The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate Security Analyst (L1)
2-3 yearsSkills to master
- Foundational security concepts, basic SIEM monitoring, vulnerability scanning, following incident response playbooks, basic scripting (e.g., Python for automation).
You're ready to move on when
- Consistently handles routine alerts without supervision.
- Proactively identifies and escalates potential issues.
- Demonstrates a strong desire to learn and take on more responsibility.
- Can clearly document findings and communicate technical issues.
- 2
IT Support / Network Administrator with Security Focus
3-4 yearsSkills to master
- Deep understanding of network infrastructure, operating system hardening, troubleshooting connectivity and access issues, awareness of common IT security threats.
You're ready to move on when
- Has taken on security-related projects in their previous role.
- Holds relevant security certifications (e.g., CompTIA Security+).
- Can demonstrate practical experience with security tools or concepts, even if not in a dedicated security role.
- Understands the impact of IT decisions on the overall security posture.
- 3
Junior Developer with a Security Interest
3-5 yearsSkills to master
- Secure coding practices, understanding of application security vulnerabilities (OWASP Top 10), experience with SAST/DAST tools, familiarity with CI/CD security integration.
You're ready to move on when
- Has actively championed security within their development team.
- Contributed to security reviews or threat modelling for applications.
- Understands how code vulnerabilities translate into business risk.
- Shows a strong interest in shifting from building features to defending them.