The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Cloud Security Analyst (L2)
2-3 yearsSkills to master
- Independently managing alert queues, performing initial incident triage, contributing to documentation, and validating vulnerability findings. You'd be comfortable with routine tasks and starting to identify areas for improvement.
You're ready to move on when
- Consistently closing security tickets accurately and efficiently.
- Proactively identifying and proposing solutions for minor security issues.
- Demonstrating a strong understanding of our cloud environments and security tools.
- Receiving positive feedback on your ability to work independently on assigned tasks.
- 2
Security Operations Centre (SOC) Analyst (L2-L3)
3-5 yearsSkills to master
- Deep experience in threat detection, incident analysis, and using SIEM tools. You'd have a strong foundation in identifying and responding to a wide range of security incidents across different platforms, now looking to specialise in cloud.
You're ready to move on when
- Proven track record of leading complex incident investigations in a SOC environment.
- Expertise in SIEM query languages and building custom detection rules.
- Strong understanding of attacker TTPs and how to detect them.
- Eagerness to specialise and apply your broad security knowledge specifically to cloud environments.
- 3
DevOps Engineer with Security Focus (L2-L3)
4-6 yearsSkills to master
- Solid understanding of cloud infrastructure, CI/CD pipelines, and automation, with a growing interest in security. You'd be familiar with building and deploying cloud applications and now want to secure them from the ground up.
You're ready to move on when
- Demonstrated ability to build and manage cloud infrastructure using IaC (Terraform, CloudFormation).
- Experience integrating security tools into CI/CD pipelines.
- A strong desire to 'shift left' security and embed it into the development process.
- Recognised as the 'security conscience' within your current DevOps team.