The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Security Engineer (L2)
2-3 years at L2Skills to master
- Moving from owning specific tools to leading projects, designing solutions, and influencing cross-functional teams. You'll need to develop stronger communication and project management skills.
You're ready to move on when
- Consistently delivering high-quality work on complex security systems.
- Proactively identifying and proposing solutions to security gaps, not just executing tasks.
- Taking initiative to mentor new joiners or lead informal technical discussions.
- Demonstrating strong problem-solving skills for non-routine security challenges.
- 2
From Senior Security Consultant (External)
Direct entry, assuming relevant experienceSkills to master
- Adapting to our specific technical environment and culture, building internal relationships, and transitioning from advisory to hands-on implementation and ownership.
You're ready to move on when
- Experience leading security projects for multiple clients.
- Strong technical depth in several security domains.
- Ability to quickly understand new technical landscapes and identify risks.
- Proven ability to influence stakeholders and drive security outcomes.
- 3
From Lead Developer / DevOps Engineer with Security Specialisation
3-5 years in development/DevOps + 2-3 years security focusSkills to master
- Deepening your security expertise across all domains, moving from 'secure coding' to broader architectural security, incident response, and GRC. You'll need to broaden your perspective beyond just application security.
You're ready to move on when
- Consistently building secure applications and infrastructure.
- Actively participating in threat modelling and security reviews within your development team.
- Taking ownership of security-related issues in your projects.
- A clear passion for moving into a dedicated security role.