The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior IoT Security Specialist (L3)
3-5 years as an L3Skills to master
- You'd need to have mastered end-to-end security assessments, started leading complex projects, and demonstrated an ability to mentor junior team members. Building strong communication skills to influence product teams is also crucial.
You're ready to move on when
- Consistently delivering high-quality, comprehensive security assessment reports with actionable recommendations.
- Successfully leading multiple security projects with minimal supervision.
- Being the go-to person for complex technical challenges within your team.
- Receiving positive feedback from mentees and cross-functional teams on your guidance and collaboration.
- 2
From Senior Embedded Systems Engineer (with Security Focus)
5-8 years in embedded engineering + 2-3 years focused on securitySkills to master
- You'd need a deep understanding of embedded hardware and firmware development, coupled with a strong shift towards security principles, threat modelling, and vulnerability analysis. Learning offensive security techniques is key.
You're ready to move on when
- Demonstrated ability to identify and fix security flaws in embedded code.
- Proactive in advocating for security-by-design within engineering teams.
- Completed relevant security certifications (e.g., OSCP, GIAC).
- Actively participating in security communities and sharing knowledge.