The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Senior Security Engineer / Lead Security Architect
3-5 years in a senior individual contributor role.Skills to master
- Moving from deep technical execution to strategic design and project leadership. You'd have been leading complex implementations, mentoring juniors, and making significant technical decisions. You'd also be getting comfortable with presenting to non-technical audiences.
You're ready to move on when
- You've successfully led at least 2-3 major security projects end-to-end, involving multiple stakeholders.
- You're the go-to person for architectural decisions in your domain, and your recommendations are trusted.
- You've informally mentored junior colleagues and enjoy helping them grow.
- You've started thinking about the 'why' behind security controls, not just the 'how'.
- 2
From Security Team Lead / Technical Lead
2-4 years leading a small team or a specific security function.Skills to master
- This path is about expanding your scope from a small team to a larger function, and from tactical leadership to strategic management. You'd have been managing a few direct reports, handling day-to-day operations, and now you're ready for more strategic ownership and budget responsibility.
You're ready to move on when
- You've managed a team of 3-5 people, including performance reviews and career development.
- You're comfortable with basic budget tracking and resource allocation for your team.
- You've successfully resolved team conflicts and fostered a positive team environment.
- You're actively looking for ways to improve team processes and efficiency.