The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Regional Security Manager (Large Region)
3-5 years at L5Skills to master
- Mastering full ownership of a major regional security programme, including budget management, team leadership, and complex incident response across multiple facilities. You'll need to demonstrate consistent success in reducing regional risks and implementing strategic initiatives.
You're ready to move on when
- Successfully managed a security budget of £500K-£2M.
- Led a team of 10-25 security professionals (including managers).
- Developed and implemented a regional security strategy that demonstrably reduced risk.
- Consistently received high ratings for stakeholder satisfaction from regional business leaders.
- 2
Principal Security Strategist (Global Function)
4-6 years at L5Skills to master
- Deep specialisation in a global security function (e.g., global threat intelligence, executive protection, security technology architecture), with a proven ability to influence strategy across the enterprise. You'll need to show you can translate your specialised knowledge into broader organisational impact.
You're ready to move on when
- Designed and implemented a global security programme for a specific function (e.g., global travel security).
- Influenced C-suite decisions based on your specialised expertise.
- Developed and mentored junior strategists or analysts.
- Recognised as an internal expert and thought leader in your specific security domain.
- 3
Head of Corporate Security (Mid-Size Organisation)
5-8 years in a similar roleSkills to master
- Broad experience owning the entire security function for a smaller, but still complex, organisation. This gives you the end-to-end P&L and strategic experience needed, even if on a smaller scale. You'll need to show you can scale up your strategic thinking and team leadership to a larger, more distributed enterprise.
You're ready to move on when
- Owned the full corporate security budget and strategy for a company with 1,000+ employees.
- Managed both physical and potentially some cyber security aspects.
- Successfully navigated board-level reporting and executive stakeholder management.
- Demonstrated ability to build and mature a security programme from the ground up.