The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From SOC Analyst II / Incident Analyst
3-5 years as an Incident AnalystSkills to master
- Leading complex incidents end-to-end, developing new detection rules, mentoring junior colleagues, and improving incident response processes. You're moving from 'doing' to 'leading and improving'.
You're ready to move on when
- Consistently resolving Tier 2 incidents without escalation.
- Proactively identifying and proposing solutions for recurring security issues.
- Demonstrating strong analytical skills during post-incident reviews.
- Providing informal guidance and support to newer team members.
- 2
From Security Consultant (with hands-on IR experience)
5-7 years in consulting, with a focus on incident response or security operations.Skills to master
- Adapting consulting frameworks to an in-house operational environment, building long-term internal relationships, and shifting from advisory to direct execution and leadership.
You're ready to move on when
- Experience leading client incident response engagements.
- Ability to translate external best practices into internal operational improvements.
- Strong communication skills for diverse internal stakeholders.
- Desire to be hands-on with tools and incidents daily.
- 3
From a Specialised Security Role (e.g., Threat Hunter, Forensics Analyst)
4-6 years in a specialised role, with a desire for broader operational leadership.Skills to master
- Broadening your technical scope beyond your specialism, developing team leadership and mentorship skills, and understanding the full incident lifecycle beyond just detection or forensics.
You're ready to move on when
- Deep expertise in a specific security domain (e.g., endpoint forensics, malware analysis).
- Demonstrated ability to apply specialised knowledge to improve overall security operations.
- Interest in mentoring and developing others in your area of expertise.
- A desire to lead and coordinate broader incident response efforts.