The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Cloud Governance Engineer (L4)
3-5 years as a LeadSkills to master
- Deep expertise in designing and implementing automated governance solutions (PaC, IaC). Proven ability to technically lead projects and mentor junior engineers. Strong understanding of multi-cloud architecture and security principles. This path is about becoming the technical authority in governance.
You're ready to move on when
- Successfully designed and deployed a new enterprise-wide governance framework (e.g., a PaC pipeline).
- Consistently delivered complex governance projects on time and within scope.
- Recognised as the go-to technical expert for cloud governance challenges.
- Has effectively mentored 2-3 junior team members, helping them grow their skills.
- 2
Senior Cloud FinOps Specialist (L4)
3-5 years as a Senior SpecialistSkills to master
- Mastery of FinOps principles, cost optimisation strategies, and cloud financial reporting. Proven ability to drive significant cost savings and manage cloud budgets. Strong stakeholder management with finance and business units. This path is about becoming the financial brain of the cloud.
You're ready to move on when
- Successfully identified and realised significant cloud cost savings (£500K+ annualised).
- Owned and managed the cloud budgeting and forecasting process for a large business unit.
- Built and maintained complex FinOps dashboards and reporting solutions.
- Effectively influenced business units to adopt cost-optimisation recommendations.
- 3
Cloud Security Architect (L4)
3-5 years as a Cloud Security ArchitectSkills to master
- Deep expertise in cloud security architecture, threat modelling, and implementing security controls across multi-cloud environments. Strong understanding of compliance frameworks and risk management. This path is about being the security conscience of the cloud.
You're ready to move on when
- Designed and implemented secure cloud architectures for critical applications.
- Successfully led efforts to achieve compliance with major security standards (e.g., ISO 27001, PCI-DSS).
- Developed and enforced cloud security policies that effectively mitigated risks.
- Has a strong track record of collaborating with CISO and engineering teams on security initiatives.


