The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Security Analyst / Lead Threat Hunter
3-5 years as a Senior/Lead AnalystSkills to master
- Deep technical expertise in a specific security domain (e.g., EDR, SIEM, cloud security), advanced incident response, threat hunting, and informal team leadership/mentoring. You'd be the go-to technical expert.
You're ready to move on when
- Consistently leading complex incident investigations from start to finish.
- Proactively identifying and implementing new detection rules and threat hunting methodologies.
- Effectively mentoring junior analysts and leading small technical projects.
- Demonstrating strong communication skills when presenting technical findings to non-technical audiences.
- 2
Security Architect
5-7 years as a Security ArchitectSkills to master
- Designing secure systems, understanding enterprise architecture, risk assessment, and working with engineering teams to embed security from the ground up. This path is more about building than defending.
You're ready to move on when
- Successfully designing and implementing secure solutions for complex business problems.
- Strong understanding of various security domains and how they integrate into an overall architecture.
- Ability to influence engineering teams on security best practices without being seen as a blocker.
- Experience in evaluating and selecting new security technologies.
- 3
Security Consultant (Internal or External)
5-8 years in consulting rolesSkills to master
- Client management, project delivery, broad security domain knowledge, regulatory compliance, and excellent communication skills. You'd be advising, not directly managing operations.
You're ready to move on when
- Proven ability to deliver complex security projects on time and within budget.
- Strong stakeholder management skills and ability to influence without direct authority.
- Broad knowledge of security frameworks, regulations, and industry best practices.
- Excellent written and verbal communication skills, especially for client-facing engagements.