The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Network Security Analyst (Internal Promotion)
3-5 years as an L3/L4Skills to master
- Leading complex incidents, mentoring junior analysts, developing new detection content, owning significant workstreams, and demonstrating strategic thinking beyond day-to-day operations.
You're ready to move on when
- Successfully led multiple major network security incidents from start to finish.
- Consistently delivered high-quality security designs and implemented robust controls.
- Mentored at least 2-3 junior analysts who have shown significant growth.
- Proactively identified and mitigated significant network risks without direct instruction.
- Demonstrated strong communication skills with both technical and non-technical stakeholders.
- 2
Lead Security Engineer (from another company)
Direct entry with 10-15 years experienceSkills to master
- Deep technical expertise in network security architecture and engineering, experience managing major security systems, and a track record of influencing security strategy.
You're ready to move on when
- Experience architecting and implementing network security solutions for large enterprises.
- Managed the lifecycle of at least one major security platform (e.g., SIEM, EDR) in a previous role.
- Proven ability to lead technical projects and drive security initiatives.
- Strong understanding of modern network attack vectors and defence strategies.
- Demonstrated leadership potential and ability to manage technical teams.
- 3
Security Operations Centre (SOC) Manager (from another company)
Direct entry with 10-15 years experienceSkills to master
- Experience managing a SOC team, developing incident response processes, and reporting on security posture to senior leadership.
You're ready to move on when
- Managed a team of security analysts or engineers for 3+ years.
- Developed and optimised SOC processes and playbooks.
- Strong experience with SIEM platforms and incident management.
- Demonstrated ability to handle high-pressure security incidents and communicate effectively during crises.
- A clear passion for network security and a desire to specialise in this domain.