The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Security Engineer (L2)
2-3 years as an engineerSkills to master
- Moving from implementing to designing solutions, leading projects independently, understanding business context for security decisions, and beginning to mentor junior staff.
You're ready to move on when
- Successfully led multiple complex security tool implementations or upgrades.
- Consistently identified and proposed solutions for significant security gaps.
- Demonstrated ability to troubleshoot and resolve novel security issues without constant supervision.
- Received positive feedback on informal guidance provided to junior team members.
- 2
From IT Administrator with Security Focus
3-5 years in IT Admin + 2-3 years dedicated securitySkills to master
- Deepening technical security expertise beyond basic hardening, understanding advanced threat detection and response, mastering security frameworks, and developing strong influencing skills.
You're ready to move on when
- Successfully transitioned from general IT to a dedicated security role.
- Implemented significant security improvements in previous IT roles.
- Obtained relevant security certifications (e.g., GSEC, CySA+).
- Demonstrated ability to think like an attacker (healthy paranoia).
- 3
From Security Consultant (External)
3-5 years in consultingSkills to master
- Adapting from project-based external advice to long-term internal ownership, navigating internal politics, and building sustainable security programmes within a single organisation.
You're ready to move on when
- Experience delivering security projects in diverse environments.
- Ability to translate external best practices into actionable internal strategies.
- Strong client-facing communication and influencing skills.
- Desire to take long-term ownership of security posture rather than short-term engagements.