The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Security Operations Manager (L5) to Director
3-5 years as a ManagerSkills to master
- Moving from managing a SOC to defining its strategic direction, managing a larger budget, and presenting to executive leadership. You'll need to develop your executive communication and strategic planning skills.
You're ready to move on when
- Successfully managed a global SOC for several years, consistently hitting operational KPIs.
- Led multiple major incident responses, demonstrating calm and decisive leadership.
- Developed and mentored a strong team of security professionals, with clear succession planning.
- Presented operational reports and strategic recommendations to senior management (e.g., CISO, CIO).
- 2
Lead Incident Responder / Head of Incident Response to Director
4-6 years in a lead IR roleSkills to master
- Broadening your scope beyond just incident response to encompass proactive security operations (threat hunting, detection engineering), budget management, and strategic programme ownership. You'll need to build out your team management and financial acumen.
You're ready to move on when
- Led the response to multiple complex, high-profile cyber incidents.
- Built and refined incident response playbooks and processes.
- Demonstrated strong technical depth in forensics and threat analysis.
- Effectively communicated incident details and impact to executive stakeholders.
- 3
Consulting Director (Cyber Security) to Director
Varies, typically 2-3 years at Director level in consultingSkills to master
- Transitioning from advising clients to directly owning and operating a security function. This means moving from recommendations to accountability for real-world outcomes, including managing internal politics and legacy systems. You'll need to adapt to an 'owner' mindset.
You're ready to move on when
- Successfully advised multiple clients on security operations strategy and implementation.
- Managed large-scale security transformation projects for clients.
- Proven ability to build relationships and influence at the executive level.
- Comfortable with the idea of long-term ownership and accountability for a security programme.