The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Network Security Manager
5-8 years as a managerSkills to master
- Moving from managing a team to managing managers, developing strategic vision, executive communication, and budget ownership for a larger function.
You're ready to move on when
- Successfully led a major incident response from start to finish.
- Consistently exceeded performance metrics for their team.
- Mentored and developed multiple junior managers or senior individual contributors.
- Presented strategic recommendations to senior leadership with positive outcomes.
- 2
From Principal Security Architect
5-8 years as a principal architectSkills to master
- Transitioning from deep technical architecture to broader operational leadership, including team management, incident response oversight, and budget accountability.
You're ready to move on when
- Designed and implemented enterprise-wide security architectures for critical systems.
- Acted as a technical lead during major security incidents, guiding response efforts.
- Demonstrated strong influence across engineering teams without direct authority.
- Developed and presented technical roadmaps to executive stakeholders.
- 3
From Head of GRC (Governance, Risk, and Compliance)
5-8 years as Head of GRCSkills to master
- Shifting from a primary focus on policy and compliance to direct operational defence, incident response, and leading technical security teams. Requires a stronger technical operations background.
You're ready to move on when
- Successfully led the organisation through major compliance audits with clean results.
- Developed and maintained the enterprise-wide risk register, influencing risk mitigation strategies.
- Collaborated closely with security operations teams on control implementation and incident reporting.
- Demonstrated a strong understanding of the technical aspects of cyber risk and defence.