The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Security Architect / Principal Incident Responder
3-5 years at this level before moving to ManagerSkills to master
- Deep technical expertise in a specific security domain, ability to design complex solutions, strong mentorship skills, and initial experience influencing technical direction across teams.
You're ready to move on when
- Successfully led 2-3 major security architecture projects from design to implementation.
- Mentored at least 3-5 junior/mid-level security professionals to significant career milestones.
- Demonstrated ability to present technical solutions and their business impact to senior leadership.
- Took ownership of critical incidents, coordinating response efforts and post-mortems.
- 2
Senior GRC Analyst / Security Programme Lead
4-6 years at this level before moving to ManagerSkills to master
- Expertise in security frameworks and regulatory compliance, strong project management skills, ability to manage relationships with auditors and legal teams, and experience driving security programme improvements.
You're ready to move on when
- Successfully managed an ISO 27001 certification or major compliance audit end-to-end.
- Developed and implemented significant security policies or controls across the organisation.
- Demonstrated ability to translate compliance requirements into actionable technical tasks for engineering teams.
- Managed cross-functional security projects with budgets up to £250K.
- 3
Security Consulting Manager (External)
2-4 years in consulting before moving in-houseSkills to master
- Broad exposure to various security programmes and industries, strong client management and presentation skills, experience advising senior leadership on security strategy, and managing consulting teams.
You're ready to move on when
- Successfully led security engagements for multiple enterprise-level clients.
- Managed a team of security consultants, delivering projects on time and budget.
- Developed and presented security strategies or risk assessments to C-suite clients.
- Proven ability to adapt security best practices to diverse organisational contexts.