The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Security Architect (L4)
3-5 years as an L4Skills to master
- Deep architectural design, leading complex security projects, influencing technical direction across multiple teams, some informal mentoring. You'd be moving from designing systems to managing the people who design and build them.
You're ready to move on when
- Successfully led 2-3 major security architecture initiatives from concept to deployment.
- Consistently sought out for technical guidance by senior engineers and managers.
- Demonstrated ability to translate complex technical risks into clear business implications.
- Taken on informal leadership roles, such as leading a technical guild or mentoring several junior team members.
- 2
Senior Security Consultant (from external firm)
Coming in with 12-15 years of consulting experienceSkills to master
- Client management, strategic advisory, programme delivery, often with exposure to multiple industries. The transition involves moving from advising to directly owning and delivering a security programme internally.
You're ready to move on when
- Successfully managed large-scale security transformation programmes for multiple clients.
- Proven ability to build and maintain strong relationships with C-suite level executives.
- Experience in developing and implementing security strategies in complex organisations.
- Strong track record of managing project budgets and client expectations.
- 3
Head of Security Operations Centre (SOC)
3-5 years in a similar leadership roleSkills to master
- Managing 24/7 operations, incident response leadership, team management, tooling optimisation, threat detection. This path brings strong operational leadership experience, which is highly valued.
You're ready to move on when
- Successfully led a SOC team through multiple major security incidents.
- Demonstrated significant improvements in MTTR and MTTD metrics.
- Proven ability to build and mature a SOC's capabilities (e.g., threat hunting, automation).
- Strong experience in managing and optimising SIEM and EDR platforms.