The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Network Security Engineer / Senior Security Architect (Internal)
3-5 years in previous roleSkills to master
- Deep technical expertise in specific security domains, leading complex projects, mentoring junior team members, and starting to influence architectural decisions beyond your immediate scope.
You're ready to move on when
- Successfully led multiple high-impact security architecture projects.
- Consistently sought out for technical guidance and problem-solving.
- Demonstrated ability to translate business requirements into secure technical designs.
- Proactively identified and mitigated significant architectural risks.
- 2
Security Consultant (External)
5-7 years as a senior consultantSkills to master
- Broad exposure to diverse security environments, strong client-facing communication, ability to quickly assess and design security solutions for various organisations, and experience in strategic security advisory.
You're ready to move on when
- Successfully delivered strategic security architecture engagements for multiple clients.
- Proven ability to influence senior client stakeholders on security strategy.
- Deep understanding of various industry security standards and best practices.
- Comfortable operating in ambiguous and rapidly changing environments.
- 3
Head of Security for a smaller organisation (External)
2-4 years in a leadership roleSkills to master
- End-to-end ownership of security programmes, budget management, team leadership, and direct reporting to executive leadership. This path brings a holistic view of security challenges.
You're ready to move on when
- Successfully built and managed a security programme from the ground up.
- Direct experience with security budget ownership and resource allocation.
- Proven ability to recruit, retain, and develop security talent.
- Comfortable presenting security posture and risks to a board or executive team.