The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From SOC Analyst (Level 1)
2-3 yearsSkills to master
- Independent incident investigation, basic forensic analysis, effective communication during incidents, understanding of the full IR lifecycle.
You're ready to move on when
- Consistently closing Tier 1 alerts without escalation.
- Proactively identifying and triaging false positives.
- Demonstrating curiosity and a desire to understand root causes, not just symptoms.
- Taking initiative on minor projects or improvements within the SOC.
- 2
From IT Security Engineer
3-4 yearsSkills to master
- Incident response methodologies, forensic evidence collection, threat intelligence application, real-time decision-making under pressure.
You're ready to move on when
- Experience with security tool administration (SIEM, EDR, firewall).
- A strong understanding of system hardening and vulnerability management.
- Ability to quickly pivot from preventative work to reactive investigation.
- Interest in understanding attack techniques and adversary behaviour.
- 3
From Network Engineer with Security Focus
3-5 yearsSkills to master
- Endpoint forensics, malware analysis, SIEM/EDR usage, understanding of the full incident response process beyond network events.
You're ready to move on when
- Deep knowledge of network protocols and traffic analysis (Wireshark).
- Experience with firewall rule analysis and network segmentation.
- A desire to apply network knowledge to identify and contain threats.
- Familiarity with common network attack vectors and defence strategies.