The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Global IT Security Manager
3-5 years as a Global IT Security Manager (L5)Skills to master
- Deepen strategic planning and programme management, expand influence beyond your direct team to cross-functional executive peers, take on more significant budget responsibilities, and gain experience presenting to board-level committees.
You're ready to move on when
- Successfully led a major security transformation programme from inception to completion.
- Consistently delivered on multi-million-pound budget targets and demonstrated clear ROI for security investments.
- Proven ability to mentor and develop a team of managers, not just individual contributors.
- Received positive feedback from C-suite executives on your strategic input and communication.
- 2
From Lead Security Architect / Principal Security Engineer
4-6 years as a Lead Security Architect (L4) or Principal Security Engineer (L5 equivalent)Skills to master
- Shift from designing technical solutions to defining the overarching security strategy, develop strong people management and leadership skills (especially managing managers), and gain significant experience in financial management and executive communication.
You're ready to move on when
- Architected and overseen the implementation of multiple enterprise-wide security solutions.
- Acted as a trusted technical advisor to the CISO and other executive leaders.
- Demonstrated ability to influence technical and non-technical stakeholders at all levels.
- Taken on informal leadership roles, mentoring senior engineers and leading cross-functional initiatives.
- 3
From Head of Security Operations / GRC
3-5 years in a Head of Operations or GRC role (L5 equivalent)Skills to master
- Broaden your scope beyond a single security domain to encompass the entire security programme, develop a more holistic understanding of enterprise risk, and gain experience in strategic planning and board-level reporting.
You're ready to move on when
- Successfully managed and matured a large security operations or GRC function.
- Led the organisation through multiple major incidents or successful external audits.
- Proven ability to build and lead high-performing teams within your domain.
- Demonstrated strong communication skills in presenting operational insights and compliance status to senior leadership.