After reviewing hundreds of cyber security CVs, five career decisions consistently separate future CISOs and Heads of Security from those who plateau at mid-level.
← Back to Insights
We review hundreds of cyber security CVs every month. After a while, you start to notice what separates the people who end up as Heads of Security or CISOs from the ones who plateau at senior analyst or team lead. It’s rarely the certifications. It’s almost never the degree. It’s a handful of career decisions that compound over time.
These aren’t obvious moves. Some of them look like sideways steps or even backwards ones at the time. But they show up again and again in the careers of the people who end up running security functions in CNI.
Every senior security leader we place who’s genuinely good at the job has spent time close to operations. Not managing a dashboard. Not writing policy. Actually dealing with incidents, or sitting in an OT environment, or working in a SOC at 2am when something was on fire.
The career path that looks efficient on paper – graduate scheme, analyst, senior analyst, manager, head of – often produces leaders who’ve never felt the weight of a real incident. The ones who took a sideways step into an incident response role, or volunteered for the overnight SOC rotation, or spent two years in an OT environment when everyone else was chasing cloud security roles, tend to carry a credibility that’s hard to fake.
If you’re three to five years into your career and wondering what separates you from the next level, look at the roles your peers are avoiding. There’s probably something useful in there.
There’s a gravitational pull in cyber security towards large organisations. Big banks, big consultancies, big government departments. The brand names look good on a CV and the structures feel safe.
But the people who progress fastest tend to have at least one stint at a smaller organisation on their record. A mid-size company where they were one of two or three security people. A growing business where they had to build something rather than maintain something. An environment where they couldn’t escalate a problem – they had to solve it, because there was nobody above them to escalate to.
That experience forces a breadth that large organisations don’t. In a team of forty, you can spend three years doing vulnerability management and nothing else. In a team of three, you’re doing vulnerability management on Monday and briefing the board on Thursday. The people who’ve done both bring a different kind of judgement to senior roles.
The CISO candidates we see who stand out in interviews are the ones who can talk about their sector, not just their specialism. They understand how energy trading works, or how water treatment processes operate, or why a particular regulatory regime matters to their board.
This usually comes from curiosity rather than formal training. They spent time with the operational teams. They sat in on commercial meetings. They asked questions about parts of the business that had nothing to do with security – and then connected those dots back to risk in ways that pure security specialists don’t.
If you’re in CNI security and you’ve never spent a day with the engineers who run the infrastructure you’re protecting, that’s a gap worth closing. The technical security knowledge is the baseline. Understanding what you’re actually securing is what makes you valuable at senior level.
This one surprises people. The conventional path says: take the management role as soon as it’s offered. More responsibility, more money, more seniority.
But we consistently see that the strongest senior hires have a period in their career where they deliberately stayed technical for longer than expected. They turned down the team lead role at 28 to spend another two years deepening their expertise. They chose a lateral move into a more complex technical environment over a promotion into people management.
The result is that when they do move into leadership, they bring a technical depth that earns respect from their teams in a way that pure management credentials don’t. In cyber security, the people you’re leading can tell very quickly whether you understand the work. The leaders who went deep before they went wide tend to keep their teams longer and make better decisions under pressure.
This isn’t advice to avoid management forever. It’s an observation that the best security leaders usually took their time getting there.
The most sought-after senior security professionals in CNI tend to have worked across at least two different sectors. Energy and defence. Financial services and utilities. Consultancy and in-house.
Each sector teaches something different. Financial services teaches you governance, regulatory rigour, and how to operate within frameworks. Defence teaches you threat-led thinking and operating under pressure. Energy teaches you the reality of OT environments and the constraints of operational uptime. Consultancy teaches you how to communicate with non-technical stakeholders and deliver under commercial pressure.
The people who’ve only ever worked in one sector can be excellent within it. But the ones who’ve moved bring a comparative perspective that’s hard to replicate. They’ve seen what good looks like in different contexts. They don’t assume that the way things work here is the way things work everywhere.
If you’ve been in the same sector for your entire career, a move might feel risky. From where we sit, it’s usually the single most valuable thing a mid-career security professional can do.
None of these are guarantees. Plenty of successful security leaders followed a conventional path. But when we look at the CVs of the people who are most in demand, who get multiple offers, who build security functions that actually work – these five patterns come up far more often than chance would explain.
Trusted by security leaders at



"I can't recommend Gyles and the team at Foundations enough. We struggled to find a suitable candidate for 5 months, Foundations found 3 perfect candidates in 24 hours."
Manager of EMEA & APAC Network Engineering, Equinix