The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate Security Analyst (L1)
1-2 yearsSkills to master
- Mastering alert triage, basic incident handling procedures, understanding security tools, and clear documentation. Basically, getting really good at following the runbooks.
You're ready to move on when
- Consistently resolving routine alerts without supervision.
- Proactively identifying areas for improvement in existing playbooks.
- Demonstrating a strong grasp of foundational security concepts.
- 2
IT Support / Network Engineer with Security Focus
2-3 yearsSkills to master
- Transitioning from general IT troubleshooting to security-specific problem-solving. This means understanding attack vectors, security controls, and incident response. You'd already know our infrastructure well.
You're ready to move on when
- Successfully completed a security-focused certification (e.g., CompTIA Security+).
- Demonstrated a keen interest in security, perhaps by identifying and escalating security issues in your previous role.
- Strong understanding of network architecture and operating systems.
- 3
Junior Penetration Tester / Ethical Hacker
1-2 yearsSkills to master
- Shifting from offensive security to defensive. This involves understanding how to detect and respond to the attacks you previously simulated. Your attacker mindset is a huge asset here.
You're ready to move on when
- Deep understanding of attacker methodologies and tools.
- Ability to translate offensive knowledge into defensive strategies.
- Strong analytical and problem-solving skills.