The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Administrator / Engineer
3-5 years in a senior roleSkills to master
- Deep technical expertise in ACS/VMS configuration and troubleshooting, leading small projects, initial exposure to system design, and informal mentorship.
You're ready to move on when
- You're the person everyone goes to for complex technical problems.
- You've successfully led several small to medium-sized security system projects.
- You've started thinking about 'why' systems are designed a certain way, not just 'how' to implement them.
- You've informally guided junior colleagues and enjoy helping them learn.
- 2
IT Security Engineer (with physical security exposure)
4-6 years in IT securitySkills to master
- Strong network security, SIEM/log management, identity and access management (IAM), and a keen interest in applying these to physical and OT environments.
You're ready to move on when
- You're an expert in network segmentation and hardening.
- You've worked extensively with SIEMs to detect and respond to cyber threats.
- You're fascinated by the convergence of IT and OT security.
- You're eager to apply your cyber security knowledge to the physical world.
- 3
Security Integrator / Consultant (Technical Lead)
5-8 years in an integrator roleSkills to master
- Extensive hands-on experience across multiple security platforms, project management, client-facing technical design, and managing installation teams.
You're ready to move on when
- You've designed and delivered complex security solutions for multiple clients.
- You're adept at managing technical teams and subcontractors.
- You understand the full lifecycle of security system deployment.
- You're looking to move from project-based work to owning the security posture for a single organisation.