The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Security Architect (Global Strategy)
3-5 years at that levelSkills to master
- Enterprise security architecture design, strategic planning, influencing senior technical stakeholders, understanding business requirements for security.
You're ready to move on when
- Successfully designed and implemented a major security system across the enterprise.
- Consistently provided technical leadership on complex projects, guiding multiple teams.
- Demonstrated ability to translate technical concepts into business language for executive audiences.
- 2
Senior Security Consultant (with Management Experience)
4-6 years in consulting, with project lead rolesSkills to master
- Client management, risk assessment methodologies, programme management, presenting to C-suite clients, building and leading project teams.
You're ready to move on when
- Successfully delivered multiple complex security engagements for diverse clients.
- Managed project teams and budgets, achieving high client satisfaction.
- Developed and presented strategic security roadmaps to client leadership.
- 3
Head of Security Operations (Regional/Large Enterprise)
3-5 years in a similar leadership roleSkills to master
- SOC management, incident response leadership, threat hunting, security tool optimisation, building and scaling operational teams.
You're ready to move on when
- Significantly improved MTTR/MTTD metrics for a large security operations centre.
- Successfully led the response to multiple major security incidents.
- Built and mentored a high-performing SOC team, reducing analyst burnout.