The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Principal Security Architect / Lead Security Engineer
You'd usually spend 3-5 years in a Principal or Lead role, mastering a specific security domain and demonstrating the ability to influence technical strategy across the organisation.Skills to master
- Deep technical expertise in a core security domain (e.g., cloud security, application security), the ability to design and implement complex security solutions, and informal leadership/mentoring skills.
You're ready to move on when
- Successfully led the design and implementation of a major security initiative (e.g., Zero Trust rollout).
- Consistently provided technical guidance and mentorship to senior engineers and architects.
- Presented technical strategies and roadmaps to senior leadership (VP-level).
- Demonstrated an understanding of business risk beyond just technical vulnerabilities.
- 2
Information Security Manager / Head of Security Operations
This path typically involves 4-6 years managing a significant security function, like SecOps, GRC, or AppSec, with a team of 10-20+ people.Skills to master
- Team leadership, budget management for a specific function, programme management, incident response management, and reporting on functional performance to senior leadership.
You're ready to move on when
- Built and managed a high-performing security team, meeting all operational KPIs.
- Successfully managed a functional security budget and demonstrated ROI for investments.
- Led the response to multiple significant security incidents, coordinating cross-functional teams.
- Consistently delivered clear, concise reports on security posture to senior management.
- 3
CISO for a Smaller Organisation
Spending 3-5 years as the top security executive in a smaller company (e.g., a start-up or SME) where you owned the entire security programme.Skills to master
- Full ownership of security strategy, P&L management, direct board interaction, regulatory compliance across all domains, and building a security programme from the ground up.
You're ready to move on when
- Successfully built and matured a security programme from scratch or significantly improved an existing one.
- Directly reported to a CEO/Board on security matters and managed external audits.
- Managed a comprehensive security budget and vendor relationships.
- Demonstrated the ability to balance security needs with the agile demands of a smaller business.