The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Mid-Level Network Security Administrator/Engineer
3-5 years in previous roleSkills to master
- Independent management of security appliances, routine incident handling, basic policy implementation, and proactive monitoring. You'd be solid on the fundamentals and ready to take on more complex challenges.
You're ready to move on when
- Successfully managed a significant security appliance (e.g., a firewall cluster) end-to-end.
- Consistently resolved security incidents without senior intervention for routine issues.
- Demonstrated ability to identify and propose solutions for security weaknesses.
- Actively sought out learning opportunities and new responsibilities.
- 2
Security Operations Centre (SOC) Analyst (Level 2/3)
4-6 years in previous roleSkills to master
- Deep understanding of threat detection, incident triage, log analysis, and SIEM query writing. You'd be excellent at spotting anomalies and understanding attack patterns, ready to move into designing the defences.
You're ready to move on when
- Led investigations for complex security alerts, not just triaged them.
- Developed custom SIEM rules or threat hunting queries.
- Provided training or guidance to junior SOC analysts.
- Demonstrated a strong interest and foundational knowledge in network infrastructure.
- 3
Systems Administrator with a Strong Security Focus
5-7 years in previous roleSkills to master
- Deep expertise in operating systems, infrastructure management, and a demonstrable passion for securing those systems. You'd have moved beyond basic admin tasks into hardening and defending infrastructure.
You're ready to move on when
- Implemented significant security hardening projects for servers or cloud infrastructure.
- Actively participated in incident response for system-level breaches.
- Obtained security certifications (e.g., CompTIA Security+, CySA+).
- Can clearly articulate how system-level security impacts network security.