The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Vulnerability Assessment Specialist (L3)
3-5 yearsSkills to master
- You'd need to have mastered leading complex individual assessments, developing custom scripts for specific targets, and consistently delivering high-quality, actionable reports. Demonstrating informal mentorship is also key.
You're ready to move on when
- Consistently leading critical infrastructure or application assessments end-to-end.
- Proactively identifying and implementing process improvements for vulnerability management.
- Being the go-to person for technical advice within your team on complex exploitation scenarios.
- Successfully mentoring 1-2 junior analysts, helping them grow their technical skills.
- 2
Security Engineer (Offensive Security Focus)
5-7 yearsSkills to master
- Coming from a broader security engineering role, you'd need to have specialised in offensive techniques, showing a strong portfolio of penetration testing, red teaming, and exploit development. Experience with security architecture and automation would be highly valued.
You're ready to move on when
- Designing and implementing security controls that you've then tried to break.
- Developing automated security testing tools or frameworks.
- Deep understanding of attack surfaces and common exploitation techniques across various technologies.
- A strong track record of identifying and remediating critical security flaws in systems you've built or managed.
- 3
External Penetration Tester / Security Consultant
6-10 yearsSkills to master
- If you're coming from a consulting background, you'd need to demonstrate experience leading diverse engagements across various industries and technologies. Strong client communication, report writing, and the ability to adapt to new environments quickly would be essential.
You're ready to move on when
- Successfully managing and delivering multiple complex penetration testing projects for external clients.
- Consistently receiving excellent client feedback on your technical skills and communication.
- Experience with a wide range of technologies and attack vectors (web, mobile, cloud, network, IoT).
- Ability to translate technical findings into clear, business-relevant risks and recommendations.