The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Vulnerability Assessment Analyst (L2)
2-3 years at L2Skills to master
- Deepening technical expertise in specific attack vectors (e.g., web app, cloud), leading full vulnerability investigations, effectively driving remediation, and informally mentoring new joiners.
You're ready to move on when
- Consistently delivering high-quality, actionable vulnerability reports without significant oversight.
- Proactively identifying and validating complex vulnerabilities beyond basic scanner output.
- Successfully negotiating remediation timelines with development teams.
- Acting as a go-to person for junior analysts' technical questions.
- 2
From Penetration Tester (Junior/Mid-level)
3-5 years in pen testingSkills to master
- Adapting offensive skills to a defensive, remediation-focused context, understanding vulnerability lifecycle management, and integrating with internal development workflows. It's about shifting from 'break it' to 'break it and help fix it'.
You're ready to move on when
- Demonstrable experience in writing clear, reproducible Proofs of Concept.
- Strong understanding of the business impact of vulnerabilities, not just the technical details.
- Ability to work collaboratively with development teams, rather than just delivering a report and walking away.
- Familiarity with vulnerability management platforms and processes.
- 3
From Security Operations Centre (SOC) Analyst (L2/L3)
4-6 years in SOCSkills to master
- Developing a deeper understanding of offensive techniques, manual vulnerability validation, and proactive threat hunting, moving beyond reactive alert triage. You'll need to learn to think like an attacker.
You're ready to move on when
- Strong analytical skills in investigating security incidents and identifying root causes.
- Experience with threat intelligence and its application to proactive defence.
- A keen interest in offensive security and a desire to learn manual testing techniques.
- Ability to translate observed attack patterns into potential vulnerabilities.