The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior IT Security Analyst / Lead Security Engineer
5-8 years of experience leading complex investigations, tuning security tools, and informally mentoring junior team members.Skills to master
- Deep technical expertise in SIEM/EDR, incident response, vulnerability management, and a proven ability to lead projects and influence technical decisions. You'll need to have demonstrated leadership potential.
You're ready to move on when
- Consistently leading complex incident responses from start to finish.
- Successfully designing and implementing new detection rules or security controls.
- Receiving positive feedback on your mentorship of junior colleagues.
- Taking initiative on process improvements and strategic projects.
- 2
Security Consultant (with management experience)
8-12 years of experience, including leading security engagements for clients and potentially managing small project teams.Skills to master
- Broad exposure to various security domains, strong client-facing communication, project management skills, and experience in implementing security programmes or controls in diverse environments. You'll need to show you can transition from advising to owning.
You're ready to move on when
- Successfully delivered multiple security projects on time and budget.
- Managed client expectations and resolved complex project issues.
- Demonstrated ability to build and lead a project team.
- Deep understanding of security frameworks and compliance requirements.
- 3
IT Operations Manager (with strong security focus)
10-15 years in IT operations, with significant responsibility for security aspects of infrastructure, systems, or networks.Skills to master
- Strong understanding of IT infrastructure, networking, and systems administration, coupled with a proven track record of implementing and enforcing security controls within an operational context. You'll need to show a clear passion and aptitude for dedicated security management.
You're ready to move on when
- Successfully managed security configurations for critical IT systems.
- Led incident response efforts involving IT infrastructure.
- Implemented significant security improvements within an IT operations context.
- Actively pursued security certifications and professional development.