The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of Offensive Security / Head of Red Team
5-8 years at this level before COSOSkills to master
- Leading large, complex red team operations, building and managing a diverse offensive security team, developing strategic threat emulation programmes, and presenting technical risks to executive audiences.
You're ready to move on when
- Successfully built and scaled an offensive security function within a large enterprise.
- Consistently delivered high-impact findings that led to significant risk reduction.
- Proven ability to manage multi-million-pound budgets and influence senior stakeholders.
- Demonstrated leadership in crisis situations, particularly during incident response.
- 2
Chief Information Security Officer (CISO) - Mid-sized Enterprise
3-6 years at this level before COSO (larger enterprise)Skills to master
- End-to-end ownership of an entire security programme (offensive and defensive), managing all aspects of cyber risk, regulatory compliance, and security operations. Board engagement and executive leadership.
You're ready to move on when
- Successfully built and matured an entire security programme in a complex environment.
- Navigated significant regulatory audits without major findings.
- Proven ability to recruit, retain, and develop a comprehensive security team.
- Strong track record of positive engagement with the Board and external regulators.
- 3
VP, Security Architecture / Head of Security Engineering
6-10 years at this level before COSOSkills to master
- Designing and implementing secure enterprise architectures, driving secure development lifecycles, evaluating and integrating advanced security technologies, and building strong relationships with engineering and product teams.
You're ready to move on when
- Architected and secured major enterprise platforms (e.g., cloud migrations, new product launches).
- Led a significant transformation in the organisation's security engineering practices.
- Demonstrated ability to balance security requirements with business innovation and speed.
- Strong understanding of offensive security principles from a defensive perspective.