The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior Security Engineer
3-5 years as a Senior EngineerSkills to master
- Moving from individual contributor to team lead, taking ownership of projects, providing technical mentorship, and starting to translate technical risks into business terms.
You're ready to move on when
- Successfully led complex security projects from start to finish.
- Consistently mentored junior team members and helped them grow.
- Demonstrated ability to influence cross-functional teams without direct authority.
- Proactively identified and proposed solutions to systemic security issues.
- Comfortable presenting technical information to non-technical audiences.
- 2
From Lead Security Architect
2-4 years as a Lead ArchitectSkills to master
- Shifting from designing solutions to managing the team that implements and operates them, managing budgets, and focusing on people leadership alongside technical strategy.
You're ready to move on when
- Designed and implemented enterprise-wide security solutions that are now in production.
- Established technical standards and best practices for security.
- Provided informal leadership and guidance to other architects or engineers.
- Demonstrated strong communication skills with executive-level stakeholders.
- Expressed a clear interest in people management and team development.
- 3
From GRC Specialist / Consultant
4-6 years in GRC, including senior rolesSkills to master
- Deepening technical understanding of security controls, moving beyond compliance frameworks to practical implementation and operational security management, and leading technical teams.
You're ready to move on when
- Successfully managed complex compliance audits (e.g., ISO 27001, SOC 2).
- Developed and implemented robust security policies and procedures.
- Demonstrated strong understanding of underlying technical security controls.
- Proven ability to influence technical teams to adopt secure practices.
- Experience with risk management frameworks beyond basic qualitative assessments.