Career Overlap Transition record Edition 1 · ESCO v1.2.1
Table 1Transition record

cybersecurity risk managertoIT auditor

A cybersecurity risk manager already meets 46% of what the IT auditor role asks for. The move turns on 9 required skills not yet in the profile.

From cybersecurity risk manager
46%
Overlap1
To IT auditor
15 Skills carried over
9 Required, not held
56.6 Difficulty2
Career overlap Partial match

46%

Learning distance Substantial retraining

56.6/ 100

1 Share of the IT auditor role’s weighted skill requirement already met by the cybersecurity risk manager profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.

Why

Why this move works

A IT auditor role treats 10 of its required skills as things a cybersecurity risk manager already does. These are the ones it depends on most.

  • ICT process quality models
  • ICT quality policy
  • ICT security legislation
  • ICT security standards
  • audit techniques
  • ensure adherence to organisational ICT standards

What stands in the way is 9 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.

Table 2

Table 2 · What you already bring

Of the 15 skills that carry over, these are the ones fewest other occupations ask for. A IT auditor role needs them, and most people applying for one will not have them already. This is the part of a cybersecurity risk manager background worth leading with.

Skill the target role also needs Area
  • already held ICT quality policy business, administration and law
  • already held ensure adherence to organisational ICT standards assisting and caring
  • already held identify ICT security risks information skills
  • already held organisational resilience business, administration and law
  • already held ICT project management business, administration and law
  • already held ICT process quality models information and communication technologies (icts)

All 15 carried skills, including the 10 the IT auditor role treats as required.

Table 3

Table 3 · What you would need to learn

The 22 missing skills fall into 8 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.

Skill to acquire Tier
01 management skills 3 required, 2 supplementary
  • required, not held develop audit plan required
  • required, not held improve business processes required
  • required, not held perform quality audits required
  • optional, not held develop ICT workflow optional
  • optional, not held define organisational standards optional
02 working with computers 2 required, 1 supplementary
  • required, not held analyse ICT system required
  • required, not held perform ICT security testing required
  • optional, not held manage IT security compliances optional
03 business, administration and law 2 required
  • required, not held product life-cycle required
  • required, not held quality standards required
04 information skills 1 required, 2 supplementary
  • required, not held prepare financial auditing reports required
  • optional, not held identify legal requirements optional
  • optional, not held monitor technology trends optional
05 engineering, manufacturing and construction 1 required
  • required, not held engineering processes required
06 communication, collaboration and creativity 3 supplementary
  • optional, not held communicate analytical insights optional
  • optional, not held develop documentation in accordance with legal requirements optional
  • optional, not held inform on workplace safety standards optional

2 further areas in the appendix

Table 4

Table 4 · Where to start

The 3 entries a IT auditor role is least likely to hire without. The ordering is computed from the skill data, not from what pays.

Each entry opens a course search for that skill. Career Overlap earns nothing from these links.

Appendix

Appendix · The rest of the record

All 15 skills that carry over
Skill Type
  • already held ICT process quality models knowledge
  • already held ICT quality policy knowledge
  • already held ICT security legislation knowledge
  • already held ICT security standards knowledge
  • already held audit techniques knowledge
  • already held ensure adherence to organisational ICT standards skill
  • already held execute ICT audits skill
  • already held legal requirements of ICT products knowledge
  • already held organisational resilience knowledge
  • already held systems development life-cycle knowledge
  • already held ICT network security risks knowledge
  • already held ICT project management knowledge
  • already held cyber security knowledge
  • already held identify ICT security risks skill
  • already held information security strategy knowledge
The 2 learning areas not shown above
Skill to acquire Tier
07 information and communication technologies (icts) 3 supplementary
  • optional, not held ICT accessibility standards optional
  • optional, not held cloud technologies optional
  • optional, not held World Wide Web Consortium standards optional
08 assisting and caring 2 supplementary
  • optional, not held apply information security policies optional
  • optional, not held protect personal data and privacy optional
13 supplementary skills, helpful but not required
Skill to acquire Tier
  • optional, not held ICT accessibility standards optional
  • optional, not held apply information security policies optional
  • optional, not held cloud technologies optional
  • optional, not held communicate analytical insights optional
  • optional, not held develop ICT workflow optional
  • optional, not held manage IT security compliances optional
  • optional, not held World Wide Web Consortium standards optional
  • optional, not held define organisational standards optional
  • optional, not held develop documentation in accordance with legal requirements optional
  • optional, not held identify legal requirements optional
  • optional, not held inform on workplace safety standards optional
  • optional, not held monitor technology trends optional
  • optional, not held protect personal data and privacy optional
57 held skills the IT auditor role does not ask for
Skill Type
  • not needed by the target role ICT encryption knowledge
  • not needed by the target role ICT performance analysis methods knowledge
  • not needed by the target role ICT problem management techniques knowledge
  • not needed by the target role ICT recovery techniques knowledge
  • not needed by the target role ICT safety skill
  • not needed by the target role ICT system user requirements knowledge
  • not needed by the target role Internet of Things knowledge
  • not needed by the target role Open source model knowledge
  • not needed by the target role Outsourcing model knowledge
  • not needed by the target role advice on security risk management skill
  • not needed by the target role assessment of risks and threats knowledge
  • not needed by the target role attack vectors knowledge
  • not needed by the target role cloud monitoring and reporting knowledge
  • not needed by the target role cloud security and compliance knowledge
  • not needed by the target role communicate with stakeholders skill
  • not needed by the target role computer forensics knowledge
  • not needed by the target role cyber attack counter-measures knowledge
  • not needed by the target role decision support systems knowledge
  • not needed by the target role define security policies skill
  • not needed by the target role define technology strategy skill
  • not needed by the target role design for organisational complexity skill
  • not needed by the target role develop information security strategy skill
  • not needed by the target role develop with cloud services skill
  • not needed by the target role domain name service knowledge
  • not needed by the target role engage with stakeholders skill
  • not needed by the target role establish an ICT security prevention plan skill
  • not needed by the target role establish an Information Security Management System skill
  • not needed by the target role ethical hacking principles knowledge
  • not needed by the target role hybrid model knowledge
  • not needed by the target role implement ICT risk management skill
  • not needed by the target role implement ICT security policies skill
  • not needed by the target role implement a firewall skill
  • not needed by the target role implement a virtual private network skill
  • not needed by the target role implement anti-virus software skill
  • not needed by the target role implement cloud security and compliance skill
  • not needed by the target role implement spam protection skill
  • not needed by the target role information confidentiality knowledge
  • not needed by the target role internal risk management policy knowledge
  • not needed by the target role internet governance knowledge
  • not needed by the target role investment analysis knowledge

17 further entries not listed here

6 gaps that are knowledge rather than practice

Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.

Skill to acquire Tier
  • required, not held engineering processes required
  • required, not held product life-cycle required
  • required, not held quality standards required
  • optional, not held ICT accessibility standards optional
  • optional, not held cloud technologies optional
  • optional, not held World Wide Web Consortium standards optional
Index
Note

How this record was compiled

Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.