The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Mid-Level Information Security Analyst (L2)
2-3 yearsSkills to master
- Independently managing low-to-medium severity incidents, interpreting vulnerability scan results, basic log analysis, and following established incident response playbooks.
You're ready to move on when
- Consistently closing incidents accurately and efficiently without supervision.
- Proactively identifying improvements to existing security processes.
- Being the 'go-to' person for complex L2 alerts or questions from junior analysts.
- 2
IT Systems Administrator with Security Focus
3-5 yearsSkills to master
- Deep understanding of operating systems (Windows/Linux), networking, system hardening, and practical experience with security tools from an operational perspective. You've managed the systems you're now trying to defend.
You're ready to move on when
- Demonstrable experience implementing security controls on servers and networks.
- Strong troubleshooting skills for system and network issues, often with a security angle.
- A clear passion for moving from general IT to dedicated security roles, evidenced by self-study or certifications.
- 3
Network Engineer with Security Specialisation
3-5 yearsSkills to master
- Expertise in network architecture, firewalls, intrusion detection/prevention systems (IDS/IPS), and secure network design. You understand network traffic patterns like the back of your hand.
You're ready to move on when
- Designing and implementing secure network segments and access controls.
- Experience configuring and managing network security devices.
- Ability to analyse network packet captures to identify malicious activity.