The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Head of Security Operations (SOC)
3-5 years at that levelSkills to master
- Scaling SOC teams, managing 24/7 operations, optimising detection engineering, incident management at scale, vendor management for SOC tools.
You're ready to move on when
- Successfully managed a global SOC team of 20+ analysts and engineers.
- Demonstrated significant improvements in MTTR and Dwell Time for a large organisation.
- Presented SOC performance metrics and strategic initiatives to senior leadership.
- Led the implementation and optimisation of major SIEM/XDR platforms.
- 2
Senior Manager, Incident Response
4-6 years at that levelSkills to master
- Leading complex, high-severity incident responses, post-incident analysis and reporting, building and maturing IR playbooks, engaging with legal and PR during crises, training and exercising IR teams.
You're ready to move on when
- Led the response to multiple P0/P1 cyber incidents with successful outcomes.
- Developed and implemented enterprise-wide incident response plans and playbooks.
- Effectively managed communications with executive leadership and external parties during crises.
- Built and mentored a dedicated incident response team.
- 3
Lead Security Architect / Principal Security Engineer (with management experience)
5-7 years at that levelSkills to master
- Designing secure architectures, evaluating new security technologies, integrating security into DevOps, deep technical expertise across multiple security domains, influencing technical direction.
You're ready to move on when
- Architected security solutions for complex enterprise environments (cloud, on-premise).
- Evaluated and recommended major security technology investments (e.g., new SIEM, XDR).
- Provided technical leadership and mentorship to security engineering teams.
- Demonstrated strong understanding of threat modelling and security by design principles.