The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Junior Security Analyst
1-2 yearsSkills to master
- Mastering basic alert triage, understanding security fundamentals, following incident response playbooks, and getting comfortable with SIEM/EDR tools.
You're ready to move on when
- Consistently resolving tier-1 alerts within SLA.
- Proactively asking questions to understand the 'why' behind security incidents.
- Demonstrating a strong grasp of network and operating system security basics.
- 2
IT Support / Network Operations Engineer
2-3 yearsSkills to master
- Deepening knowledge of network protocols, system administration, troubleshooting complex IT issues, and developing a security-first mindset in daily operations.
You're ready to move on when
- Successfully troubleshooting network connectivity and server issues.
- Identifying and escalating potential security issues noticed during IT support tasks.
- Taking initiative to learn about security tools and concepts in your own time.
- 3
Software Developer with Security Interest
2-4 yearsSkills to master
- Understanding common application vulnerabilities (OWASP Top 10), secure coding practices, and how to analyse code for security flaws. Developing a strong interest in the 'attacker's mindset'.
You're ready to move on when
- Actively participating in code reviews with a security lens.
- Fixing security bugs in your own code or others'.
- Demonstrating an understanding of how applications can be exploited.