The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Cloud Security Engineer (Internal Promotion)
3-5 years as a Senior EngineerSkills to master
- Deep technical expertise in multiple cloud platforms, leadership of complex security projects, strong ability to mentor junior team members, and a proven track record of driving security improvements.
You're ready to move on when
- Consistently leads and delivers on complex security initiatives without significant supervision.
- Proactively identifies and solves architectural security problems.
- Acts as a go-to expert for specific cloud security domains.
- Actively mentors and develops junior engineers, with positive feedback from them.
- 2
Cloud Security Architect (from another organisation)
8-10+ years total experience in security, with significant cloud architecture focusSkills to master
- Broad architectural experience across multiple cloud providers, strong design principles, and the ability to translate business requirements into secure technical solutions.
You're ready to move on when
- Can demonstrate experience designing enterprise-scale cloud security architectures.
- Has led the selection and implementation of major cloud security tools.
- Comfortable presenting complex technical designs to senior leadership.
- Proven ability to influence and collaborate with diverse technical teams.
- 3
DevSecOps Lead (from another organisation)
8-10+ years total experience, with strong focus on CI/CD security and automationSkills to master
- Deep understanding of CI/CD pipelines, extensive experience with IaC security tools, strong automation skills (Python/Go), and a passion for integrating security into the development lifecycle.
You're ready to move on when
- Can show examples of automated security gates implemented in CI/CD.
- Has experience training developers on secure coding practices.
- Proficient in scripting and API integrations for security tooling.
- Understands the trade-offs between security and development velocity.