The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Junior Security Analyst
1-2 yearsSkills to master
- Basic alert monitoring, log review, understanding security fundamentals, following clear playbooks, documenting findings accurately.
You're ready to move on when
- Consistently handles routine alerts without supervision.
- Demonstrates a solid grasp of basic security concepts.
- Proactively seeks out learning opportunities.
- Reliably completes assigned tasks and documentation.
- 2
IT Support / Network Engineer with Security Focus
2-3 yearsSkills to master
- Deep understanding of network protocols, firewall rules, system administration, troubleshooting connectivity issues, and an interest in security principles.
You're ready to move on when
- Has taken on security-related tasks in their previous role (e.g., firewall rule reviews, access control management).
- Holds a security-specific certification (e.g., CompTIA Security+).
- Can articulate how IT infrastructure choices impact security.
- Shows a clear drive to specialise in cybersecurity.
- 3
Graduate Cyber Security Programme
1-2 years (post-degree)Skills to master
- Foundational security knowledge, exposure to various security domains (GRC, SOC, AppSec), project-based learning, structured mentorship.
You're ready to move on when
- Successfully completed all rotations or projects within a structured graduate programme.
- Demonstrates a broad understanding of the cybersecurity landscape.
- Has a clear interest in a hands-on technical security role.
- Received positive feedback from mentors and project leads.