The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Junior Penetration Tester / Security Analyst
2-3 yearsSkills to master
- Web application security, network penetration testing, basic scripting (Python), vulnerability reporting. You'd need to pick up a strong interest in hardware and embedded systems.
You're ready to move on when
- Consistently delivering high-quality penetration test reports.
- Demonstrating a curiosity for how things work 'under the hood' of devices.
- Successfully completing personal projects involving hardware or firmware analysis.
- 2
Embedded Software Engineer / Firmware Developer
3-4 yearsSkills to master
- C/C++ programming for microcontrollers, RTOS development, debugging embedded systems. You'd need to develop a 'hacker's mindset' and learn offensive security techniques.
You're ready to move on when
- Deep understanding of embedded system architecture and common vulnerabilities.
- Proactively identifying security flaws in your own code or during code reviews.
- Experimenting with reverse engineering tools on personal devices.
- 3
Security Consultant (with IoT exposure)
2-4 yearsSkills to master
- Client engagement, project management, broad security domain knowledge, some exposure to IoT security assessments. You'd need to deepen your hands-on technical skills in specific IoT areas.
You're ready to move on when
- Successfully managing and delivering security projects for clients.
- Demonstrating strong technical aptitude across various security domains.
- Expressing a desire to specialise and get more 'hands-on' with hardware/firmware.