The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Security Engineering Manager / Principal Security Engineer
5-8 years in a management or principal-level roleSkills to master
- Moving from managing a team or specific domain to owning a broader business unit's security. This means developing stronger executive communication, budget management, and organisational design skills. You'll need to think more about business outcomes than pure technical excellence.
You're ready to move on when
- Successfully led a major security programme from end-to-end, with measurable business impact.
- Consistently delivered on budget and resource allocation for your functional area.
- Mentored and developed multiple senior engineers or junior managers.
- Regularly presented to and influenced senior (non-security) leadership on technical risk.
- 2
From another Director-level role (e.g., Director of IT Operations, Director of Infrastructure)
3-5 years in a related Director roleSkills to master
- While you'd have strong leadership and operational skills, you'd need to deepen your specific security expertise across all domains (network, cloud, data, identity) and develop a strategic understanding of the threat landscape. You'd also need to get up to speed on security governance and compliance frameworks.
You're ready to move on when
- Managed a large technical department with significant budget and P&L responsibility.
- Proven ability to build and lead high-performing technical teams.
- Demonstrated strategic planning and execution capabilities.
- A strong personal interest and foundational knowledge in information security principles.