The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate Security Operations Analyst (L1)
1-2 yearsSkills to master
- Basic alert triage, playbook execution, foundational understanding of SIEM/EDR, clear documentation, escalation procedures.
You're ready to move on when
- Consistently accurate L1 alert triage with minimal supervision.
- Proactive identification of process improvements for L1 tasks.
- Demonstrated curiosity and initiative to learn beyond immediate tasks.
- Ability to articulate basic incident response steps and concepts.
- 2
IT Support / Network Engineer with Security Focus
2-3 years in IT, then 1-2 years in security-adjacent roleSkills to master
- Deep understanding of system internals, network protocols, troubleshooting, basic scripting, and an eagerness to pivot into dedicated security.
You're ready to move on when
- Successfully troubleshooted complex IT/network issues with a security lens.
- Taken initiative to implement security best practices in their previous role.
- Obtained relevant security certifications (e.g., Security+, CySA+).
- Demonstrated a strong desire and aptitude for incident investigation.
- 3
Security Intern / Apprenticeship Programme
1-2 yearsSkills to master
- Practical application of security theory, understanding of a real-world SOC environment, hands-on experience with security tools, professional communication.
You're ready to move on when
- Successfully completed a structured security internship or apprenticeship.
- Received strong recommendations from mentors and supervisors.
- Contributed meaningfully to security projects during their programme.
- Developed a foundational understanding of incident response and threat detection.