The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Mid-Level Incident Response Specialist (L2)
2-3 years at L2Skills to master
- Leading complex incidents independently, advanced forensic techniques, developing custom detection rules, effective crisis communication, and mentoring junior staff.
You're ready to move on when
- Consistently closing moderately complex incidents without senior oversight.
- Proactively identifying and proposing improvements to IR processes or tools.
- Demonstrating strong analytical skills in post-incident reviews, identifying root causes.
- Actively mentoring new joiners or less experienced colleagues.
- 2
From Senior SOC Analyst (Tier 3)
3-5 years as a Tier 3 SOC AnalystSkills to master
- Deep-dive forensic analysis (beyond log review), incident coordination across multiple teams, understanding the full IR lifecycle (containment, eradication, recovery), and producing executive-level incident reports.
You're ready to move on when
- Consistently triaging and escalating high-fidelity alerts with detailed context.
- Developing complex SIEM queries and detection rules.
- Experience with initial containment actions and evidence preservation.
- A strong desire to move from detection to full response and recovery.
- 3
From Security Engineer with IR Focus
4-6 years in Security Engineering with exposure to incident responseSkills to master
- Practical application of forensic tools, incident management methodologies, crisis communication, and the legal/compliance aspects of incident response.
You're ready to move on when
- Experience building and deploying security tooling that aids in detection or response.
- A strong understanding of system internals and network protocols.
- Actively participating in incident response exercises or real-world incidents from an engineering perspective.
- A desire to shift from building defences to actively engaging with threats.