The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Security Analyst (L1)
2-3 yearsSkills to master
- Mastering alert triage, basic incident response, vulnerability scanning, and security tool operation. Essentially, becoming really good at the fundamentals.
You're ready to move on when
- Consistently closing assigned security tickets within SLA.
- Accurately identifying and escalating genuine threats.
- Demonstrating a proactive approach to learning new security concepts.
- Reliably following established security procedures and playbooks.
- 2
IT Support Engineer / Network Engineer
3-4 years (with a pivot to security)Skills to master
- Deepening knowledge of network security, operating system hardening, and then gaining specific experience with security tools and incident response. It's about shifting from 'keeping systems running' to 'keeping systems secure'.
You're ready to move on when
- Taking on security-related projects within your IT role.
- Pursuing security certifications (e.g., CompTIA Security+).
- Demonstrating a keen interest in threat intelligence and attack vectors.
- Proactively identifying security gaps in existing IT infrastructure.
- 3
DevOps Engineer (with security focus)
2-4 years (with a pivot to security)Skills to master
- Understanding secure coding practices, cloud security configurations, and integrating security into CI/CD pipelines. This path often brings a strong automation and cloud-native perspective.
You're ready to move on when
- Championing security best practices within development teams.
- Implementing security scanning tools in CI/CD pipelines.
- Demonstrating expertise in cloud security services and configurations.
- Actively participating in threat modelling for new applications.