding of core security concepts and our tech stack.
- 2
IT Support / Network Engineer (with security focus)
3-4 yearsSkills to master
- Deep understanding of network infrastructure, system administration (Windows/Linux), troubleshooting complex IT issues, and a growing interest in security. You've seen the vulnerabilities from the other side.
You're ready to move on when
- Has taken on security-related projects or responsibilities in their previous role.
- Completed relevant security certifications (e.g., Security+).
- Can articulate how their previous experience translates to security operations.
- Shows a proactive interest in security best practices and emerging threats.
- 3
Graduate Cyber Security Programme
1-2 yearsSkills to master
- Intensive training across various security domains, mentored rotations, exposure to enterprise-level security tools and processes. This is a fast track if you've got the aptitude.
You're ready to move on when
- Successfully completed all programme modules and projects.
- Received strong performance reviews from mentors and managers.
- Demonstrates a broad understanding of security principles and practical application.
- Eager to take on more responsibility and tool ownership.