The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Cybersecurity Support Analyst (Level 2)
2-3 yearsSkills to master
- Independent incident handling for routine alerts, strong log analysis fundamentals, basic threat hunting, and effective use of our core security tools.
You're ready to move on when
- Consistently closing incidents within SLA without significant oversight.
- Proactively identifying and documenting false positives for tuning.
- Demonstrating a curious mindset, digging deeper than just closing tickets.
- Reliably contributing to team knowledge sharing and documentation.
- 2
IT Security Engineer / Junior Incident Responder (from another organisation)
Varies (often 3-5 years)Skills to master
- Adapting to our specific tech stack and processes, understanding our threat landscape, and integrating into our team's incident response methodology.
You're ready to move on when
- Proven experience in a similar hands-on security role, even if the tools were different.
- Strong foundational knowledge of incident response and security operations.
- A quick learner who can pick up new tools and processes rapidly.
- Ability to work collaboratively and share knowledge effectively.
- 3
Network/Systems Administrator with Security Focus
Varies (often 4-6 years)Skills to master
- Transitioning from an operational mindset to a security-first incident response mindset, deepening knowledge of attack vectors, and mastering security-specific tools.
You're ready to move on when
- Demonstrated strong interest and self-study in cybersecurity.
- Experience implementing security controls in a previous role.
- A solid understanding of system internals and network protocols.
- Ability to apply operational knowledge to security investigations.