The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Incident Responder / Staff Threat Hunter (L4)
3-5 years as an L4Skills to master
- Deep technical leadership in major incidents, architecting detection rules, leading proactive threat hunts, informal mentorship of junior staff, strong cross-functional influencing skills.
You're ready to move on when
- Consistently leading complex incidents to successful resolution without direct supervision.
- Proactively identifying and implementing improvements to IR processes and tools.
- Demonstrating an ability to influence senior stakeholders on technical decisions.
- Successfully mentoring and developing junior team members, showing a knack for people development.
- 2
Senior Security Engineer (with IR focus)
4-6 years as a Senior EngineerSkills to master
- Deep technical expertise in a specific security domain (e.g., network security, cloud security) combined with significant incident response experience, strong problem-solving, and project leadership.
You're ready to move on when
- Leading security projects that have a direct impact on incident detection or response capabilities.
- Acting as a subject matter expert during major incidents, providing critical technical insights.
- Proactively identifying security gaps and proposing strategic solutions, not just technical fixes.
- Demonstrating an understanding of business risk and how security decisions impact it.
- 3
Security Operations Centre (SOC) Manager
3-5 years as a SOC ManagerSkills to master
- Managing a 24/7 security operations team, optimising detection capabilities, developing and refining playbooks, managing team performance, and reporting on SOC metrics.
You're ready to move on when
- Successfully managing and motivating a team of SOC analysts and engineers.
- Demonstrating continuous improvement in MTTA and MTTR for alerts.
- Strong understanding of SIEM/EDR tuning and alert correlation.
- Proven ability to handle escalations and communicate effectively during incidents.