The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Principal Regulatory Engineer
3-5 years as a PrincipalSkills to master
- Moving from setting technical strategy for a domain to owning the entire programme, managing multiple teams, and engaging with C-suite stakeholders. This means developing strong organisational leadership and executive communication.
You're ready to move on when
- Successfully led multiple large-scale, cross-domain compliance initiatives.
- Demonstrated ability to influence senior leadership and drive architectural consensus.
- Proven track record of mentoring and developing other senior engineers and leads.
- Managed significant budgets and resources for technical projects.
- 2
From Head of Security Architecture
4-6 years as Head of ArchitectureSkills to master
- Transitioning from designing secure systems to specifically focusing on regulatory adherence and audit defence. This requires deep immersion in compliance frameworks and a strong understanding of legal and risk perspectives.
You're ready to move on when
- Owned the security architecture for a major business unit or enterprise.
- Deep understanding of how architectural decisions impact compliance.
- Experience presenting complex technical designs and risks to executive committees.
- A strong interest and foundational knowledge in regulatory frameworks.
- 3
From Director of Information Security Operations
5-7 years as Director of SecOpsSkills to master
- Shifting from incident response and operational security to proactive compliance programme management and strategic risk mitigation. This means developing a more long-term, preventative mindset and strong regulatory interpretation skills.
You're ready to move on when
- Managed a large SecOps function, including incident response and vulnerability management.
- Strong understanding of security controls and their operational effectiveness.
- Experience managing operational budgets and leading large teams.
- A clear grasp of how operational security feeds into compliance reporting and audit requirements.