The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior SOC Analyst / Incident Responder (L3)
3-5 years at L3Skills to master
- Leading complex incident investigations, developing advanced detection rules, mentoring junior analysts, strong understanding of MITRE ATT&CK and threat hunting basics.
You're ready to move on when
- Consistently leading P1/P2 incidents to successful resolution with minimal supervision.
- Proactively identifying and closing detection gaps, not just reacting to alerts.
- Demonstrating strong communication skills during incident calls and post-mortems.
- Receiving positive feedback from junior analysts on your mentorship and guidance.
- 2
Security Engineer (focused on Detection & Response)
4-6 years in Security EngineeringSkills to master
- Deep expertise in SIEM/SOAR engineering, building and maintaining security infrastructure, automating security tasks, strong scripting skills (Python), understanding of security architecture.
You're ready to move on when
- Successfully deployed and optimised major security tools (SIEM, EDR, SOAR) in a production environment.
- Developed robust automation scripts that significantly reduced manual security tasks.
- Can articulate the 'why' behind security architecture decisions and their impact on detection.
- Desire to move from building tools to leading the operational use of those tools in a high-pressure environment.
- 3
Threat Intelligence Analyst (Senior)
3-5 years in Threat IntelligenceSkills to master
- Advanced threat actor profiling, intelligence collection and analysis, producing actionable intelligence reports, integrating intel into security tools, understanding of adversary TTPs.
You're ready to move on when
- Consistently produced high-quality, actionable threat intelligence relevant to the organisation.
- Successfully integrated threat intel feeds to improve detection capabilities.
- Can clearly articulate threat actor motivations and capabilities to a technical audience.
- Desire to apply intelligence directly to active defence and lead hunting operations.