The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Junior Security Analyst / Associate Compliance Analyst
2-3 yearsSkills to master
- Basic security principles, evidence collection basics, understanding of a single compliance framework (e.g., ISO 27001), effective use of ticketing systems, clear documentation.
You're ready to move on when
- Consistently delivers accurate evidence under supervision.
- Can clearly explain basic security controls.
- Proactively identifies opportunities for process improvement in their tasks.
- Receives positive feedback on their organisational skills and attention to detail.
- 2
IT Auditor (Internal or External)
2-4 yearsSkills to master
- Audit methodologies, control testing, risk assessment, understanding of various IT general controls, stakeholder interviewing, report writing.
You're ready to move on when
- Experience conducting IT audits and documenting findings.
- Strong understanding of control objectives and testing procedures.
- Ability to interact professionally with diverse stakeholders.
- Proficient in using audit management software or tools.
- 3
IT Support / Operations Specialist with Security Focus
3-5 yearsSkills to master
- Deep technical understanding of systems (e.g., network, servers, cloud), incident response basics, vulnerability management, problem-solving, process improvement.
You're ready to move on when
- Demonstrated interest in security beyond daily operational tasks.
- Can articulate how technical configurations impact security posture.
- Experience implementing security-related changes or remediations.
- Proactively suggests security enhancements to existing systems.