The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Analyst / Engineer (L3)
3-5 yearsSkills to master
- Deep technical expertise in a specific security domain (e.g., cloud, network, application security), leading technical projects, mentoring junior team members, and strong incident response capabilities.
You're ready to move on when
- Successfully led 3+ major security projects from conception to completion.
- Consistently identified and remediated complex vulnerabilities that others missed.
- Demonstrated ability to mentor and elevate the technical skills of junior colleagues.
- Proactively contributed to security strategy discussions, bringing technical insights to the table.
- 2
Experienced Security Consultant
2-4 yearsSkills to master
- Broad exposure to various security environments and technologies, strong client-facing communication, ability to quickly assess and design security solutions for diverse business needs, and experience translating high-level requirements into technical plans.
You're ready to move on when
- Managed multiple client engagements, delivering impactful security solutions.
- Proven ability to adapt security strategies to different industry contexts.
- Strong track record of influencing stakeholders and driving adoption of security recommendations.
- Developed and presented security architectures to senior client leadership.
- 3
Senior Software Engineer (with Security Specialisation)
4-6 yearsSkills to master
- Deep understanding of secure coding practices, application security vulnerabilities, secure SDLC integration, and experience designing and building security features directly into software products. You'd bring a 'developer's eye' to security architecture.
You're ready to move on when
- Designed and implemented critical security features in production applications.
- Led secure code reviews and mentored development teams on security best practices.
- Contributed to the development of internal security tooling or frameworks.
- Demonstrated ability to balance security requirements with development velocity.