Skip to main content
Security architecture

Security Architect (after 7+ years)

Design the trust boundaries. Pursued after 7+ years of hands-on work, not as a starting lane.

Last reviewed May 2026Reviewed by a practitioner working in senior security engineer → security architect hiringUpdated quarterly against live job listings
The verdict

A real job, not a starting lane. Pursued after seven or more years of hands-on work, and the people who try to skip there end up running PowerPoints rather than designing systems.

You've built and broken production systems for years, you can hold a threat model and a budget in the same conversation, and you're done with hands-on day-to-day work.

You're trying to use it as a fast track. There isn't one. Architects who haven't done the engineering get exposed by their own designs inside six months.

Phased progression

Foundations → first role → specialisation → advanced. The realistic order, not a script.

  1. 01Foundations
    0–6 months

    Literacy, lab habits, the cert that opens first conversations.

    CISSP
  2. 02First paid role
    6–18 months

    Land a Senior Security Engineer → Security Architect. Operational time, not more certs, earns the next move.

    Senior Security Engineer → Security Architect
    £90–125k security architect
  3. 03Specialisation
    1.5–3 years

    Add a specialist credential aligned to the work you're already doing.

    SC-100CCSP
    £125–160k principal / head of (UK; FAANG / US-listed banks higher)
  4. 04Advanced
    3+ years

    Move into adjacent roles. Long-term credentials become worth their cost.

    Enterprise ArchitectTOGAF
    £125–160k principal / head of (UK; FAANG / US-listed banks higher)

Certification sequence

Ordered by realistic relevance, not vendor marketing.

  • CCSP
  • SABSA

Practical projects

What to actually build, the portfolio that opens interviews.

  • Author one reference architecture for a real product
  • Threat-model a real system with STRIDE or LINDDUN
  • Drive one cross-team security control to production
Enterprise ArchitectSecurity ManagerPlatform Security Engineer
  • ·GRC-led management track
  • ·Platform security from the inside

Realistic expectations

What no recruiter will tell you.

Misconception

That CISSP makes you an architect. CISSP gets your CV past the filter for the role. The job itself is years of judgment, scar tissue and the ability to say no to the business without losing the room.

Honest window

Seven years plus from a senior engineering seat is the honest floor. Some people take a decade. The route doesn't reward shortcuts.

Where this fits

A pathway is a sequence, not a destination. Here are the roles and certs along it.

The next step

The pathway is plausible. Whether it holds for five years is a different question.

A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.