The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Security Compliance Specialist (L2)
2-4 yearsSkills to master
- Independently managing control testing for specific frameworks (e.g., SOC 2), effectively gathering evidence, and beginning to identify process improvements. You'd be comfortable with the day-to-day operations of compliance.
You're ready to move on when
- Consistently delivering on assigned control testing and evidence collection tasks with minimal supervision.
- Proactively identifying minor control gaps or process inefficiencies.
- Demonstrating strong communication with internal teams and junior auditors.
- Taking ownership of your assigned areas and resolving routine issues independently.
- 2
IT Auditor (Internal/External)
3-5 yearsSkills to master
- Deep understanding of audit methodologies, risk assessment, and control evaluation from an auditor's perspective. You'd be skilled at identifying findings and recommending corrective actions.
You're ready to move on when
- Successfully leading audit engagements and presenting findings to clients or internal stakeholders.
- Strong analytical skills in evaluating control effectiveness and identifying risks.
- Familiarity with various regulatory frameworks and audit standards.
- Ability to translate audit findings into actionable recommendations for technical teams.
- 3
Security Engineer (with Compliance Interest)
4-6 yearsSkills to master
- Hands-on experience with implementing and managing security controls in technical environments (e.g., cloud, network, application security). You'd have a strong technical foundation and an interest in how those controls map to compliance.
You're ready to move on when
- Proven experience in implementing and maintaining security tools and infrastructure.
- Understanding of secure coding practices and SDLC security.
- A clear desire to move into a role that focuses on governance, risk, and compliance, leveraging your technical background.
- Ability to articulate how technical configurations meet specific compliance requirements.