The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Engineer / Architect
5-8 years of experienceSkills to master
- Deep technical expertise in a specific security domain (e.g., cloud, application, network security), leading project implementations, strong problem-solving, and initial exposure to mentoring.
You're ready to move on when
- Consistently delivering complex security projects on time and to a high standard.
- Being the 'go-to' person for technical challenges in your specialisation.
- Proactively identifying and proposing solutions to architectural security flaws.
- Providing informal guidance and support to junior team members.
- 2
Security Consultant (External)
6-10 years of experienceSkills to master
- Broad exposure to different security challenges across various industries, strong client communication, risk assessment, and solution design. You'll have seen a lot of different environments.
You're ready to move on when
- Successfully delivering security assessments and architectural designs for multiple clients.
- Developing strong client relationships and influencing their security strategies.
- Ability to quickly understand new technical environments and identify critical risks.
- Comfortable presenting complex findings to diverse audiences.
- 3
Lead Incident Responder / Threat Hunter
7-10 years of experienceSkills to master
- Expertise in incident response methodologies, digital forensics, threat intelligence analysis, and proactive threat hunting techniques. You'll be a seasoned veteran of the front lines.
You're ready to move on when
- Leading major incident response efforts from start to finish.
- Developing and tuning advanced detection rules and playbooks.
- Consistently uncovering hidden threats through proactive hunting.
- Mentoring junior analysts during incident investigations.