The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Vulnerability Management Engineer (L3)
3-5 years as a Senior EngineerSkills to master
- Mastering the end-to-end management of complex vulnerability workstreams, designing new scan policies, automating workflows, and consistently mentoring junior analysts. You'd be seen as a subject matter expert, ready to take on architectural challenges.
You're ready to move on when
- Successfully led 2-3 major vulnerability programme improvements (e.g., new scanner integration, significant automation).
- Consistently sought out by junior team members for technical guidance and problem-solving.
- Demonstrated ability to influence cross-functional teams on complex technical issues.
- Can independently troubleshoot and resolve highly complex scanner configuration and data integration issues.
- Proactively identifies and proposes solutions for systemic vulnerability management challenges.
- 2
Security Architect (with VM Specialisation)
4-6 years as an ArchitectSkills to master
- Designing secure systems from the ground up, understanding threat modelling, and integrating security controls across the software development lifecycle. You'd bring a strong understanding of how vulnerabilities are introduced and prevented at the design phase.
You're ready to move on when
- Proven experience designing secure architectures for new applications or infrastructure.
- Strong understanding of secure development lifecycles (SDLC) and DevSecOps principles.
- Ability to conduct threat modelling exercises and identify potential weaknesses at the design stage.
- Experience evaluating security tools and technologies for architectural fit.
- Can articulate the security implications of architectural decisions to both technical and non-technical audiences.
- 3
Senior DevOps / SRE Engineer (with Security Focus)
5-7 years in DevOps/SRESkills to master
- Deep expertise in cloud infrastructure, CI/CD pipelines, automation, and site reliability. You'd bring a strong operational perspective on how to integrate security into development and deployment processes, understanding the challenges of patching at scale.
You're ready to move on when
- Expertise in cloud platforms (AWS, Azure, GCP) and cloud-native services.
- Strong scripting and automation skills (Python, Go, PowerShell).
- Experience implementing security controls within CI/CD pipelines.
- Deep understanding of infrastructure as code (IaC) and configuration management.
- Proven ability to manage and troubleshoot complex production systems, including patching and vulnerability remediation.