The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director/VP of Offensive Security
3-5 years at this levelSkills to master
- Enterprise-level programme management, strategic budget allocation for offensive security, executive reporting on adversary risk, building and scaling high-performing red teams.
You're ready to move on when
- Successfully built and led a multi-disciplinary offensive security programme that significantly reduced enterprise risk.
- Consistently provided actionable threat intelligence and risk insights that influenced C-suite decisions.
- Demonstrated strong leadership in crisis situations and effective communication with executive stakeholders.
- 2
Head of Governance, Risk & Compliance (GRC)
3-5 years at this levelSkills to master
- Deep expertise in regulatory frameworks (GDPR, DORA, NIS2), enterprise risk management methodologies, audit management, policy development and enforcement, board-level reporting on compliance.
You're ready to move on when
- Successfully navigated complex regulatory audits and ensured enterprise-wide compliance.
- Developed and implemented robust GRC frameworks that integrated security into business operations.
- Demonstrated strong ability to translate technical risks into business language for executive decision-making.
- 3
Chief Technology Officer (CTO) / Chief Digital Officer (CDO) (with strong security background)
5-7 years at this levelSkills to master
- Overall technology strategy, product development leadership, digital transformation, innovation management, large-scale engineering team leadership, P&L responsibility for technology functions.
You're ready to move on when
- Successfully led significant technology transformations while maintaining strong security posture.
- Demonstrated ability to balance innovation with risk management across a broad technology portfolio.
- Proven track record of building and leading large, diverse technology organisations.