The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate Penetration Tester (L1)
1-2 yearsSkills to master
- Mastering core tools (Burp, Nmap, Metasploit basics), understanding PTES methodology, writing clear finding reports, strict adherence to RoE.
You're ready to move on when
- Consistently delivers accurate findings on routine tests under supervision.
- Can explain basic vulnerabilities (e.g., XSS, SQLi) and their impact.
- Shows strong initiative in learning new techniques and tools.
- Trusted to work independently on specific tasks within a larger engagement.
- 2
Security Operations Centre (SOC) Analyst
2-3 yearsSkills to master
- Deep understanding of defensive security, incident response, log analysis, threat detection, and how attackers typically operate (which is great for offensive roles).
You're ready to move on when
- Can articulate common attack vectors and how they are detected.
- Has experience triaging security alerts and understanding attacker TTPs.
- Shows a clear interest in moving from defence to offence.
- Has started self-studying offensive security techniques (e.g., CTFs, home lab).
- 3
Junior Security Engineer
2-4 yearsSkills to master
- Experience with security tool deployment and management, understanding of security architecture, scripting for automation, and some exposure to vulnerability management.
You're ready to move on when
- Has deployed or managed security tools (e.g., WAFs, EDRs).
- Understands network and system security configurations.
- Can write scripts to automate security tasks.
- Has a strong desire to transition into a hands-on 'breaking' role.