The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
SOC Analyst (Tier 1)
1-2 yearsSkills to master
- Mastering alert triage, understanding common attack patterns, basic SIEM querying, and meticulous documentation. Essentially, getting really good at the fundamentals of security monitoring.
You're ready to move on when
- Consistently closing Tier 1 alerts with high accuracy and speed.
- Proactively identifying false positives and suggesting improvements to detection rules.
- Demonstrating a strong desire to understand the 'why' behind alerts, not just closing them.
- Taking initiative to learn new security tools and concepts beyond daily tasks.
- 2
IT Support / Systems Administrator with Security Focus
2-3 yearsSkills to master
- A deep understanding of operating systems (Windows/Linux), networking, and common enterprise applications. You'll need to layer security principles onto this technical foundation, learning about vulnerabilities and defence mechanisms.
You're ready to move on when
- Actively participating in security projects or initiatives within your IT role.
- Demonstrating a strong understanding of system hardening and vulnerability management.
- Successfully troubleshooting and resolving security-related issues (e.g., malware removal, access control problems).
- Seeking out opportunities to learn about security tools and incident response processes.
- 3
Junior Security Engineer
1-2 yearsSkills to master
- Building and maintaining security tools, automating security tasks, and understanding security architecture. This path gives you a good grasp of the technical underpinnings of security systems.
You're ready to move on when
- Successfully deploying and configuring security tools (e.g., firewalls, EDR agents).
- Writing scripts to automate security tasks or improve operational efficiency.
- Contributing to the design or implementation of security controls.
- Proactively identifying security gaps in systems you manage.