The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Vulnerability Management Engineer (L2)
2-3 yearsSkills to master
- Mastering scanner configuration and tuning, independently driving remediation tickets to closure, performing detailed false positive triage, and building basic reporting dashboards.
You're ready to move on when
- Consistently meeting individual remediation SLAs.
- Demonstrating a strong understanding of RBVM principles in daily work.
- Proactively identifying and resolving scanner configuration issues.
- Successfully automating small, repetitive tasks within the VM workflow.
- 2
Security Analyst (Generalist)
3-4 yearsSkills to master
- Developing a broad understanding of various security domains (e.g., incident response, security operations, GRC), then specialising in vulnerability management. This path often brings a wider perspective.
You're ready to move on when
- A clear demonstrated interest and specialisation in vulnerability management.
- Strong analytical skills applied to security data beyond just vulnerabilities.
- Ability to connect vulnerability findings to broader security risks and incidents.
- Proven ability to learn and adapt to new security tools and methodologies quickly.
- 3
DevSecOps Engineer
4-5 yearsSkills to master
- Focusing on embedding security into the CI/CD pipeline, including automated vulnerability scanning, secure coding practices, and infrastructure as code security. This background brings a strong automation and developer-centric view.
You're ready to move on when
- Deep understanding of software development lifecycles and CI/CD pipelines.
- Experience with security tools integrated into developer workflows.
- Strong scripting and automation skills.
- Ability to communicate effectively with development teams.