The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Principal Security Architect / VM Programme Manager
3-5 years in a Principal/Manager roleSkills to master
- Deepen your understanding of enterprise architecture, master large-scale programme management, refine executive communication, and gain significant experience in budget management and team leadership.
You're ready to move on when
- Successfully owned and delivered a major enterprise-wide security programme.
- Consistently presented to senior leadership and influenced strategic decisions.
- Built and mentored a high-performing team of security professionals (even if not direct reports).
- Managed budgets exceeding £500K and demonstrated strong financial acumen.
- 2
Director of Security Operations / Head of Cyber Defence
4-6 years in a similar Director-level role in Security OperationsSkills to master
- Expand your scope beyond vulnerability management to include incident response, security monitoring, and threat hunting. Develop a holistic view of cyber defence and learn to integrate these functions seamlessly.
You're ready to move on when
- Successfully led a large security operations centre (SOC) or similar defence function.
- Demonstrated ability to respond to and manage major cyber incidents effectively.
- Proven experience in integrating various security functions into a cohesive defence strategy.
- Strong track record of managing and developing diverse security teams.