The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Incident Response Engineer (L2)
2-3 years at L2Skills to master
- Leading routine incidents independently, developing strong forensic analysis skills, starting to build custom SIEM queries and EDR detections, and providing informal guidance to new joiners.
You're ready to move on when
- Consistently handles routine incidents without supervision, from start to finish.
- Can perform basic host-based and network forensics to identify initial compromise.
- Proactively identifies areas for improvement in existing playbooks or detection rules.
- Is sought out by junior analysts for technical advice on specific tools or techniques.
- 2
From Senior SOC Analyst
3-5 years as a Senior SOC AnalystSkills to master
- Deepening forensic analysis skills, gaining hands-on experience with advanced EDR/XDR platforms, developing scripting for automation, and understanding the full incident lifecycle beyond just detection and initial triage.
You're ready to move on when
- Has consistently handled complex, multi-stage alerts and performed initial scoping.
- Can demonstrate strong SIEM query and data analysis skills for threat detection.
- Has a good understanding of common attacker TTPs and how to map them to MITRE ATT&CK.
- Shows a proactive mindset, moving beyond alert-driven work to hypothesis-based investigation.
- 3
From Security Consultant (DFIR focus)
4-6 years in a DFIR consulting roleSkills to master
- Adapting to an internal, long-term security posture focus rather than project-based work, building internal stakeholder relationships, and contributing to ongoing detection and response improvements.
You're ready to move on when
- Demonstrates extensive experience across various incident types and industries.
- Can quickly integrate into an existing IR team and contribute immediately.
- Understands the nuances of internal vs. external incident response.
- Shows a desire to build and mature an internal security capability.