The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Engineer
3-5 years as a Senior EngineerSkills to master
- Deep technical expertise in a specific security domain (e.g., cloud, application, network security), ability to independently lead complex technical projects, strong problem-solving skills, and initial experience mentoring junior team members.
You're ready to move on when
- You're consistently asked to solve the hardest technical problems on the team.
- You've successfully led several complex security implementations from start to finish.
- You're regularly providing technical guidance and mentoring to other engineers.
- You've started thinking beyond individual components to how systems fit together securely.
- 2
Security Consultant (External)
5-8 years as a consultantSkills to master
- Broad exposure to diverse security architectures across different industries, strong client-facing communication and presentation skills, ability to quickly assess and design solutions for new environments, and experience managing complex engagements.
You're ready to move on when
- You've advised multiple clients on their security architecture and strategy.
- You can quickly understand a new organisation's security posture and identify key architectural gaps.
- You're adept at translating technical risks into business language for executive stakeholders.
- You enjoy the challenge of designing solutions for varied environments.
- 3
DevSecOps Lead/Architect
4-6 years in DevSecOps rolesSkills to master
- Expertise in integrating security into the software development lifecycle (SDLC), automation of security controls, secure coding practices, and strong collaboration with development and operations teams. A real 'shift left' mindset.
You're ready to move on when
- You've successfully implemented security automation within CI/CD pipelines.
- You're a champion for secure coding practices within development teams.
- You've designed and implemented security controls for cloud-native applications.
- You understand the developer's perspective and can build security solutions that enable, not hinder, agility.