The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate Vulnerability Analyst (L1)
1-2 yearsSkills to master
- Mastering basic scan execution, initial finding validation, using ticketing systems, and understanding fundamental network and OS concepts. Learning our internal processes and tools.
You're ready to move on when
- Consistently accurate scan configurations and execution.
- Reliable initial validation of low-to-medium severity findings.
- Proactive in asking questions and seeking to understand 'why' behind vulnerabilities.
- Effective documentation of work following templates.
- 2
IT Security Operations Centre (SOC) Analyst
2-3 yearsSkills to master
- Experience triaging security alerts, understanding attack patterns, incident response basics, and familiarity with security tooling. You'd bring a good understanding of real-time threats.
You're ready to move on when
- Strong analytical skills in investigating security incidents.
- Good understanding of different types of cyber attacks and their indicators.
- Ability to work under pressure and prioritise quickly.
- Interest in proactive threat identification beyond just reacting to alerts.
- 3
Junior Penetration Tester
1-2 yearsSkills to master
- Hands-on experience with exploitation techniques, understanding attack surfaces, and report writing. You'd already have a good 'attacker mindset'.
You're ready to move on when
- Proven ability to find and exploit vulnerabilities in a controlled environment.
- Strong understanding of web application and network security principles.
- Excellent problem-solving skills for bypassing security controls.
- Desire to move into a more programmatic, continuous assessment role.