The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Manager, Security Compliance (L5)
3-5 years at L5Skills to master
- Mastering team leadership, budget management for a specific compliance domain, managing multiple audit cycles end-to-end, and effectively influencing senior technical leads.
You're ready to move on when
- Successfully built and led a high-performing team of 5-10 compliance professionals.
- Consistently delivered 'clean' audit reports for major frameworks (e.g., SOC 2, ISO 27001).
- Demonstrated ability to manage a significant compliance budget (£500K-£2M).
- Proven track record of influencing cross-functional VPs and Directors on security control implementation.
- 2
Principal GRC Architect (L5)
3-5 years at L5Skills to master
- Architecting enterprise-wide GRC solutions, designing complex automated compliance controls, translating new regulations into technical requirements, and providing expert technical guidance to multiple compliance teams.
You're ready to move on when
- Designed and implemented a major GRC platform integration or automation project.
- Successfully translated a complex new regulation into a comprehensive set of technical controls.
- Recognised as the go-to technical expert for GRC strategy and architecture across the organisation.
- Mentored multiple Lead Compliance Engineers and significantly contributed to their technical growth.