The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Analyst / Staff Security Engineer (IR) at a large enterprise
Moving from this role to Director typically takes an additional 5-8 years, focusing on programme management and team leadership.Skills to master
- Strategic programme management, budget oversight, executive communication, team leadership (managing managers), vendor relationship management, and organisational design.
You're ready to move on when
- Successfully led multiple major incident response programmes end-to-end.
- Managed a significant portion of a security budget (e.g., £500K+).
- Regularly presented to and influenced senior leadership (VP level and above).
- Built and mentored a high-performing team of 10+ engineers/analysts.
- 2
Cybersecurity Operations Manager / Principal Engineer at a large enterprise
Transitioning from this role to Director usually takes 3-5 years, with a focus on expanding scope and strategic influence.Skills to master
- Enterprise-wide security strategy development, board-level reporting, M&A security integration, cross-functional executive alignment, and large-scale organisational transformation.
You're ready to move on when
- Owned the P&L for a significant security function (e.g., £1M+).
- Managed a team of 15+ individuals, including other managers.
- Successfully driven major security initiatives that impacted the entire organisation.
- Consistently received positive feedback from executive peers and direct reports on leadership and strategic impact.
- 3
Head of Security for a smaller company or a specific business unit
This path can be quicker, perhaps 2-4 years, if the scope of the smaller company or business unit provided broad strategic and operational experience.Skills to master
- Full CISO-like responsibilities (risk, compliance, governance, operations) within a smaller context, building security programmes from the ground up, and direct board interaction.
You're ready to move on when
- Successfully built and scaled a security function from scratch or significantly matured an existing one.
- Directly reported to a CEO or Board on security matters.
- Managed all aspects of security (not just operations) for a company of 100-500 employees.
- Demonstrated strong business acumen alongside deep security expertise.