The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Mid-Level IoT Security Specialist
2-3 years of growthSkills to master
- Independently conducting full device security assessments, writing clear vulnerability reports, foundational firmware reverse engineering, basic hardware debugging.
You're ready to move on when
- Consistently delivering high-quality, independent security assessments for individual IoT devices.
- Demonstrating initiative in learning new attack techniques and tools without constant supervision.
- Successfully mentoring junior colleagues on specific technical tasks.
- Proactively identifying areas for process improvement within assessments.
- 2
Experienced Penetration Tester (with Embedded Focus)
3-5 years of transitionSkills to master
- Deepening knowledge of embedded systems, real-time operating systems (RTOS), hardware hacking techniques, and IoT-specific protocols (e.g., Zigbee, LoRaWAN).
You're ready to move on when
- Moving beyond network/web app pen testing to actively seeking out hardware and firmware vulnerabilities.
- Building a home lab and experimenting with microcontroller security and hardware interfaces.
- Demonstrating a strong understanding of the unique constraints and attack surfaces of resource-limited devices.
- Successfully completing embedded security CTFs or personal projects.
- 3
Embedded Systems Engineer (with Security Passion)
4-6 years of transitionSkills to master
- Shifting from building secure systems to actively breaking them, developing an offensive security mindset, learning reverse engineering tools and techniques, and understanding common exploitation methods.
You're ready to move on when
- Actively participating in security code reviews and identifying potential vulnerabilities in their own or others' embedded code.
- Taking online courses or certifications in offensive security (e.g., OSCP, eJPT).
- Demonstrating a strong interest in vulnerability research and ethical hacking.
- Proactively identifying security flaws in existing products or personal projects.