The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of Information Security (Large Enterprise)
3-5 years at Director levelSkills to master
- Mastering multi-million-pound budget management, leading large functional security teams (e.g., SecOps, GRC), and regularly presenting to senior leadership. You'd be owning a significant chunk of the enterprise security programme.
You're ready to move on when
- Successfully built and scaled a security function within a large organisation.
- Proven ability to influence executive stakeholders and drive security initiatives without direct authority.
- Managed a significant security budget (e.g., £5M+) and demonstrated ROI.
- Led a major incident response from start to finish.
- 2
VP of Security (Mid-Size to Large Enterprise)
2-4 years at VP levelSkills to master
- Developing and executing multi-year security strategies, managing a portfolio of security programmes, and building strong relationships with C-suite peers. You'd be operating at a strategic level, probably second-in-command to a CISO.
You're ready to move on when
- Owned the end-to-end security strategy for a major business unit or a mid-sized company.
- Directly managed other security managers or directors.
- Regularly engaged with the executive team and potentially the Board.
- Demonstrated ability to drive cultural change around security.
- 3
Chief Security Architect (Very Large Enterprise)
5-7 years as Chief Security ArchitectSkills to master
- While more technical, this path requires deep expertise in designing enterprise-wide security solutions, influencing engineering leadership, and translating complex architectural risks into business terms. It's about having a profound understanding of how security is built into everything.
You're ready to move on when
- Architected security for complex, multi-cloud enterprise systems.
- Led the security architecture review board and set technical security standards.
- Proven ability to influence engineering and product roadmaps for security.
- Strong understanding of business implications of architectural decisions.