The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Analyst/Engineer (L3-L4) to Manager
3-5 years as a Senior/LeadSkills to master
- Moving from individual contribution to leading projects and mentoring others. Developing strong communication skills for non-technical audiences. Understanding programme management and basic budget oversight.
You're ready to move on when
- Successfully led multiple complex security projects end-to-end.
- Consistently mentored junior team members, helping them grow and solve problems.
- Demonstrated ability to influence technical decisions and gain buy-in from peers.
- Shown initiative in identifying and proposing solutions to organisational security challenges.
- 2
Security Consultant (External) to Internal Manager
Roughly 10-15 years in consulting, with management experienceSkills to master
- Adapting from project-based consulting to long-term programme ownership. Building internal relationships and navigating organisational culture. Deepening understanding of a specific organisation's risk appetite and constraints.
You're ready to move on when
- Experience managing consulting teams and client engagements.
- Proven ability to design and implement security strategies for multiple clients.
- Strong communication and stakeholder management skills from client-facing roles.
- A desire to build and nurture a long-term internal security capability rather than move between projects.
- 3
Technical Lead/Architect in a related IT field (e.g., Infrastructure, DevOps) to Security Manager
5-8 years in a technical lead role, plus specific security trainingSkills to master
- Transitioning from a general technical focus to a dedicated security mindset. Gaining deep knowledge of cybersecurity frameworks, incident response, and threat landscapes. Developing a 'productive paranoia'.
You're ready to move on when
- Demonstrated strong technical leadership and architectural design skills.
- Taken on security-focused projects or responsibilities in previous roles.
- Completed relevant cybersecurity certifications (e.g., CISSP, CISM).
- Shown a genuine passion for security and a commitment to continuous learning in the field.