The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Manager, Vulnerability Management (L5)
3-5 years as an L5 ManagerSkills to master
- Mastering team leadership, operational delivery, budget management for a specific VM segment, and effective stakeholder communication. You need to prove you can run a significant part of the programme.
You're ready to move on when
- Consistently exceeding team KPIs and SLAs.
- Successful development and promotion of team members.
- Demonstrated ability to manage a complex budget within target.
- Positive feedback from peer managers and senior leadership on collaboration and influence.
- 2
Lead / Staff Security Architect (with VM focus)
5-8 years as an L4 Lead/Staff ArchitectSkills to master
- Deep expertise in security architecture, particularly around vulnerability prevention and detection. Proven ability to design and implement enterprise-scale security solutions, combined with strong leadership and influence skills.
You're ready to move on when
- Successful design and deployment of major security architectural components.
- Recognition as a subject matter expert across the organisation.
- Mentorship of other architects and engineers.
- Demonstrated ability to influence strategic technical decisions.
- 3
Senior Manager, Security Operations (from another domain)
4-6 years as a Senior Manager in a related security domain (e.g., Incident Response, Security Engineering)Skills to master
- Strong leadership across security operations, deep understanding of the incident lifecycle, and a proven ability to manage complex security functions. You'd need to quickly ramp up on the specifics of vulnerability management.
You're ready to move on when
- Successful leadership of a large security operations function.
- Strong track record in incident response and crisis management.
- Demonstrated ability to learn and adapt to new security domains quickly.
- Excellent cross-functional leadership and stakeholder management skills.