The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Vulnerability Analyst (L3) to Lead Vulnerability Analyst (L4) to Programme Manager (L5)
Roughly 4-6 years from Senior Analyst to Programme Manager.Skills to master
- Moving from deep technical analysis to leading projects, then to designing and automating processes, and finally to owning the entire programme. This involves developing strong leadership, strategic planning, and stakeholder management skills.
You're ready to move on when
- Successfully led multiple complex vulnerability investigations and remediation efforts.
- Demonstrated ability to mentor and guide junior analysts effectively.
- Proven experience in designing and implementing process improvements or automation for VM.
- Strong track record of influencing cross-functional teams to prioritise security work.
- 2
Security Architect / Senior Security Engineer to Programme Manager (L5)
Around 3-5 years as an architect/engineer before moving into programme management.Skills to master
- Translating deep architectural knowledge into programme strategy. This path requires developing strong people leadership, budget management, and communication skills, as the focus shifts from technical design to programme execution and oversight.
You're ready to move on when
- Designed and implemented security architectures for critical systems.
- Deep understanding of security controls and their effectiveness in different environments.
- Experience in presenting technical solutions and risks to non-technical audiences.
- A desire to move from individual technical contribution to leading a team and a programme.
- 3
Consultant (Security/Risk Management) to Programme Manager (L5)
Typically 5-8 years in security consulting roles.Skills to master
- Leveraging broad industry experience in security programme design and implementation. This path requires adapting to an internal, long-term ownership mindset, building internal relationships, and managing a permanent team rather than project-based engagements.
You're ready to move on when
- Successfully delivered security programme design or improvement projects for multiple clients.
- Strong client-facing communication and presentation skills.
- Experience in developing security policies and procedures.
- A desire to take long-term ownership of a security programme within a single organisation.