The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior IT Security Analyst
3-5 years as a Senior AnalystSkills to master
- Deep expertise in incident response, advanced threat hunting, security tool tuning, and mentoring junior team members. You'd be the go-to person for complex investigations.
You're ready to move on when
- You've successfully led multiple complex security incidents from detection to post-mortem.
- You're regularly consulted by peers for technical advice and problem-solving.
- You've driven significant improvements in our detection and response capabilities.
- You've informally mentored junior colleagues and enjoyed seeing them grow.
- 2
Security Consultant (External)
5-8 years in consultancySkills to master
- Broad exposure to different security challenges across various industries, strong client-facing communication, and the ability to design security solutions for diverse environments. You'd have seen a lot of different ways to do (and not do) security.
You're ready to move on when
- You've managed security projects for multiple clients, delivering tangible improvements.
- You're adept at translating technical risks into business impact for diverse audiences.
- You've designed and overseen the implementation of various security architectures.
- You're comfortable with a high degree of autonomy and problem-solving in novel situations.
- 3
System Architect with Security Specialisation
6-10 years in architecture rolesSkills to master
- Deep understanding of system design, infrastructure, and application architecture, with a strong focus on building security in from the start. You'd be excellent at identifying architectural weaknesses.
You're ready to move on when
- You've designed and implemented large-scale IT systems, with security as a core consideration.
- You're proficient in threat modelling and secure design principles.
- You're regularly involved in architectural review boards, providing security input.
- You can articulate how architectural decisions impact security posture.