Security Architect (after 7+ years)
Design the trust boundaries. Pursued after 7+ years of hands-on work, not as a starting lane.
A real job, not a starting lane. Pursued after seven or more years of hands-on work, and the people who try to skip there end up running PowerPoints rather than designing systems.
You've built and broken production systems for years, you can hold a threat model and a budget in the same conversation, and you're done with hands-on day-to-day work.
You're trying to use it as a fast track. There isn't one. Architects who haven't done the engineering get exposed by their own designs inside six months.
Phased progression
Foundations → first role → specialisation → advanced. The realistic order, not a script.
- 010–6 monthsFoundations
Literacy, lab habits, the cert that opens first conversations.
CISSP - 026–18 monthsFirst paid role
Land a Senior Security Engineer → Security Architect. Operational time, not more certs, earns the next move.
Senior Security Engineer → Security Architect£90–125k security architect - 031.5–3 yearsSpecialisation
Add a specialist credential aligned to the work you're already doing.
SC-100CCSP£125–160k principal / head of (UK; FAANG / US-listed banks higher) - 043+ yearsAdvanced
Move into adjacent roles. Long-term credentials become worth their cost.
Enterprise ArchitectTOGAF£125–160k principal / head of (UK; FAANG / US-listed banks higher)
- 01Foundations0–6 months
Literacy, lab habits, the cert that opens first conversations.
CISSP - 02First paid role6–18 months
Land a Senior Security Engineer → Security Architect. Operational time, not more certs, earns the next move.
Senior Security Engineer → Security Architect£90–125k security architect - 03Specialisation1.5–3 years
Add a specialist credential aligned to the work you're already doing.
SC-100CCSP£125–160k principal / head of (UK; FAANG / US-listed banks higher) - 04Advanced3+ years
Move into adjacent roles. Long-term credentials become worth their cost.
Enterprise ArchitectTOGAF£125–160k principal / head of (UK; FAANG / US-listed banks higher)
Certification sequence
Ordered by realistic relevance, not vendor marketing.
Practical projects
What to actually build, the portfolio that opens interviews.
- Author one reference architecture for a real product
- Threat-model a real system with STRIDE or LINDDUN
- Drive one cross-team security control to production
- ·GRC-led management track
- ·Platform security from the inside
Realistic expectations
What no recruiter will tell you.
That CISSP makes you an architect. CISSP gets your CV past the filter for the role. The job itself is years of judgment, scar tissue and the ability to say no to the business without losing the room.
Seven years plus from a senior engineering seat is the honest floor. Some people take a decade. The route doesn't reward shortcuts.
Where this fits
A pathway is a sequence, not a destination. Here are the roles and certs along it.
- Is CISSP actually worth it in 2026?
Yes, but only for a specific person at a specific moment. For everyone else it's 12–18 months optimising for the wrong thing.
- The hidden downside of a GRC career
In progress. GRC is one of the calmest, best-paid entries into security. It also quietly closes doors you may not realise you wanted open.
The next step
The pathway is plausible. Whether it holds for five years is a different question.
A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.
A route shows what people usually do. A Career Verdict judges whether it's realistic for you.
A Career Verdict includes
Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.