The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Mid-Level Vulnerability Assessment Specialist
2-3 yearsSkills to master
- Independent execution of routine assessments, initial PoC development, clear reporting of findings, and a solid grasp of CVSS scoring.
You're ready to move on when
- Consistently delivers accurate vulnerability reports with minimal supervision.
- Successfully validates complex findings and can articulate their impact.
- Proactively identifies opportunities for process improvement within their scope.
- Has started informally guiding newer team members.
- 2
Penetration Tester (Junior/Mid-Level)
3-4 yearsSkills to master
- Hands-on experience with various penetration testing tools (e.g., Burp Suite, Metasploit), understanding of common attack vectors, and strong PoC development skills.
You're ready to move on when
- Can execute full penetration tests on web applications or networks independently.
- Consistently finds and exploits vulnerabilities beyond what automated scanners report.
- Produces high-quality, actionable penetration test reports.
- Demonstrates a strong attacker mindset.
- 3
Security Operations Centre (SOC) Analyst L2/L3
4-5 yearsSkills to master
- Deep understanding of threat detection, incident response workflows, SIEM analysis, and the attacker kill chain. This background gives you a great perspective on what *actually* gets exploited.
You're ready to move on when
- Has led incident response efforts for complex security incidents.
- Can analyse and interpret logs from various security tools (firewalls, EDR, IDS/IPS).
- Understands adversary tactics and techniques (MITRE ATT&CK).
- Has a strong desire to transition from defence to offence.