The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Incident Response Manager (L5)
3-5 years as a ManagerSkills to master
- Expanding scope from managing a team to owning a full function, strategic budget management (multi-million £), executive communication, and cross-functional influence across an entire enterprise.
You're ready to move on when
- Successfully owned a large incident response programme end-to-end.
- Consistently delivered on programme-level KPIs (e.g., MTTR reduction, dwell time reduction).
- Demonstrated ability to build and retain a high-performing team.
- Regularly presented to senior leadership and influenced strategic decisions.
- 2
From Head of SOC / Threat Hunting (L5)
3-5 years in a similar leadership roleSkills to master
- Integrating SOC/Threat Hunting with broader IR and vulnerability management, strategic vendor management, and leading a diverse set of security disciplines.
You're ready to move on when
- Successfully built or significantly matured a SOC/Threat Hunting capability.
- Implemented new detection methodologies that reduced risk.
- Managed a substantial budget and team within their domain.
- Proven ability to translate technical findings into business risk for executives.
- 3
From Senior Security Architect / Engineer (L5)
5-7 years in a Principal/Lead architecture roleSkills to master
- Transitioning from deep technical design to operational leadership, people management at scale, and strategic programme ownership. This path requires a strong desire to lead and manage.
You're ready to move on when
- Designed and implemented complex enterprise security solutions.
- Acted as a technical mentor and informal leader for large teams.
- Demonstrated understanding of operational challenges and incident response.
- Expressed a clear desire and aptitude for leadership and strategic management.