Build AI capability your team will actually use

Build AI capability your team will actually use
From first steps to systems that run without you. Short courses, custom training, and the UK's Level 4 AI and Automation apprenticeship, which we created with Skills England.

Why The Coders Guild

We created this.

The Coders Guild led the research and development that produced the UK’s first Level 4 AI and Automation apprenticeship standard β€” built with Skills England and the Alan Turing Institute after a year of research into what SMEs actually need from AI training. We’re not reselling someone else’s framework. We designed it, and we’re running the first cohorts now.

Our trainers work in the field.

Our trainers work in the field. Every programme is delivered by industry practitioners β€” people using these tools in real businesses, not academics teaching from a curriculum. That means what gets taught reflects how AI and automation work in practice, not how they looked two years ago.

Built for smaller businesses.

Built for smaller businesses. Most AI training is designed with enterprise budgets and infrastructure in mind. Ours isn’t. Everything we do is built around the constraints and opportunities of SMEs β€” businesses where one capable person can genuinely change how the whole organisation works.

Three ways to build AI capability

Pick the one that matches where you are. If it’s not obvious, tell us what you’re working with and we’ll point you right.

You're making the decisions

Spend, policy, risk, who on the team needs what. AI for Leaders is six weeks that take you from using the tools to leading the doing.

You're growing your own AI talent

Grow your own AI capability with fully funded, hands-on training. Your people learn on real work in your business, on the UK’s Level 4 AI and Automation apprenticeship, the standard we created with Skills England.

You want the whole team trained together

Closed cohorts on your dates, up to twelve people, built around how your business actually works. One conversation tells you what fits.

Want to go deep yourself? Our courses run from Foundations through Intermediate to Advanced. See them all below.

β€œBusinesses need outputs, not certifications. That’s why our training returns value fast: people do the work on your business, instead of watching videos and hoping some of it sticks.”

Crispin Read – who led the R&D on the UK’s new Level 4 AI and Automation standard with Skills England

Not sure which route fits your team?

Not sure which route fits your team?

Every business is different. If you’re unsure which option works best, or you need something more tailored to your specific challenges, fill in the form and we’ll send you some options and arrange a call.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Cyber Security Apprenticeships & Training

Cyber Security Apprenticeships & Training

Cyber security is about protecting systems, data and people from threats. It’s one of the fastest-growing areas in tech, with demand far outstripping supply. Every organisation needs security capability β€” and most are struggling to find people with the right skills. AI is making this harder: it’s being used by attackers to automate and accelerate threats, and it’s introducing new attack surfaces that most existing security teams don’t yet know how to assess. Our programmes train security professionals for that reality, covering both established security practice and the emerging challenges AI brings.

The Coders Guild led the research and development that created the UK’s first Level 4 AI and Automation apprenticeship standard with Skills England and the Alan Turing Institute. Understanding AI systems β€” including how they can be exploited β€” is part of how we think about security training.

All available courses in Cyber Security Apprenticeships & Training

Cyber Security Level 4 Apprenticeship

Develop cyber security professionals ready to protect critical digital infrastructures and data. This apprenticeship builds practical skills in security system design, threat mitigation and incident response – strengthening your security posture and resilience against cyber attacks from day one.

Improving Website Security Workshop

Understand how websites get attacked and how to prevent it. Learn OWASP security protocols through practical white hat hacking exercises on deliberately vulnerable applications. Build more secure products.

Not sure which route fits your team?

Not sure which route fits your team?

Every business is different. If you’re unsure which option works best, or you need something more tailored to your specific challenges, fill in the form and we’ll send you some options and arrange a call.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

FAQs

FAQs

Do I need a computer science degree to work in cyber security?

No. While degrees can help, many successful security professionals came from different backgrounds – IT support, network administration, military, or even completely non-technical fields. What matters is security knowledge, practical skills, and ability to think like an attacker.

Some roles (particularly in government or large corporates) prefer degrees, but most employers care more about demonstrated capability. Certifications like Security+, CEH, or OSCP can substitute for degrees. A strong portfolio of security projects and practical experience often matters more than where you studied.

That said, if you’re starting from scratch with no IT experience, some formal education (degree, apprenticeship, or intensive bootcamp) provides structured learning and credentials that help get your foot in the door.

The terms are often used interchangeably, but there are subtle differences:

Penetration testing is structured security assessment with defined scope and rules of engagement. Pen testers systematically test systems for vulnerabilities, document findings, and provide recommendations. It’s planned, authorised, and professional.

Ethical hacking is broader – using hacking skills for defensive purposes. This might include penetration testing, but also security research, vulnerability discovery, and security tool development.

In practice, most professional “ethical hackers” are penetration testers conducting authorised security assessments for clients. The key word is authorised – ethical hackers have explicit permission to test systems. Unauthorised access is illegal, regardless of intentions.

It depends on your starting point and target role:

With IT experience: 6-12 months of focused security learning can make you ready for junior security analyst or SOC analyst roles. You’re building on existing technical knowledge.

Without IT experience: 12-18 months to learn IT fundamentals plus security concepts. You need to understand systems before you can secure them.

Via intensive bootcamp: 12-16 weeks full-time can prepare you for entry-level roles, though you’ll continue learning heavily on the job.

Via apprenticeship: 15-24 months combining work and study. You’re job-ready from day one because you’re already working, but qualification takes time.

Job-ready means you can contribute to a security team and learn on the job – not that you’re an expert. Security is vast, and everyone continues learning throughout their career. Early roles focus on learning and development as much as production work.

Yes. The Cyber Security Level 4 Apprenticeship is funded through the Growth and Skills Levy. For SMEs with a wage bill under Β£3 million, the government covers 95% of training costs and you contribute 5%. Larger organisations draw directly from their levy pot. The apprentice is employed by you throughout, earning a salary and working in your team while completing the programme. We handle the compliance and admin from start to finish.

You don’t strictly need certifications, but they help, especially early in your career:

Entry-level: CompTIA Security+ is widely recognised and covers security fundamentals. Good starting point for junior roles.

Penetration testing: CEH (Certified Ethical Hacker) or OSCP (Offensive Security Certified Professional). OSCP is particularly well-regarded but challenging – it’s hands-on and requires passing a 24-hour practical exam.

Security operations: GIAC Security Essentials (GSEC) or Certified SOC Analyst (CSA) demonstrate SOC capabilities.

Senior level: CISSP (Certified Information Systems Security Professional) is respected for senior and management roles but requires five years of experience.

Specialist certifications: SANS/GIAC offer certifications for forensics, incident response, penetration testing, and other specialisms.

Certifications demonstrate commitment and baseline knowledge, but practical skills matter more. Employers would rather see someone who can actually find vulnerabilities and explain them clearly than someone with certificates but no practical capability. Balance certification study with hands-on practice.

Yes, but you’ll need to build technical foundations. Security requires understanding how systems work before you can secure them, but you don’t need to be a programmer or hardcore techie.

Some security areas suit less technical backgrounds better than others:

Security governance, risk and compliance (GRC): Focus on policies, risk management, auditing, and compliance. Less technical than penetration testing or security engineering, but still requires security understanding.

Security awareness and training: Teaching others about security threats, phishing, safe practices. Benefits from communication skills and understanding human behaviour.

Security analysis: Investigating incidents and analysing threats requires analytical thinking more than deep technical skills initially. You’ll build technical knowledge over time.

Career changers from teaching, investigation, military, law enforcement, or analytical roles often succeed in security. Your non-technical background can be an asset – you bring different perspectives and communication skills that technical-only people may lack.

Expect to invest time learning technical fundamentals: networking basics, how operating systems work, common security concepts. But you don’t need to become a software developer to work in security.

If your organisation pays the apprenticeship levy (wage bill over Β£3 million), you have a digital apprenticeship account with funds that can be used directly for approved training β€” including the Cyber Security Level 4 Apprenticeship. If you don’t pay the levy, the government covers 95% of costs and you contribute 5%. Unused levy funds expire after 24 months, so many organisations already have budget available. We can check what’s accessible for your business and handle the paperwork.

Most employers see useful contribution within the first few months. The programme is built around real security challenges in your organisation from the start β€” apprentices aren’t learning in isolation. Early in the programme they’ll be assessing your security posture, identifying vulnerabilities, and supporting your response processes. By the end, you have someone with hands-on experience in your specific environment, systems, and threat profile. That embedded knowledge is hard to replicate by bringing in an external consultant.

Significantly on both sides. Attackers are already using AI to automate threat discovery, craft more convincing phishing campaigns, and accelerate exploit development. At the same time, AI systems themselves are introducing new attack surfaces β€” prompt injection, model poisoning, data exfiltration through AI APIs β€” that most existing security teams haven’t yet been trained to assess or defend against. Our programmes cover modern security practice including AI-related threats, so apprentices arrive in your team equipped to understand and respond to the threat landscape as it actually is now, not as it was five years ago.

The Cyber Security Level 4 Apprenticeship works well for IT support staff moving into security, network administrators building specialist skills, junior security analysts needing formal training, and developers who want to specialise in application security or DevSecOps. It also works for people transitioning from adjacent roles β€” risk and compliance, IT project management, or technical support β€” who have the analytical thinking and attention to detail security requires. You don’t need a programmer β€” you need someone curious about how systems can be broken and motivated to learn how to protect them.

More Info

What is Cyber Security?

Cyber security professionals protect digital systems from unauthorised access, theft, damage and disruption. That includes defending networks, applications, data, and infrastructure against attacks – while also responding when breaches happen.

The field is broad. Some security professionals focus on preventing attacks through secure system design, testing for vulnerabilities, or implementing security controls. Others respond to incidents, investigate breaches, or work on security operations – monitoring systems and responding to threats in real time.

Security work exists across every sector. Banks, healthcare providers, retailers, government departments, manufacturers, startups – all need people who understand threats and can protect against them. The work is varied: some days you’re testing applications for vulnerabilities, other days you’re investigating suspicious activity or building security into development processes.

Modern security isn’t just technical. It’s about understanding how people work, where processes break down, and how attackers think. Social engineering, phishing, and insider threats are often bigger risks than sophisticated technical attacks. Good security professionals understand both technology and human behaviour.

The field changes constantly. New vulnerabilities are discovered, attack methods evolve, and technologies shift. This means continuous learning is part of the job. Security professionals read security bulletins, follow researchers, test new tools, and stay current with threats.

Unlike some tech careers, security benefits from diverse backgrounds. Former network administrators, developers, system administrators, and even people from non-technical fields bring valuable perspectives. Understanding how systems are built helps you understand how they can be broken – but creative thinking and attention to detail matter more than deep technical knowledge starting out.

Cyber security requires a mix of technical knowledge, analytical thinking, and communication skills. Here’s what matters across different security roles:

Technical Fundamentals

Networking basics: Understanding how networks work – TCP/IP, DNS, HTTP/HTTPS, firewalls, routers, switches. Many attacks exploit network vulnerabilities, so you need to know how traffic flows and where weak points exist.

Operating systems: Deep knowledge of Linux and Windows. How they’re configured, where logs are stored, what processes should be running, how permissions work. Attackers exploit OS weaknesses, so defenders need to understand them thoroughly.

Security principles: CIA triad (Confidentiality, Integrity, Availability), defence in depth, least privilege, separation of duties. The foundational concepts that inform security decisions.

Cryptography basics: How encryption works, different encryption methods, hashing, digital signatures, certificates. You don’t need to be a cryptographer, but you need to understand when and how to use cryptographic tools.

Web technologies: How web applications work, common vulnerabilities (SQL injection, XSS, CSRF), API security, authentication and authorisation. Most modern attacks target web applications.

Security-Specific Skills

Vulnerability assessment: Identifying security weaknesses in systems, applications, and networks. Using scanning tools, manual testing, and understanding common vulnerability types.

Penetration testing: Ethical hacking – attempting to break into systems to find vulnerabilities before malicious actors do. Requires creativity, persistence, and methodical documentation.

Threat modelling: Thinking like an attacker. Identifying valuable assets, potential attack vectors, and likely threat actors. Understanding what you’re defending against.

Incident response: What to do when something goes wrong. Containing breaches, investigating what happened, recovering systems, and learning from incidents.

Security monitoring: Using SIEM tools, analysing logs, identifying suspicious activity, distinguishing real threats from false positives.

Secure coding: Understanding common programming vulnerabilities and how to write code that’s harder to exploit. Input validation, secure authentication, avoiding injection flaws.

Tools You’ll Use

Penetration testing tools: Metasploit, Burp Suite, Nmap, Wireshark, Kali Linux. Industry-standard tools for testing security and identifying vulnerabilities.

Vulnerability scanners: Nessus, OpenVAS, Qualys. Automated tools that scan systems for known vulnerabilities.

SIEM platforms: Splunk, ELK Stack, QRadar. For collecting and analysing security logs across systems.

Security frameworks: OWASP guidelines, NIST Cybersecurity Framework, CIS Controls. Established best practices and standards.

Cloud security tools: AWS Security Hub, Azure Security Center, cloud-native security controls. As more systems move to cloud, understanding cloud security becomes essential.

Forensics tools: For investigating incidents and analysing compromised systems. FTK, EnCase, Autopsy.

Analytical & Soft Skills

Problem-solving: Security work is constant puzzle-solving. Why is this traffic anomalous? How did the attacker get in? What’s the root cause of this vulnerability?

Attention to detail: Missing one vulnerability can compromise an entire system. Small indicators in logs can reveal major incidents. Security requires careful, thorough work.

Communication: Explaining technical risks to non-technical stakeholders. Writing clear vulnerability reports. Presenting findings to management. Security professionals spend significant time communicating, not just testing systems.

Ethical judgement: Security work involves access to sensitive systems and data. Strong ethics and trustworthiness are essential – one reason why security vetting is common in these roles.

Continuous learning: New vulnerabilities, attack methods, and tools emerge constantly. Good security professionals read security blogs, follow researchers, take training, and stay current.

Thinking like an attacker: Understanding attacker motivations, common techniques, and how criminals or nation-states operate. Security isn’t just about technology – it’s about understanding adversaries.

Certifications That Matter

While not strictly required, certain certifications are well-regarded in security:

CompTIA Security+: Entry-level security fundamentals. Good starting point covering broad security concepts.

CEH (Certified Ethical Hacker): Penetration testing and ethical hacking techniques.

OSCP (Offensive Security Certified Professional): Hands-on penetration testing certification, highly regarded but challenging.

CISSP (Certified Information Systems Security Professional): Senior-level certification covering security management and strategy. Requires several years of experience.

SANS certifications (GIAC): Specialised certifications for specific security domains – forensics, incident response, penetration testing.

Certifications can help, especially early in your career, but practical skills and demonstrable capability matter more. A strong portfolio of security projects or contributions often trumps certificates.

Cyber security offers diverse career paths with strong progression and good salaries. Here’s how careers typically develop:

Entry Level

Junior Security Analyst / SOC Analyst: Monitoring security systems, responding to alerts, investigating potential incidents, escalating serious threats. Working in a Security Operations Centre (SOC), often with shift work. Learning security tools and processes. Salary: Β£22,000 – Β£32,000.

Entry roles focus on learning security fundamentals, understanding common threats, using security tools, and developing incident response skills. You’ll spend time investigating alerts (many will be false positives), documenting findings, and learning from more experienced team members.

Junior Penetration Tester / Security Tester: Learning penetration testing under supervision, conducting vulnerability assessments, testing applications and infrastructure for weaknesses. Salary: Β£25,000 – Β£35,000.

These roles involve more active testing – attempting to find vulnerabilities before attackers do. You’ll learn testing methodologies, use penetration testing tools, and document findings clearly for technical and non-technical audiences.

Mid-Level

Security Analyst: Independently investigating security incidents, implementing security controls, conducting risk assessments, managing security tools. Working with less supervision and making more decisions. Salary: Β£35,000 – Β£50,000.

At this level you’re trusted to handle incidents independently, identify patterns in security data, and recommend improvements to security posture. You understand your organisation’s systems well and can assess threats in context.

Penetration Tester: Conducting independent security assessments, performing penetration tests on applications and infrastructure, identifying complex vulnerabilities, writing detailed reports. Salary: Β£40,000 – Β£60,000.

Mid-level pen testers work with minimal supervision, conduct comprehensive assessments, and find vulnerabilities that automated tools miss. You’re expected to think creatively about attack vectors and explain risks clearly to clients or stakeholders.

Security Engineer: Designing and implementing security solutions, building security into systems from the start, automating security processes, working with development and operations teams. Salary: Β£40,000 – Β£60,000.

Security engineers focus on building secure systems rather than just defending existing ones. You’ll work on secure architecture, implement security controls in cloud environments, integrate security into CI/CD pipelines, and help development teams write secure code.

Senior & Specialist Roles

Senior Security Analyst / SOC Manager: Leading incident response, managing security operations teams, developing security processes, making strategic security decisions. Salary: Β£50,000 – Β£70,000.

Senior analysts often lead major incident responses, mentor junior team members, and influence security strategy. You’re the escalation point for complex incidents and help shape how your organisation handles security.

Senior Penetration Tester / Lead Tester: Leading complex penetration tests, specialising in specific areas (web apps, infrastructure, red teaming), training other testers, building testing methodologies. Salary: Β£55,000 – Β£80,000+.

Senior pen testers often specialise deeply – becoming experts in web application security, infrastructure testing, or red team operations (simulating advanced persistent threats). You might lead teams or work independently on high-value assessments.

Security Architect: Designing security architecture for organisations, making strategic technology decisions, defining security standards, advising on security across major projects. Salary: Β£60,000 – Β£90,000+.

Security architects work at a strategic level, designing how security should be implemented across systems, choosing security technologies, and ensuring security requirements are met in large initiatives.

Incident Response Manager: Leading major incident responses, coordinating across teams during breaches, developing incident response plans, managing crisis situations. Salary: Β£55,000 – Β£80,000.

When serious security incidents happen, incident response managers coordinate the response – containing threats, investigating causes, recovering systems, and learning from incidents.

Specialisation Paths

Application Security Specialist: Focus on securing software throughout development. Code review, security testing, working with developers to fix vulnerabilities, building security into DevOps processes.

Cloud Security Specialist: Securing cloud environments (AWS, Azure, GCP). Understanding cloud-native security controls, identity and access management, compliance in cloud, and cloud-specific threats.

Digital Forensics Analyst: Investigating security incidents and cybercrimes. Collecting and analysing digital evidence, reconstructing what happened during breaches, supporting legal proceedings.

Threat Intelligence Analyst: Researching threat actors, tracking emerging threats, understanding attacker tactics and techniques, providing intelligence to inform security decisions.

Security Compliance Analyst: Ensuring organisations meet security standards and regulations (GDPR, ISO 27001, PCI DSS). Conducting audits, documenting compliance, managing certifications.

Red Team Specialist: Simulating advanced attackers to test organisational defences. Multi-stage attacks, social engineering, physical security testing, adversary emulation.

Industrial Control Systems (ICS) Security: Securing operational technology in manufacturing, utilities, critical infrastructure. Specialised area requiring both IT security and OT knowledge.

Leadership Paths

Security Team Lead / Manager: Managing security analysts or engineers, running security operations, hiring and developing team members, translating between technical teams and management.

Chief Information Security Officer (CISO): Executive-level security leadership. Overall responsibility for organisational security, managing security strategy, board-level reporting, significant budgets. Salary: Β£80,000 – Β£150,000+ depending on organisation size.

Consultant / Independent Security Advisor: Many experienced security professionals move into consulting, providing advice to multiple organisations, conducting assessments, or specialising in particular security domains.

Alternative Directions

Security skills open doors to adjacent careers: security training and education, security product management, security sales engineering (technical sales for security products), security research, or security policy and governance roles.

The chronic shortage of security professionals means experienced people have options. Whether you want deep technical work, management, consulting, or specialisation – security offers diverse career paths with strong demand.

Cyber security needs people from diverse backgrounds. There’s no single “security person” type – the field benefits from different perspectives and varied experience.

What Actually Matters

Curiosity about how things work (and break): Good security professionals want to understand systems deeply – how they’re built, where they’re vulnerable, what happens when they fail.

Analytical thinking: Security involves investigating anomalies, piecing together evidence, understanding attack patterns. If you enjoy detective work and puzzles, security might suit you.

Attention to detail: Small indicators matter in security. One unusual log entry might reveal a major incident. One missed vulnerability could compromise a system. This work requires careful, thorough attention.

Ethical judgement: Security roles involve access to sensitive systems and data. Trustworthiness and strong ethics are essential. Many security roles require security clearance or background checks.

Communication skills: Security isn’t just technical work. You’ll explain risks to non-technical stakeholders, write reports, present findings, and convince people to take security seriously. Communication matters as much as technical skills.

Persistence: Finding vulnerabilities requires patience. Some security work involves methodically testing hundreds of possibilities. Some investigations take weeks. Giving up isn’t an option.

Common Backgrounds

IT support and systems administration: Many security professionals started in IT support, help desk, or system administration. Understanding how systems are used and maintained provides excellent foundation for security work.

Network administration: Network admins often move into security because they already understand how networks work, what normal traffic looks like, and how to secure infrastructure.

Software development: Developers who understand how applications are built make excellent security professionals – you know where vulnerabilities hide because you’ve built similar systems.

Military and law enforcement: The structured thinking, attention to detail, and security mindset from military or police work transfers well. Many ex-military personnel work in security.

Complete career changers: People from non-technical backgrounds can succeed in security if they’re willing to learn technical fundamentals. Teaching, investigation, research, and analytical roles all develop transferable skills.

Who Succeeds in Security

People who are naturally suspicious and question how things work. Those who enjoy finding problems and figuring out solutions. Individuals who can think creatively about how systems might be abused. People who stay calm under pressure when incidents happen.

Age doesn’t matter. Security benefits from experience and maturity – understanding business context, risk, and human factors often matters more than youthful energy. Many people enter security mid-career.

You don’t need to be a hardcore programmer, though basic scripting helps. You don’t need advanced maths. You don’t need to have been “into computers” since childhood. You need willingness to learn technical concepts and develop security thinking.

What Makes Security Work Challenging

You’re often fighting asymmetry: Attackers only need to find one vulnerability. Defenders need to protect everything. Attackers choose when and how to attack. Defenders must be ready constantly.

Keeping up is demanding: New vulnerabilities are discovered daily. Attack methods evolve. Technologies change. Security requires continuous learning to stay current.

Dealing with incidents is stressful: When breaches happen, there’s pressure to respond quickly while thoroughly investigating. Incident response can be intense.

Convincing people is frustrating: Security often means saying “no” or “that’s risky” when others want to move fast. Getting people to take security seriously can be an uphill battle.

The stakes are real: Security failures can cost organisations millions, damage reputations, or expose personal data. The responsibility can feel heavy.

What Makes Security Work Rewarding

Constant learning: If you enjoy learning, security provides endless opportunities. The field never gets boring.

Tangible impact: Finding a critical vulnerability before attackers do, stopping an incident before major damage, building systems that withstand attacks – security work has clear, meaningful impact.

Problem-solving variety: Every day brings different challenges. Security work is rarely repetitive.

Strong demand: Organisations struggle to find security professionals. Job security is excellent, salaries are good, and opportunities are plentiful.

Respected expertise: Security professionals are valued. Your opinion matters on important decisions, and organisations need your expertise.

Common Concerns

“I’m not technical enough:” Many successful security professionals started with minimal technical background. Security fundamentals can be learned – critical thinking and attention to detail are harder to teach.

“I’m not a hacker:” Not all security work involves hacking. Incident response, security operations, compliance, risk management, and governance roles need different skills. Penetration testing is just one path.

“I don’t have a security background:” Most security professionals came from somewhere else – IT support, development, networking, or completely different fields. Security benefits from diverse backgrounds.

“The field seems intimidating:” Security culture can sometimes feel exclusive or gatekept. Don’t let that discourage you. The field desperately needs more people, and many security professionals are happy to help newcomers learn.

If You’re Completely New

Start with security fundamentals – understanding common threats, basic security principles, and how systems are attacked and defended. You don’t need to become a penetration tester immediately.

Learn security basics:

  • Common attack types: phishing, malware, SQL injection, cross-site scripting
  • Security principles: CIA triad, defence in depth, least privilege
  • How networks work: TCP/IP, DNS, firewalls
  • Operating system basics: Linux and Windows command line, user permissions, logs

Free resources like OWASP (Open Web Application Security Project) provide excellent security learning materials. TryHackMe and HackTheBox offer hands-on security learning through gamified challenges.

Build foundational IT knowledge: If you’re new to IT generally, consider starting with broader IT skills before specialising in security. Understanding how systems work is essential before you can secure them. Network fundamentals, Linux/Windows administration, and basic programming/scripting provide crucial foundation.

Set up a home lab: Install virtual machines, set up test environments, practice security tools. Most security work happens in labs initially – you can’t practice on production systems or attack real targets legally.

If You Have IT Experience

Leverage your existing knowledge as foundation for security learning:

From IT support/helpdesk: You understand how users work, common problems, and system basics. Add security thinking – how could users be tricked? Where are systems vulnerable? Learn security tools and monitoring.

From network administration: You know how networks operate. Add security perspective – network scanning, firewalls, intrusion detection, VPNs, secure network design.

From development: You understand how applications work. Learn secure coding practices, common vulnerabilities (OWASP Top 10), penetration testing, and how to find security flaws in code.

From systems administration: You manage servers and systems. Add hardening practices, security monitoring, incident response, logging and auditing.

Start applying security thinking to your current role. How could your systems be attacked? What security controls exist? What’s missing? Volunteer for security-related projects or tasks in your current job.

Practical Learning Steps

Study common vulnerabilities: Learn the OWASP Top 10 (most critical web application risks). Understand how SQL injection, XSS, CSRF, and other common attacks work – and how to prevent them.

Practice penetration testing basics: Use platforms like TryHackMe, HackTheBox, or PentesterLab to practice finding vulnerabilities in safe, legal environments. Start with beginner challenges and progress gradually.

Learn a scripting language: Python is most common in security. Bash scripting for Linux automation is valuable. PowerShell for Windows environments. Security work often involves automating tasks and writing custom tools.

Understand security tools: Learn Nmap (network scanning), Wireshark (packet analysis), Burp Suite (web application testing), Metasploit (penetration testing framework). Start with free/community versions.

Read security content: Follow security blogs, read vulnerability disclosures, study real-world breaches. Understanding how actual attacks happen teaches more than theoretical knowledge. Security Twitter and Reddit’s /r/netsec are good sources.

Participate in CTFs (Capture The Flag competitions): These security challenges teach practical skills through problem-solving. Many are designed for beginners. CTFs are how security professionals stay sharp and learn.

Structured Training Routes

Apprenticeships: Work as a security analyst, SOC analyst, or junior security engineer while completing structured training. Government-funded, paid positions that combine work and learning. Duration: 15-24 months depending on level.

Apprenticeships work well in security because hands-on experience is crucial. You’ll see real incidents, work with security tools in production environments, and learn from experienced security professionals while building your skills.

Bootcamps: Intensive security training covering penetration testing, security operations, or security engineering. Some bootcamps are government-funded through Skills Bootcamps. Duration: 8-16 weeks full-time.

Bootcamps suit career changers who can commit full-time. They’re intensive but get you job-ready quickly with practical skills and portfolio projects.

University degrees: Cyber security degrees (undergraduate or postgraduate) provide comprehensive security education including theory, practical skills, and broader context. Some roles (particularly government or large corporations) prefer degrees, especially for more senior positions.

Certifications: Industry certifications like CompTIA Security+, CEH (Certified Ethical Hacker), or OSCP (Offensive Security Certified Professional) demonstrate security knowledge and are valued by employers. Some are expensive, but government funding or employer sponsorship may be available.

Self-taught: Many successful security professionals are self-taught through online resources, practice platforms, reading, and hands-on experimentation. Takes longer than structured training but proves self-motivation and practical skills.

Building Your Portfolio

Security employers want to see what you can do:

Document your learning: Write blog posts explaining security concepts, vulnerabilities you’ve discovered in practice environments, or tools you’ve learned. This demonstrates knowledge and communication skills.

Contribute to security projects: Open source security tools need contributors. Documentation, testing, or code contributions all count.

Participate in bug bounty programmes: Once you have solid skills, look for vulnerabilities in programmes that reward security researchers. Start with smaller programmes before tackling major platforms.

Complete security challenges: TryHackMe and HackTheBox profiles show completed challenges and learned skills. These platforms are recognised by employers.

Build security tools: Create scripts or tools that solve security problems. Password strength checkers, log analysers, or security automation scripts all demonstrate practical capability.

Legal and Ethical Considerations

Critical: Only test systems you have explicit permission to test. Unauthorised access to computer systems is illegal, even if your intentions are good. Always:

  • Use practice platforms (TryHackMe, HackTheBox, etc.) designed for learning
  • Only scan or test systems you own
  • Get written permission before testing any organisation’s systems
  • Follow responsible disclosure if you find real vulnerabilities
  • Understand computer misuse laws in your jurisdiction

Security careers require trustworthiness. Criminal records for computer offences will severely limit opportunities. Don’t let enthusiasm lead to illegal activity.

Getting Your First Security Role

Entry-level security jobs are competitive but attainable:

Target junior SOC analyst roles: These are common entry points. Focus applications on organisations with 24/7 security operations centres. Expect shift work initially.

Look for “pathway” programmes: Some larger organisations run security graduate schemes or junior security programmes specifically for people entering the field.

Consider adjacent roles: IT support, help desk, or junior system administration roles in security-conscious organisations can provide stepping stones. Once inside, you can move toward security.

Highlight transferable skills: If you’re career changing, emphasise analytical thinking, attention to detail, problem-solving, and any technical experience. Security teams need diverse skills.

Demonstrate passion: Employers want people genuinely interested in security. Point to CTF participation, security learning platforms, relevant reading, or security projects.

Network: Attend security meetups (BSides, OWASP chapters, local security groups), engage in security communities online, connect with security professionals on LinkedIn. Many security jobs are filled through referrals.

Our Training Options

The Coders Guild offers cyber security apprenticeships and bootcamps covering security operations, penetration testing, and security engineering. Training is practical, includes real security tools and scenarios, and is taught by working security professionals.

Government funding is available for apprenticeships and qualifying bootcamps. Browse our cyber security courses below or get in touch to discuss which route might work for you.

Typical Salary Ranges (UK)

Junior Security Analyst / SOC Analyst: Β£22,000 – Β£32,000 depending on location and organisation size. Entry-level security operations roles, often with shift work. London pays significantly more.

Junior Penetration Tester: Β£25,000 – Β£35,000 for trainee or junior testing roles. Higher than some other junior tech positions due to specialised skills.

Security Analyst (mid-level): Β£35,000 – Β£50,000 with a few years of experience. Conducting incident response, security monitoring, and security operations independently.

Penetration Tester: Β£40,000 – Β£60,000 for experienced testers. Specialist skills command good salaries. Freelance pen testers can charge Β£400-Β£800 daily.

Security Engineer: Β£40,000 – Β£60,000 for implementing security solutions, working with development teams, and building security into systems.

Senior Security Analyst / SOC Manager: Β£50,000 – Β£70,000 for leading security operations or incident response teams.

Senior Penetration Tester / Security Consultant: Β£55,000 – Β£80,000+ for experienced specialists or consultants. High-end specialists can earn Β£100,000+.

Security Architect: Β£60,000 – Β£90,000+ for designing security architecture and leading security strategy.

CISO (Chief Information Security Officer): Β£80,000 – Β£150,000+ depending on organisation size. Executive-level security leadership with significant responsibility.

Salaries vary significantly by location. London typically pays 30-50% more than other regions but has higher living costs. However, many security roles are now remote or hybrid, which helps equalise regional differences.

Market Demand

Cyber security faces a critical skills shortage. Demand far exceeds supply, making it one of the strongest areas in tech for job security and career growth.

Key demand drivers:

Increasing threats: Cyber attacks are growing in frequency and sophistication. Ransomware, data breaches, and state-sponsored attacks make headlines regularly. Every organisation needs better security.

Regulatory requirements: GDPR, NIS regulations, industry-specific compliance requirements – organisations must meet security standards, driving demand for security professionals.

Digital transformation: As organisations move more systems online and to cloud, their attack surface expands. More digital systems mean more security needs.

Skills gap: Estimates suggest tens of thousands of unfilled security positions in the UK. Organisations struggle to find qualified candidates, creating excellent opportunities for people entering the field.

Industries Hiring Security Professionals

Every sector needs security, but particular demand exists in:

  • Financial services: Banks, fintech, insurance – heavily regulated and high-value targets
  • Healthcare: NHS, private healthcare, healthtech – handling sensitive patient data
  • Government and defence: Central government, local councils, defence contractors – often requiring security clearance
  • Technology companies: Software companies, SaaS providers, cloud services
  • Consulting firms: Security consultancies providing services to multiple clients
  • Retail and e-commerce: Protecting customer data and payment systems
  • Critical infrastructure: Energy, water, transport – protecting essential services
  • Manufacturing: Increasingly targeted by cyber criminals and state actors

Security roles exist everywhere. Even smaller organisations increasingly hire security professionals or work with security consultants.

Remote Working & Flexibility

Security work is often remote-friendly, though some roles have constraints:

Remote-friendly roles: Penetration testing, security consulting, some security engineering. Many security tasks can be done from anywhere with secure remote access.

Less remote-friendly: SOC analyst roles often require on-site presence, especially in government or highly secure environments. Shift work makes remote working challenging for 24/7 operations.

Security clearance roles: Government and defence security roles often require on-site work and UK-based residence. Clearance requirements limit location flexibility.

COVID accelerated remote security work. Many organisations now offer hybrid arrangements, with security teams working remotely part-time but coming together for collaboration and incident response.

Contracting & Freelancing

Security contracting can be lucrative:

Penetration testing contractors: Β£400-Β£800+ per day depending on experience and specialisation. Red team specialists can command premium rates.

Security consultants: Β£500-Β£1,000+ daily for experienced consultants providing advisory services.

Interim security managers/architects: Β£600-Β£900+ daily for temporary leadership or architecture roles.

Contracting requires several years of experience first. You need proven capability, professional reputation, and often security clearances or certifications. Most contractors spend 3-5+ years in permanent roles before going independent.

Career Progression & Earning Potential

Security offers excellent progression. Specialists with in-demand skills can reach six-figure salaries within 10 years. Progression depends on:

Specialisation: Deep expertise in penetration testing, cloud security, incident response, or forensics commands premium salaries.

Certifications: OSCP, CISSP, SANS certifications, and other respected credentials increase earning potential.

Industry sector: Finance, consulting, and technology typically pay more than public sector or smaller organisations.

Location and mobility: Willingness to relocate or work remotely opens higher-paying opportunities.

Leadership path: Moving into management (SOC manager, security manager, CISO) increases salaries significantly.

Unlike some tech careers, security professionals remain valuable throughout their careers. Experience matters enormously – senior security professionals are highly valued and well-compensated.

Job Security

Security is about as secure as careers get. Threats aren’t going away. Organisations increasingly recognise security as essential, not optional. The skills shortage means qualified security professionals have multiple opportunities.

Even during economic downturns, security roles are often protected. Cutting security capability when threats persist is risky, so security budgets tend to be more resilient than other IT spending.

Latest From the Journal

Latest From the Journal
A whiteboard drawing titled "FREE AI RESOURCES" in dark blue marker with a red underline. Below and to the left is a red circular stamp with a checkmark and text reading "verified Sept 2026". On the right, an open treasure chest doodle in dark blue is shown spilling out colorful icons, including a book, a video play button, speech bubbles, and a lightbulb. Hand-drawn dark blue and red arrows connect the title, stamp, and treasure chest, with scattered star doodles in both colors around them.

Best Free AI Courses, Tools and Platforms for Beginners (Updated Sept 2026)

AI is already changing how people work. Not in some future-tense, speculative way – right now, in offices and workshops

Coding on Claude: How Non-Technical People Can Master

Traditional boundaries between product management, strategy, and engineering are rapidly dissolving. Non-technical leaders, product managers, and founders no longer need

A team working through AI training together around a laptop, one person helping colleagues at the screen.

AI Leadership Traits: The Skills Every Future-Focused Manager Needs

The introduction of generative tools and autonomous agents has completely disrupted traditional management frameworks. How AI is redefining leadership isn’t

How to Automate Feedback Loops With AI Without Losing Oversight

If you run any kind of training, coaching or client delivery business, you already have feedback pouring in from every

Claude AI vs ChatGPT for Business Teams

When evaluating enterprise artificial intelligence platforms for integration into corporate workflows, decision-makers, such as HR leaders, operations directors, and training

How SMEs Can Build AI-Ready Teams: A Realistic Structural Field Guide

Most small and medium-sized enterprises (SMEs) approach artificial intelligence from a tooling perspective. They buy software licenses, distribute access keys,

Got something to share with us?

Got something to share with us?

If you’ve got an event, collaboration or success story we should know about – get in touch.

FREE AI WEBINARS

Get the invite to our next AI session

Two short, practical AI sessions a month. Free. Drop your email and we’ll send you the link, plus the recordings of the ones you’ve missed.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
The Coders Guild
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.