Plot a route
Pick where you are now and where you want to get to. Atlas draws a realistic route, lets you optimise it for time, cost or coding, and explains what each step actually asks of you.
Optimise for
Stretched route, one hop does most of the work
SOC Analyst to Detection Engineer is roughly a £32k step on POST's estimates. A gap that size is not closed by the next certification. It is closed by operating evidence: something you owned, at production scale, that the interview can be taken through end to end. Without that, this is the hop where the route stalls.
IT Support to Detection Engineer is reachable but uncommon. The endpoint depends on org context, timing and trust, not just skill progression.
- Reachability
- Stretch
- Timeline
- ~3–5 years · +£38k · 2 hops
Most people aiming at Detection Engineer stop at: SOC L2 or Defender/Sentinel Engineer. Detection engineering as a discrete seat lives in mature SOCs only; most orgs run their content out of analyst goodwill.
Sigma fluency without a content lifecycle. The interview signal is shipped detections with measured false-positive rates and a test pipeline, not a library of YAML.
Reachable, not typical. Expect timing, org context, and trust to do more of the work than skill progression.
Of the hops on this route, POST rates this one weakest (documented). That makes it the likeliest place for a plan to stall, and it is a judgement about the transition, not a measured failure rate. The cost is named as Biggest risk above.
Salary and time figures are POST practitioner estimates, not survey data.
- BottleneckIT Support↓ SOC AnalystAdjacent pivot
Most SOC analysts come through support, alert triage rewards ticketing instincts.
~1–2y on step·+£6k·documented - Common hopSOC Analyst↓ Detection EngineerSpecialisation
Detection engineering is the natural senior path out of SOC.
TradeoffYou move from reacting to writing the rules others react to. Mistakes are now systemic, not individual.
~2–3y on step·+£32k·common
What the labels on this route mean
- Adjacent pivot
- Cross-domain move documented in real careers. Senior in your old lane, mid-level in the new one for a year or so.
- Pacing: documented
- POST rates this real but not the default: it turns up in career histories without being the obvious next move.
- Specialisation
- Narrower remit within the same domain. You go deeper on one thing and adjacent doors quietly close.
- Pacing: common
- POST rates this a load-bearing transition: the move the rest of the route is built around. A judgement about the transition, not a measured rate.
Most of the calendar time on this route sits here. If you're impatient, this is the step to question.
The full interactive map is easier to explore on a larger screen.
Stretched route, one hop does most of the work
SOC Analyst to Detection Engineer is roughly a £32k step on POST's estimates. A gap that size is not closed by the next certification. It is closed by operating evidence: something you owned, at production scale, that the interview can be taken through end to end. Without that, this is the hop where the route stalls.
Of the hops on this route, POST rates this one weakest (documented). That makes it the likeliest place for a plan to stall, and it is a judgement about the transition, not a measured failure rate. The cost is named as Biggest risk above.
Stretch means the endpoint is reachable but uncommon. Senior architect and leadership roles depend on org politics, trust and timing, not just skill progression. Most people in this domain finish a tier or two below.
Authored steps carry POST's own written rationale. Inferred steps are derived from the shape of the graph alone and deserve stronger scrutiny before you plan around them. Salary and time figures are POST practitioner estimates, not survey data.
- 1IT SupportSOC AnalystAdjacent pivot
Most SOC analysts come through support, alert triage rewards ticketing instincts.
~1–2y on step·+£6k·documented - 2SOC AnalystDetection EngineerSpecialisation
Detection engineering is the natural senior path out of SOC.
TradeoffYou move from reacting to writing the rules others react to. Mistakes are now systemic, not individual.
~2–3y on step·+£32k·common
What the labels on this route mean
- Stretch route, endpoint is ambitious, not typical
- How trustworthy this route is, not just whether it exists. Common means load-bearing. Stretch means possible but slow or org-dependent. Compressed means Fewest steps mode has skipped realistic dwell. Rare means an uncommon hop plus an aspirational endpoint.
- Adjacent pivot
- Cross-domain move documented in real careers. Senior in your old lane, mid-level in the new one for a year or so.
- Pacing: documented
- POST rates this real but not the default: it turns up in career histories without being the obvious next move.
- Specialisation
- Narrower remit within the same domain. You go deeper on one thing and adjacent doors quietly close.
- Pacing: common
- POST rates this a load-bearing transition: the move the rest of the route is built around. A judgement about the transition, not a measured rate.
The next step
You have the route. Now judge whether it holds up for you.
The free route shows what tends to happen. The Career Verdict tests that route against your experience, time and constraints.
A route shows what is possible. A Career Verdict makes the call.
Career Verdict
Helpdesk → Security Architect
- 01The callA clear judgement on whether your route is realistic, and under what conditions.
- 02Where the route breaksThe most likely point to stall, and why it happens in practice.
- 03What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Career Verdict
- The callA single written judgement on whether the route is realistic for you.
- Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
- Where you standThe strongest and weakest parts of your current position, named.
- Salary realityWhat this route actually pays, set against what you've been told it pays.
Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.
Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.