The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate Vulnerability Analyst
1-2 yearsSkills to master
- Basic scanner operation, initial triage, ticket creation, foundational understanding of CVEs and CVSS.
You're ready to move on when
- Consistently accurate in initial vulnerability triage and ticket creation.
- Can run scheduled scans independently and troubleshoot basic issues.
- Demonstrates a proactive attitude to learning new vulnerability types and tools.
- Receives positive feedback on communication with remediation teams.
- 2
Security Operations Centre (SOC) Analyst
2-3 yearsSkills to master
- Incident response, threat detection, log analysis, understanding of attack methodologies, which directly informs vulnerability prioritisation.
You're ready to move on when
- Strong understanding of how vulnerabilities are exploited in real-world attacks.
- Experience with various security tools (SIEM, EDR) and correlating data.
- Ability to work under pressure during security incidents.
- A desire to shift from reactive defence to proactive risk reduction.
- 3
IT Systems Administrator / Engineer (with security focus)
3-4 yearsSkills to master
- Deep understanding of system hardening, patching processes, network configurations, and infrastructure management. This practical experience is invaluable for understanding remediation challenges.
You're ready to move on when
- Proven track record of managing and securing IT infrastructure.
- Excellent troubleshooting skills for system and network issues.
- A strong interest in moving from implementing security controls to actively identifying and managing weaknesses.
- Understands the operational impact of security changes.