The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior SOC Analyst (L3) to Lead SOC Analyst (L4) to SOC Manager (L5)
5-8 yearsSkills to master
- Deep technical expertise in multiple security domains, strong incident leadership, mentorship of junior analysts, initial exposure to process improvement and stakeholder communication. Moving from 'doing' to 'leading' technical work.
You're ready to move on when
- Consistently leading complex incident investigations with successful outcomes.
- Proactively identifying and implementing improvements to SOC processes or detections.
- Demonstrated ability to mentor and develop junior team members.
- Effective communication of technical issues to non-technical audiences.
- Taking initiative on projects beyond assigned tasks.
- 2
Incident Response Lead (from another organisation) to SOC Manager (L5)
Direct entry, 1-2 years ramp-upSkills to master
- Strong incident response methodology, crisis management, cross-functional coordination. Needs to quickly learn our specific tech stack, organisational context, and build relationships.
You're ready to move on when
- Proven track record of leading major incident responses in previous roles.
- Experience managing a small team or leading project-based work.
- Ability to quickly adapt to new environments and build credibility.
- Strong communication and leadership skills, even with external teams.
- Understanding of different security tools and their application.
- 3
Security Architect/Engineer (L4) to SOC Manager (L5)
3-5 yearsSkills to master
- Deep understanding of security systems design, implementation, and vulnerabilities. Needs to develop strong people management, operational oversight, and incident response leadership skills. Moving from 'building' to 'operating and leading'.
You're ready to move on when
- Designing and implementing robust security solutions.
- Strong grasp of security best practices and architectural patterns.
- Demonstrated ability to influence technical decisions and mentor engineers.
- Expressed interest and aptitude for people management and operational leadership.
- Willingness to shift focus from pure technical design to operational execution and team development.