The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Cybersecurity Engineer
3-5 years as a Senior EngineerSkills to master
- Leading medium-sized projects, mentoring junior team members, developing new detection content, performing advanced tool tuning, and making technical recommendations to leadership.
You're ready to move on when
- Consistently taking ownership of complex workstreams without direct supervision.
- Proactively identifying areas for security improvement and proposing solutions.
- Successfully guiding junior colleagues through technical challenges.
- Demonstrating strong technical judgment in non-routine situations.
- 2
Security Architect (Implementation Focus)
5-8 years in a security architecture roleSkills to master
- Translating high-level security requirements into detailed technical designs, understanding enterprise architecture patterns, and collaborating closely with development and operations teams to ensure secure system design.
You're ready to move on when
- Proven ability to design secure, scalable, and resilient systems.
- Strong understanding of enterprise architecture principles and how security integrates.
- Excellent communication skills for articulating architectural decisions and trade-offs.
- 3
DevOps Engineer with Security Specialisation
5-8 years in a DevOps role with increasing security responsibilitiesSkills to master
- Deep expertise in CI/CD pipelines, infrastructure as code, containerisation, and cloud platforms, coupled with a strong focus on embedding security controls and automation throughout the development lifecycle.
You're ready to move on when
- Successfully implemented security automation within CI/CD pipelines.
- Demonstrated ability to 'shift left' security practices effectively.
- Strong understanding of both development and operational challenges in a cloud-native environment.