The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead / Staff Vulnerability Engineer
3-5 years in a Lead/Staff roleSkills to master
- Architecting complex VM solutions, solving novel technical challenges, mentoring junior engineers, and influencing technical direction without direct authority.
You're ready to move on when
- Successfully led multiple large-scale VM projects end-to-end.
- Consistently provided high-quality technical guidance and mentorship to peers.
- Demonstrated ability to influence technical decisions across different engineering teams.
- Developed and implemented significant improvements to VM processes or tooling.
- 2
Security Architect (with VM specialisation)
4-6 years as a Security ArchitectSkills to master
- Designing secure architectures, performing threat modelling, integrating security into the SDLC, and translating architectural risks into actionable plans.
You're ready to move on when
- Designed and reviewed security architectures for critical business systems.
- Successfully embedded security controls into CI/CD pipelines.
- Demonstrated a strong understanding of vulnerability implications across different architectural layers.
- Effectively communicated architectural risks and solutions to technical and non-technical audiences.
- 3
Security Operations Lead
3-5 years in a Security Operations Lead roleSkills to master
- Managing security incidents, leading a small team of security analysts, developing incident response playbooks, and understanding the broader SecOps landscape.
You're ready to move on when
- Successfully led responses to major security incidents.
- Managed and mentored a small team of security analysts.
- Developed and optimised security operations processes.
- Demonstrated a strong understanding of threat detection and response methodologies.