CISOCareer GuideLeadership

How to Become a CISO in 2026: the Three Paths, the Deputy Route & the First 90 Days

IJB

InfoSec Job Board

July 31, 2026 · 10 min read

CISO is the one cybersecurity role you cannot study your way into. It is awarded, not earned by exam: someone with a security org, a budget, and a risk problem decides you are the person accountable for it. That makes the path less legible than the analyst or engineer tracks - but it is not random. Watching the security-leadership roles that cross our board (19 live right now: CISO, Head of Security, VP Security, Director of Security), the same three routes produce almost every serious candidate.

What the job actually is in 2026

Strip the title down and the modern CISO owns three things: risk (deciding which threats matter and what the business accepts), the program (people, tooling, budget, and the roadmap), and the story (explaining both to a board, a regulator, and sometimes a courtroom). SEC cyber-disclosure rules, DORA in European finance, and personal-liability precedents against individual security executives have made the seat board-facing in a way it simply was not five years ago. The consequence for your career planning: the skills that gate the title are increasingly the business ones, because the technical bar is assumed.

The three paths that actually produce CISOs

1. The operator path (most common)

SOC or security engineering, then team lead, then manager, then Director of Security Operations or Engineering, then the seat. Its strength is credibility - you have run the machinery you now govern. Its trap is staying too technical too long: the candidates who stall at director level are usually the strongest engineers in the room, because nobody has seen them own a budget or present risk to non-engineers. If you are on this path, start collecting business artifacts early: a budget you proposed, a board slide you wrote, a risk decision you argued and documented.

2. The GRC path (most underrated)

Governance, risk, and compliance work is board-language work: risk registers, audit findings, framework mappings, regulator conversations. GRC leaders step into deputy CISO and CISO seats surprisingly often - especially in regulated industries where the job is more risk governance than threat hunting. If you came up through audit or compliance, the gap to close is technical fluency, not depth: you need to hold your own in an architecture review, not win it. The on-ramp is mapped in our GRC transition guide.

3. The consulting path

Big 4 and boutique security consultants who have run assessments and programs across dozens of clients bring pattern-matching no single-company career can. The usual move is consultant to client: a company you advised hires you as its first serious security leader. The gap to close is operational scar tissue - advising on incident response is not the same as owning one at 3 a.m.

The real accelerator: the deputy tier

The strongest predictor we see in leadership hiring is time in a deputy CISO, BISO, or Head of Security seat. These roles carry real scope - a business unit's risk, a region's program, the CISO's stand-in - without requiring anyone to bet the whole company on you. Two or three years there converts an engineering-manager resume into a leadership one. When you scan the leadership board, do not skip past Director and Head-of titles looking for the letters C-I-S-O: those postings are the pipeline.

Skills and credentials that gate the title

  • Board communication. Can you compress a technical risk into three minutes a non-technical audience can decide on? This is the interview, in most cases.
  • Risk quantification. Frameworks matter less than the habit: exposure, likelihood, cost, options, recommendation - in writing.
  • Budget and vendor ownership. You will spend more time on renewals, headcount cases, and consolidation than on exploits. Evidence of having done it wins offers.
  • Certifications, honestly. CISSP and CISM are table stakes for the resume screen at traditional enterprises and near-irrelevant at startups. They will not make you a CISO; their absence can filter you out before a human looks. If you hold neither, the CISM reads more managerial, the CISSP travels further - comparison in our cert face-off.
  • An AI answer. Boards now ask what the company's AI exposure is. A CISO candidate with a concrete view on model risk, AI governance (EU AI Act, ISO 42001), and how the security program covers AI systems stands out immediately - the fastest-growing corner of the field, mapped in the AI security guide.

The side door: fractional and vCISO work

Smaller companies increasingly buy security leadership part-time, and fractional (vCISO) work has become a legitimate route to the full title: you accumulate first-leader experience across several companies at once, and one of them eventually converts you to full-time. It suits consultants and senior ICs with strong communication skills. Be honest about the trade: you get breadth and autonomy, you give up the deep organizational ownership that enterprise CISO searches want to see.

The first 90 days (what you are actually hired to do)

Nearly every new CISO mandate reduces to the same quarter: inventory what exists (assets, access, vendors, prior findings), rank the risks in business terms, fix the two or three things that are both dangerous and fast, and publish a roadmap with a budget attached. Candidates who describe that plan unprompted in interviews - instead of a tooling wishlist - consistently read as ready for the seat.

What the seat pays

Once you are in range of the title, know your market: $200,000 - $350,000 base in the US, tax-free packages in the Gulf that beat it on take-home, and full bands for 21 countries in our CISO salary guide - grounded in the same benchmarks as the country leaderboards, where the CISO tops the table in every market we track.

If you already run a security org

Half the readers of a page like this are not aspiring CISOs - they are sitting CISOs and Heads of Security benchmarking themselves. If that is you, the practical note is this: the analysts, engineers, and researchers you are trying to hire are this board's daily audience, and they apply directly (compare that to an agency fee with the cost-to-hire calculator).

For security leaders

Hiring for your security team?

Put your open roles in front of security professionals who apply directly - no agency fees, live in minutes, seen by candidates from 100+ countries.

From $299 for a 30-day listing

Live security leadership roles

cape logo

CapeNew York

$300,000 - $350,000Security
Posted Jul 30
drata logo

DrataUnited States

$210,000 - $350,000SecurityRemote
Posted Jul 23
catonetworks logo

Cato NetworksPhoenix

Security
Posted Jul 22

Browse CISO & security leadership jobs

Get weekly alerts for Get weekly alerts for new CISO & security leadership jobs:

Related guides

Stay ahead of the curve. Get new infosec jobs in your inbox.