The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From SOC Manager / Head of Incident Response (L5)
3-5 years as a high-performing SOC Manager or Head of IR, managing large teams and significant programmes.Skills to master
- Strategic budget management, executive communication, cross-functional programme leadership, talent development across multiple teams, and a deep understanding of organisational risk.
You're ready to move on when
- Successfully led the response to multiple high-severity incidents with positive outcomes.
- Demonstrated ability to build and retain a high-performing team of managers and individual contributors.
- Consistently met or exceeded key SOC/IR performance metrics (MTTD/MTTR, false positive rates) at scale.
- Presented strategic recommendations and updates to senior leadership (e.g., CISO, CTO) with positive feedback.
- 2
From Senior Security Architect / Principal Security Engineer (L5)
5-7 years as a Principal-level architect, with significant experience designing and implementing enterprise-wide security solutions, coupled with some leadership experience.Skills to master
- People management (managing managers), budget ownership, incident response programme management, and the ability to translate technical architecture into operational strategy.
You're ready to move on when
- Designed and overseen the successful deployment of major security platforms (e.g., SIEM, XDR) across the enterprise.
- Developed and implemented security strategies that significantly reduced architectural risk.
- Demonstrated strong influencing skills with technical and non-technical stakeholders.
- Taken on informal leadership roles, mentoring senior engineers and leading complex projects.
- 3
From Cyber Security Consultant (Senior Manager/Director level)
5-7 years at a senior level within a reputable cyber security consultancy, leading large client engagements focused on security operations maturity, incident response, or cyber defence strategy.Skills to master
- Translating consulting recommendations into practical, in-house operational execution
- building and leading internal teams
- navigating internal organisational dynamics
- long-term budget ownership.
You're ready to move on when
- Successfully delivered multiple complex cyber security strategy and operations projects for diverse clients.
- Managed significant client relationships and project budgets.
- Proven ability to build strong relationships and influence senior client stakeholders.
- Demonstrated experience in pre-sales, solution design, and team leadership within a consulting environment.