The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior Security Compliance Manager
3-5 years as a Senior ManagerSkills to master
- Mastering programme management for multiple compliance frameworks, leading a team of managers, developing strong executive communication skills, and owning significant budget responsibility.
You're ready to move on when
- Successfully led 2-3 major enterprise-wide compliance programmes (e.g., a new ISO 27001 certification, a GDPR overhaul).
- Consistently received strong feedback on executive presentations and stakeholder influence.
- Demonstrated ability to manage and develop a team of 10+ professionals, including other managers.
- Proven track record of managing budgets over £1M and making strategic investment recommendations.
- 2
From Head of GRC (in a smaller/mid-sized company)
4-6 years as Head of GRCSkills to master
- Scaling compliance programmes for a larger, more complex organisation, navigating increased regulatory scrutiny, managing larger teams and budgets, and operating at a more strategic, board-level engagement.
You're ready to move on when
- Successfully built and led a GRC function from scratch or significantly scaled an existing one.
- Managed all aspects of compliance for a company undergoing rapid growth or significant regulatory change.
- Experience presenting to a Board or Executive Committee on security and compliance matters.
- Demonstrated ability to attract, hire, and retain top talent in the GRC space.