The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior SOC Analyst / Incident Responder (L3)
3-5 years at L3Skills to master
- Mastering complex incident investigations, developing advanced detection rules, informal mentorship of junior analysts, and leading smaller incident response efforts end-to-end.
You're ready to move on when
- Consistently handling the most complex incidents without significant oversight.
- Proactively identifying gaps in detection and proposing solutions.
- Being the 'go-to' person for technical questions from junior analysts.
- Successfully leading small-scale purple team exercises or threat hunts.
- 2
Cyber Security Consultant (with IR focus)
5-8 years in consultingSkills to master
- Experience across various client environments, exposure to diverse security tools and incident types, strong client-facing communication, and project management skills.
You're ready to move on when
- Successfully managed multiple incident response engagements for different clients.
- Developed and delivered incident response plans or playbooks for client organisations.
- Strong ability to adapt to new technical environments quickly.
- Excellent stakeholder management and communication skills.
- 3
Security Engineer (with strong detection/response focus)
4-7 years in security engineeringSkills to master
- Deep understanding of security architecture, experience implementing security controls, and a strong focus on building resilient systems that are easy to monitor and defend.
You're ready to move on when
- Designed and implemented security solutions that significantly improved an organisation's defensive posture.
- Built robust logging and monitoring capabilities into new systems.
- Proactively identified and mitigated security risks during the system development lifecycle.