The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Staff Risk Technology Engineer (L4)
3-5 yearsSkills to master
- Deep expertise in a specific risk domain (e.g., cloud security, GRC automation), ability to architect multi-system solutions, strong influence skills across teams, and initial experience in technical leadership/mentorship.
You're ready to move on when
- Consistently delivering complex, cross-team security projects.
- Recognised as the 'go-to' expert for a critical technical area.
- Proactively identifying and solving ambiguous technical problems.
- Successfully mentoring 2-3 junior engineers.
- 2
Lead Security Architect (from another domain)
4-6 yearsSkills to master
- Broad enterprise security architecture experience, strong understanding of business context and risk, ability to translate security requirements into technical designs, and a solid grasp of automation principles.
You're ready to move on when
- Proven track record of designing secure systems across diverse technologies.
- Ability to articulate security risks and trade-offs to non-technical audiences.
- Experience working with compliance and audit teams.
- Demonstrated ability to influence architectural decisions at a senior level.
- 3
Senior Manager, Security Engineering
3-5 yearsSkills to master
- Strong people management skills, experience building and leading high-performing security teams, strategic planning, and budget management, combined with deep technical credibility.
You're ready to move on when
- Successfully managed a team of 5+ security engineers.
- Delivered significant security programmes through a team.
- Strong technical background, still able to contribute to architectural discussions.
- Experience with resource planning and performance management.