The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Engineer / Architect
3-5 years in this roleSkills to master
- Deep technical expertise in a specific security domain (e.g., cloud security, incident response), ability to design and implement complex security solutions, strong mentorship of junior colleagues, and initial experience leading small projects or initiatives.
You're ready to move on when
- Successfully led the design and deployment of a major security control or architecture.
- Consistently sought out to mentor and guide less experienced team members.
- Demonstrated ability to communicate complex technical concepts to non-technical audiences.
- Took ownership of significant security incidents from start to finish.
- 2
Security Team Lead / Programme Lead
2-4 years in this roleSkills to master
- Direct experience managing a small team (2-5 people), ownership of a specific security programme (e.g., vulnerability scanning, security awareness), strong organisational and communication skills, and initial budget management experience.
You're ready to move on when
- Successfully managed a small team, including performance reviews and development plans.
- Developed and executed a roadmap for a security programme, achieving measurable improvements.
- Effectively managed relationships with key internal stakeholders for their programme.
- Demonstrated ability to prioritise and allocate resources for their team/programme.
- 3
Consulting Cyber Security Manager
5-8 years in consultingSkills to master
- Broad exposure to different security programmes and organisational structures, strong client-facing communication and presentation skills, experience leading project teams, and a deep understanding of multiple compliance frameworks. You'll need to translate that consulting experience into directly owning and operating an internal programme.
You're ready to move on when
- Successfully led multiple cybersecurity engagements for diverse clients.
- Consistently received high client satisfaction scores.
- Managed project budgets and timelines effectively.
- Demonstrated ability to build and lead consulting teams.