The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Cybersecurity Engineer (L2) Internal Promotion
2-3 years as an L2Skills to master
- Mastering Tier 2 incident response, independently operating core security tools, beginning to tune detection rules, and informal guidance of new joiners.
You're ready to move on when
- Consistently resolving complex incidents without escalation.
- Proactively identifying areas for security tool optimisation.
- Demonstrating strong analytical skills in vulnerability prioritisation.
- Receiving positive feedback from managers and peers on technical contributions.
- 2
Experienced Security Analyst from another Organisation
Direct entry with 5-8 years experienceSkills to master
- Adapting to our specific tech stack and processes, understanding our unique threat landscape, building relationships with key internal stakeholders.
You're ready to move on when
- Proven track record of leading security projects and incidents in previous roles.
- Strong technical skills aligning with our core competencies (SIEM, EDR, Python).
- Demonstrable ability to work autonomously and make sound technical decisions.
- Excellent communication skills for cross-functional collaboration.
- 3
DevSecOps Engineer Transition
3-5 years as a DevSecOps Engineer + 1-2 years focused on security operationsSkills to master
- Deepening incident response skills, threat hunting, vulnerability management beyond just CI/CD, and understanding the 'attacker's mindset' more broadly.
You're ready to move on when
- Strong background in secure coding and CI/CD pipeline security.
- Demonstrated ability to identify and remediate security flaws in applications and infrastructure.
- A clear passion for defensive security and a willingness to learn incident response techniques.
- Experience with security automation and infrastructure-as-code.