The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Network Security Engineer (Internal Promotion)
3-5 years as an L4 Lead EngineerSkills to master
- At L4, you'd be architecting solutions and leading projects. To step up to L5, you need to master team leadership, strategic planning, budget management, and executive communication. It's about shifting from technical authority to strategic and people leadership.
You're ready to move on when
- Successfully led 2-3 major network security projects from conception to completion, demonstrating strong project management skills.
- Consistently mentored junior engineers and acted as an informal team lead, showing a knack for developing others.
- Presented technical solutions and risks effectively to senior management, demonstrating strong communication and influence.
- Developed a deep understanding of the business context and how security decisions impact the wider organisation.
- 2
Security Engineering Manager (External Hire)
Coming from a similar managerial role at another company (5+ years of management experience)Skills to master
- You'd need to quickly get up to speed on our specific network architecture, tech stack, and organisational culture. Demonstrating adaptability and the ability to build rapport with a new team is crucial.
You're ready to move on when
- Proven track record of building and managing high-performing security teams in previous roles.
- Experience managing significant security budgets and vendor relationships.
- Ability to quickly assess and understand a new organisation's security posture and strategic needs.
- Strong references from former direct reports and senior leaders.
- 3
Principal Security Architect (Internal Lateral Move)
5-8 years as a Principal Architect in another security domain (e.g., Cloud Security, Application Security)Skills to master
- You'd need to deepen your specific network security expertise and understand the nuances of network-centric threats and controls. While you'd have the architectural chops, the network-specific knowledge would be key.
You're ready to move on when
- Demonstrated ability to architect complex security solutions in other domains at an enterprise level.
- Strong understanding of how different security domains (e.g., application, cloud) interact with network security.
- A willingness to dive deep into network protocols and infrastructure, even if it's not your primary specialisation.
- Proven ability to influence technical direction across different teams and departments.