The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
University Graduate (Cyber Security/Computer Science)
0-1 year post-graduationSkills to master
- Translating academic knowledge into practical application, mastering core tools like Burp Suite, understanding the 'why' behind vulnerabilities, and effective technical communication.
You're ready to move on when
- Successfully completed a security-focused final year project or dissertation.
- Achieved relevant security certifications (e.g., eJPT) during or shortly after studies.
- Demonstrated practical skills through CTF participation or personal lab projects.
- 2
Self-Taught / Hobbyist
1-3 years of dedicated self-study and practiceSkills to master
- Formalising self-taught knowledge into structured methodologies, understanding professional reporting standards, and building a portfolio of demonstrable practical skills.
You're ready to move on when
- A comprehensive home lab setup with documented projects and findings.
- Strong performance in recognised online security challenges (e.g., Hack The Box, TryHackMe).
- Contributions to open-source security projects or a personal blog detailing security research.
- 3
IT Support / Junior Developer with Security Interest
1-2 years in previous role, plus dedicated security learningSkills to master
- Shifting from a defensive/building mindset to an offensive one, understanding exploitation techniques, and applying existing IT/dev knowledge to security contexts.
You're ready to move on when
- Proactively implemented security improvements in previous roles.
- Completed relevant security certifications or extensive online courses.
- Can articulate how their previous experience provides a unique perspective on security vulnerabilities.