The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Analyst (L3) Promotion
3-5 years as a Senior AnalystSkills to master
- Leading complex incidents end-to-end, consistently creating high-fidelity detection rules, mentoring junior team members effectively, and taking ownership of significant workstreams.
You're ready to move on when
- You're consistently the go-to person for the trickiest technical problems.
- You've successfully led multiple major incident investigations without significant escalation.
- You've actively mentored 2-3 junior analysts to a point where they're much more independent.
- You're proactively identifying and closing detection gaps, not just reacting to alerts.
- 2
External Lead SOC Analyst / Threat Hunter
Coming from a similar Lead or Staff level role at another organisation (8-12 years experience)Skills to master
- Demonstrable experience architecting detection capabilities, leading threat hunts, and managing small technical teams or projects. A strong portfolio of automation scripts or detection rules is a huge plus.
You're ready to move on when
- You can clearly articulate your experience leading technical initiatives and driving security improvements.
- You have a track record of building and deploying advanced detection rules in complex environments.
- You can demonstrate your mentorship capabilities through examples of developing junior team members.
- You're comfortable presenting technical findings and strategic recommendations to senior stakeholders.
- 3
Security Engineer with SOC Experience
Moving from a Security Engineering role after 8-10 years, with significant exposure to SOC operationsSkills to master
- Deep understanding of security architecture and infrastructure, coupled with hands-on experience with SIEM/EDR platforms and incident response processes. You'll need to bridge the gap between engineering and operations.
You're ready to move on when
- You've designed and implemented security controls that directly feed into SOC detection capabilities.
- You're proficient in scripting and automation, having built tools to streamline security tasks.
- You have a strong grasp of threat modelling and how to translate those into detection strategies.
- You're eager to take on a more operational, hands-on role in threat detection and hunting.