The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Principal DevSecOps Engineer
3-5 years as a PrincipalSkills to master
- As a Principal, you'd have been the go-to technical expert, influencing strategy without direct reports. To step up to Director, you need to master organisational leadership, budget management, executive communication, and building a team through others.
You're ready to move on when
- Successfully led multiple complex, cross-functional security initiatives to completion.
- Consistently provided strategic technical direction that was adopted across multiple engineering teams.
- Mentored and coached senior engineers, demonstrating a knack for talent development.
- Presented technical strategies and risks effectively to senior management (e.g., VPs, CISO).
- 2
Lead Security Architect (from a large enterprise)
4-6 years as a Lead ArchitectSkills to master
- Here, you've already got the architectural chops. The jump to Director means adding significant people management, P&L responsibility, and a much stronger focus on organisational change management and board-level influence.
You're ready to move on when
- Designed and oversaw the implementation of major security architectures across multiple business units.
- Developed and maintained enterprise-wide security standards and patterns.
- Successfully influenced engineering leaders to adopt secure architectural practices.
- Demonstrated ability to manage complex projects and stakeholder expectations.
- 3
Senior Security Manager (leading a large team)
3-5 years as a Senior ManagerSkills to master
- You've got the people management down. Now, it's about expanding your scope from managing a team to leading a full function, owning the strategic roadmap, and operating at a much higher level of executive and board engagement. Think broader impact, deeper strategy.
You're ready to move on when
- Managed a team of 15+ security engineers or analysts, with strong performance outcomes.
- Successfully delivered significant security programmes within budget and on time.
- Demonstrated strong stakeholder management and conflict resolution skills.
- Developed and mentored team members, with clear examples of career progression for your reports.