The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Junior SOC Analyst
2-3 yearsSkills to master
- Incident triage, log analysis, understanding attack patterns, basic threat intelligence. You'd have seen plenty of 'alerts' and now want to understand the root cause.
You're ready to move on when
- You're constantly asking 'why did this alert fire?' and 'how could this have been prevented?'
- You've taken the initiative to research CVEs related to alerts you've handled.
- You're comfortable with command-line tools and basic scripting for log parsing.
- 2
IT Support Engineer (with Security Focus)
3-4 yearsSkills to master
- Operating system administration, network troubleshooting, understanding user permissions, basic security configurations. You've been on the 'fix-it' side and now want to prevent the breaks.
You're ready to move on when
- You've been involved in patching cycles and understand the impact of vulnerabilities.
- You're the person who always checks for default passwords or insecure configurations.
- You've got a strong grasp of system internals and how they interact.
- 3
Junior Developer (with Security Interest)
2-4 yearsSkills to master
- Coding practices, understanding application architecture, debugging, identifying common coding flaws. You know how software is built and now want to find its weaknesses.
You're ready to move on when
- You've taken courses or read books on secure coding practices (e.g., OWASP Top 10 for developers).
- You're interested in how code vulnerabilities are exploited, not just how to fix bugs.
- You're comfortable reading and understanding different programming languages.