The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior Security Engineer / Lead Security Architect
3-5 years in a senior technical role before moving into management.Skills to master
- Moving from deep technical individual contribution to leading a team, managing projects, and influencing stakeholders. You'll need to develop strong communication and delegation skills.
You're ready to move on when
- Successfully led complex security projects end-to-end.
- Consistently mentored junior team members and helped them grow.
- Demonstrated ability to translate technical concepts into business language.
- Proactively identified and proposed solutions to organisational security challenges.
- 2
From Security Programme Manager (non-technical lead)
4-6 years managing security programmes or projects, often with a strong GRC background.Skills to master
- Deepening technical understanding of security operations and architecture, moving beyond project management to direct team leadership and technical decision-making. You'll need to earn technical credibility.
You're ready to move on when
- Successfully managed large-scale security initiatives.
- Developed a solid understanding of core security technologies and their implementation.
- Proactively engaged with technical teams to understand operational challenges.
- Demonstrated ability to influence technical outcomes without direct authority.
- 3
From Security Consultant (with internal experience)
5-7 years in consulting, with some internal security team experience.Skills to master
- Transitioning from advisory to direct operational responsibility, including budget ownership and people management. You'll need to move from recommending to owning the execution and outcomes.
You're ready to move on when
- Proven track record of delivering security solutions for multiple clients.
- Strong understanding of various security frameworks and best practices.
- Demonstrated ability to build relationships and influence at different organisational levels.
- Expressed a clear desire to move into a permanent leadership role with direct accountability.