The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Mid-Level Security Operations Assistant
2-3 yearsSkills to master
- Mastering incident triage, routine vulnerability management tasks, and user access provisioning/deprovisioning. Getting really good at following runbooks and documenting everything.
You're ready to move on when
- Consistently closing tickets within SLAs with high accuracy.
- Proactively identifying and escalating issues before they become critical.
- Demonstrating a solid understanding of core security principles (e.g., least privilege).
- Starting to identify areas for process improvement.
- 2
IT Support Engineer with Security Focus
3-4 yearsSkills to master
- Strong troubleshooting skills, understanding of IT infrastructure, and a growing interest in security. You'd move from fixing general IT issues to focusing on security-related problems.
You're ready to move on when
- Successfully resolving security-related IT issues (e.g., malware removal, access problems).
- Taking initiative to learn about security tools and concepts in your own time.
- Proactively suggesting security improvements for IT systems.
- Demonstrating an analytical approach to problem-solving beyond just following scripts.
- 3
Junior Security Analyst (from another company)
1-2 yearsSkills to master
- Bringing existing security analysis skills and adapting them to our specific tools, processes, and threat landscape. You'd be expected to hit the ground running on investigations.
You're ready to move on when
- Proven track record of incident analysis and response in a previous role.
- Familiarity with common security tools and methodologies.
- Ability to quickly learn new systems and integrate into a new team.
- Clear examples of independent investigation and problem-solving.