Skip to content
Breaking into cybersecurity

Changing career to cyber security in the UK: routes for career switchers

A cyber security career change in the UK: the four realistic routes, how NCSC schemes and Council titles fit in, and a 90-day plan you can start this week.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 9 min read

A cyber security career change in the UK is realistic, but the people who make it rarely do so by collecting courses. They pick one entry route that matches the experience they already have, build evidence that a hiring manager can check, and learn how the UK’s own professional structure (the NCSC and the UK Cyber Security Council) shapes the senior roles they will eventually want.

This guide is written for two groups: people already living and working in the UK who want out of their current field, and diaspora readers, including many Nigerians, who are planning a move or have recently arrived. The routes are the same; the paperwork differs, and we cover both.

We deliberately leave out salary and job-market figures. Numbers quoted online for the UK vary wildly by source and date, and you will make a better decision from job adverts in your own city than from a headline statistic.

Is cyber security a good career change in the UK?

It can be, if you go in with the right expectations. The honest version:

  • The work is real and varied. Security operations, governance and risk, security testing, cloud security, identity, incident response and audit are all distinct jobs with distinct days.
  • “Entry level” is a contested term. Many adverts labelled junior still ask for some IT background. Career changers usually do best by entering through a role adjacent to what they already know, then moving sideways.
  • Your previous career is an asset, not a gap. A former nurse understands clinical systems and patient data. A former accountant already thinks in controls and evidence. A former teacher can explain risk to a room. Those are hiring arguments.
  • Nothing guarantees a job, including any course, bootcamp or certification. Anyone promising otherwise is selling something.

If you want the general version of this advice, not tied to the UK, start with our roadmap on how to get into cybersecurity with no experience. If age is the worry, read switching to cybersecurity at 30, 40 or later.

The UK bodies you should know about

Two organisations shape how the UK thinks about cyber security skills. You don’t need either of them to land a first job, but understanding them helps you read job adverts and plan the longer game.

The NCSC

The National Cyber Security Centre is part of GCHQ and is the UK’s technical authority for cyber security. For a career changer, three things matter:

  1. NCSC Assured Training. The NCSC assesses training courses against its own criteria, mapped to the Cyber Security Body of Knowledge (CyBOK). It certifies courses at an Awareness level for newcomers and an Application level for deeper professional development. If you are choosing a paid UK course, check whether it appears in the NCSC Assured Training listings. Assured status is not a hiring guarantee, but it tells you an independent body has checked the content.
  2. The CHECK scheme. CHECK is how NCSC-approved companies carry out penetration tests on government and critical systems. It matters because it sets the bar for a lot of UK testing work (more on this below).
  3. Free guidance. The NCSC’s public guidance (Cyber Essentials, the small business guide, the 10 Steps to Cyber Security) is excellent study material. Reading it teaches you the vocabulary UK employers use.

The UK Cyber Security Council

The UK Cyber Security Council is the body for professional standards in the field. It does two things worth knowing about:

  • Professional registration titles. The Council awards four titles: Associate, Practitioner, Principal and Chartered Cyber Security Professional. The Associate title is not tied to a specialism; the higher three are held against a chosen specialism.
  • The Cyber Career Framework. This describes 16 specialisms, from security testing and incident response to governance and risk management, with the knowledge and typical roles in each. It’s one of the best free tools for working out what a job actually involves before you commit to it. The Council lists which specialisms are currently open for registration; check the page, as the list has grown over time.

A note if you’ve seen “CCP” in older articles: the NCSC’s Certified Cyber Professional scheme has closed to new applicants; existing CCP certifications stay recognised only until the last ones expire in December 2026, and the Council’s titles are the route forward. Older blog posts often haven’t caught up.

Four realistic routes for a UK career switcher

Most successful switchers use one of these four routes. Pick the one closest to the experience you already have.

Your background Most natural entry route First roles to look at What to build first
IT support, networking, sysadmin Security operations (SOC) SOC analyst, security operations, junior security engineer Log analysis, SIEM basics, Security+ level knowledge
Audit, compliance, finance, law, healthcare admin, project management Governance, risk and compliance (GRC) GRC analyst, information security officer, third-party risk analyst ISO 27001, NIST CSF, Cyber Essentials, risk registers
Software development, QA, DevOps Application or cloud security AppSec engineer, DevSecOps, security-minded developer OWASP Top 10, secure code review, cloud IAM
Strong technical curiosity, no IT job yet IT first, security second Service desk, junior infrastructure, then SOC Networking, Linux, Windows administration, home lab

The fourth route is the one people resist, because it feels like a detour. It isn’t. A year on a service desk teaches you Active Directory, ticketing discipline, how users actually behave and how a real network is laid out. Those are exactly the things a SOC analyst needs on day one.

Route 1: security operations

SOC work suits people who like patterns, logs and puzzles. You triage alerts, investigate suspicious activity and escalate genuine incidents. The knowledge base overlaps heavily with CompTIA Security+ (SY0-701), whose largest domain, Security Operations, carries 28% of the exam weighting. Our Security+ SY0-701 study guide has a full plan. CompTIA expects a new Security+ version to launch on or around 17 November 2026, while SY0-701 remains available for now, so check CompTIA’s Security+ page for the current version before you book.

What a hiring manager wants to see: evidence that you have investigated something. Write up a home-lab investigation of a simulated brute-force attack against your own virtual machine, with the log lines, what you concluded and what you would recommend.

Route 2: governance, risk and compliance

GRC is the route most often overlooked by career changers who assume cyber security means hacking. If you’ve worked in audit, finance, healthcare governance, legal or project delivery, you already handle policies, evidence and risk. GRC adds the security frameworks: ISO/IEC 27001, the NIST Cybersecurity Framework and, in the UK specifically, Cyber Essentials.

What to build: a small, realistic artefact. For example, a risk register and a short Statement of Applicability for a fictional ten-person company, or a gap assessment of that company against the Cyber Essentials requirements. One well-reasoned document beats ten course certificates.

Route 3: application and cloud security

Developers have a strong position. Security teams need people who can read code and talk to engineering teams without friction. Start with the OWASP Top 10, run vulnerable practice apps in your own lab, and learn how identity and permissions work in whichever cloud your current employer uses. Internal moves are common here: volunteering for security tasks in your current team is often the fastest route of all.

Route 4: IT first

If you have no IT background, the dependable route is a first IT job, then a move into security within the same organisation or the next one. Build a home lab alongside: a couple of virtual machines, a firewall, a log collector. Document everything on a simple blog or GitHub.

How to become a penetration tester in the UK

Penetration testing gets the most attention and has the steepest ladder, so it deserves its own section.

The UK has a well-defined professional structure for testers. Under the NCSC’s current CHECK scheme requirements, CHECK Team Members must hold at least the UK Cyber Security Council’s Practitioner title in the Security Testing specialism, CHECK Team Leaders must hold at least the Principal title, and both need valid SC (Security Check) clearance. Not every testing job is CHECK work, but this tells you where the profession’s senior end sits: recognised competence, assessed by a professional body, plus vetting.

For a career changer, that implies a sequence:

  1. Get the foundations solid. Networking, Linux, Windows and Active Directory, web fundamentals. There’s no shortcut.
  2. Practise legally. Use your own lab and deliberately vulnerable platforms. Only test systems you own or have written permission to test; the Computer Misuse Act 1990 applies to everyone, including learners.
  3. Take an industry certification when you’re ready, such as CompTIA PenTest+ (PT0-003) or an equivalent practical exam, so there’s an externally assessed signal on your CV.
  4. Enter adjacent if needed. Many UK testers started in SOC, infrastructure or development roles and moved into a testing team.
  5. Plan for professional registration once you have experience to evidence, using the Council’s Security Testing specialism.

Our guide on how to become a penetration tester from scratch goes into the skills in more depth.

Notes for diaspora readers moving to the UK

If you’re relocating from Nigeria or elsewhere, three practical points:

  • Right to work comes first. Employers must check it before you start. If you need sponsorship, read the official Skilled Worker visa guidance yourself rather than relying on social media summaries; the rules change, and the gov.uk page is the only version that counts.
  • Security clearance can take time. Government, defence and CHECK work often requires vetting, which has residency and background requirements. If you have recently arrived, focus first on private-sector roles where clearance isn’t required, and read the gov.uk national security vetting guidance before applying for cleared roles.
  • Your overseas experience counts. IT, banking, telecoms and fintech experience gained in Lagos or Abuja is directly relevant. Describe it in terms UK employers recognise: the size of the environment, the controls you ran, the frameworks you worked to (ISO 27001 is international; PCI DSS applies wherever card data is handled).

Certifications from CompTIA and similar bodies are recognised internationally, which is one reason career changers on the move often start there. Remember the distinction: a course certificate shows you finished a course; a certification is an exam-based credential from a certifying body. Employers weigh them differently.

A 90-day plan you can start this week

This plan assumes around eight to ten hours a week alongside a job.

Days 1–14: decide.

  • Read three or four specialisms in the Council’s Cyber Career Framework and choose one route from the table above.
  • Collect 15 real job adverts for your target role in your area. Highlight the skills that appear in more than half of them. That list is your syllabus.

Days 15–60: build.

  • Study the core knowledge for your route (for SOC and general roles, Security+ objectives are a sensible map).
  • Build a small home lab. Two virtual machines and a log collector is enough to start.
  • Produce one artefact a fortnight: an investigation write-up, a risk register, a hardening checklist, a secure code review of a practice app.

Days 61–90: show and connect.

  • Rewrite your CV around transferable skills plus your three best artefacts. Keep it to two pages.
  • Join a local security meetup or a BSides event and talk to people doing the job you want.
  • Apply internally first if your employer has a security team. Internal transfers skip a lot of the screening that filters out career changers.

Common mistakes career switchers make

  • Course stacking. Five introductory certificates say less than one strong project.
  • Ignoring GRC. Many changers would be better suited to governance work but never consider it.
  • Hiding the old career. Your domain knowledge is your differentiator. Put it on the first half of page one.
  • Testing without permission. Scanning a website you don’t own “to practise” can be a criminal offence. Use your own lab.
  • Trusting stale advice. Schemes change. Check the NCSC and Council pages directly before you plan around any title or certification.

Questions

Can I change to cyber security in the UK without a degree?

Yes. Many roles ask for skills and evidence rather than a specific degree, and professional registration with the UK Cyber Security Council is based on assessed competence. Some graduate schemes do require a degree, so read each advert.

Which certification should a UK career changer start with?

For most technical routes, CompTIA Security+ (SY0-701) is a well-recognised, vendor-neutral starting point. GRC changers may prefer to pair foundational knowledge with framework study such as ISO 27001.

Do I need security clearance to get my first job?

No. Many private-sector roles don't require it. Clearance becomes relevant for government, defence and CHECK work.

Is the NCSC's CCP certification still worth getting?

No. The scheme is closed to new applicants and the last existing CCP certifications expire in December 2026. Look at the UK Cyber Security Council's professional titles instead.