The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Engineer (with Architectural Focus)
3-5 years in this role before moving to PrincipalSkills to master
- Deep technical expertise in a specific security domain (e.g., cloud, application security), strong problem-solving skills, initial experience designing security for smaller systems or features, and a knack for explaining complex technical concepts.
You're ready to move on when
- Consistently delivers high-quality, secure solutions for complex features.
- Proactively identifies architectural security flaws and proposes robust mitigations.
- Mentors junior engineers and is seen as a technical expert within their team.
- Has led the security design for at least 2-3 significant projects end-to-end.
- 2
Security Consultant (Specialising in Architecture)
4-6 years in consulting before moving in-houseSkills to master
- Broad exposure to various security architectures across different industries, strong client-facing communication and presentation skills, ability to translate business requirements into technical security designs, and experience managing project timelines.
You're ready to move on when
- Successfully delivered multiple security architecture engagements for diverse clients.
- Demonstrates ability to adapt architectural principles to different organisational contexts.
- Can articulate complex security risks and solutions to executive-level clients.
- Has a strong portfolio of architectural designs and recommendations that led to tangible improvements.
- 3
Enterprise Architect (with Security Specialisation)
3-5 years in enterprise architectureSkills to master
- Holistic understanding of enterprise IT landscapes, experience with architectural frameworks (e.g., TOGAF), ability to align technical strategy with business objectives, and a strong focus on cross-domain integration.
You're ready to move on when
- Has designed enterprise-level solutions that incorporate security by default.
- Understands the interdependencies between various IT domains and their security implications.
- Can effectively communicate architectural vision to a wide range of technical and business stakeholders.
- Possesses a strong understanding of IT governance and compliance from an architectural perspective.