The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Engineer (Specialising in Architecture)
3-5 years as a Senior EngineerSkills to master
- Deep technical expertise in a specific domain (e.g., cloud, application, network security), leading complex technical projects, early exposure to threat modelling and design reviews, mentoring junior engineers.
You're ready to move on when
- You're already the go-to person for complex technical security problems in your current role.
- You've successfully led the security design and implementation for at least one major system.
- You're comfortable presenting technical solutions to non-technical audiences.
- You've started mentoring junior team members and enjoy helping them grow.
- 2
Security Consultant (with a focus on Design)
4-6 years in consultingSkills to master
- Broad exposure to different security architectures and industries, client-facing communication, translating business requirements into technical solutions, risk assessment, and framework implementation.
You're ready to move on when
- You've designed and delivered security architectures for multiple clients.
- You're adept at understanding diverse business contexts and tailoring security solutions.
- You can effectively manage stakeholder expectations and influence decisions.
- You're looking to move from project-based work to owning a long-term architectural vision within one organisation.
- 3
Lead DevOps/Cloud Engineer (with strong security focus)
5-7 years in a lead engineering roleSkills to master
- Deep understanding of cloud infrastructure, CI/CD pipelines, automation, infrastructure-as-code, and a strong passion for embedding security into the development lifecycle.
You're ready to move on when
- You've been responsible for the security of your own team's deployments and infrastructure.
- You're constantly thinking about how to build secure systems from the ground up.
- You've implemented security controls and practices within your engineering workflows.
- You're looking to specialise purely in security architecture and influence wider organisational security.