The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Junior Vulnerability Analyst / Associate Security Analyst
1-2 yearsSkills to master
- Basic vulnerability scanning, initial triage of low-severity findings, understanding of CVSS, clear documentation, following established procedures.
You're ready to move on when
- Consistently accurate in basic vulnerability identification and reporting.
- Can independently run and interpret standard vulnerability scans.
- Demonstrates a proactive approach to learning new security concepts.
- Receives positive feedback on communication and teamwork.
- 2
IT Support Engineer / System Administrator with Security Focus
2-3 yearsSkills to master
- Deep understanding of operating systems (Windows/Linux), networking, troubleshooting, patch management, exposure to security incidents and basic hardening techniques.
You're ready to move on when
- Has actively participated in resolving security-related issues in their previous role.
- Shows a strong interest in moving from general IT to a dedicated security function.
- Can demonstrate practical experience with system hardening and vulnerability remediation.
- Has taken initiative to learn security tools or concepts in their own time.
- 3
Network Engineer with Security Exposure
2-4 yearsSkills to master
- In-depth knowledge of network protocols, firewalls, intrusion detection/prevention systems, network segmentation, and understanding of network-based attack vectors.
You're ready to move on when
- Has configured and managed network security devices.
- Can analyse network traffic for suspicious activity.
- Understands how network architecture impacts overall security posture.
- Is comfortable with tools like Nmap and Wireshark.