Career Overlap Transition record Edition 1 · ESCO v1.2.1
Table 1Transition record

ethical hackertocybersecurity risk manager

A ethical hacker already meets 52% of what the cybersecurity risk manager role asks for. The move turns on 9 required skills not yet in the profile.

From ethical hacker
52%
Overlap1
To cybersecurity risk manager
35 Skills carried over
9 Required, not held
59.5 Difficulty2
adjacent 0–30
moderate 30–55
substantial 55–75
career change 75–100
this move, 59.5

This move: 59.5 of 100 · substantial

1 Share of the cybersecurity risk manager role’s weighted skill requirement already met by the ethical hacker profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.

Table 2

Table 2 · What you already bring

Of the 35 skills that carry over, these are the ones fewest other occupations ask for. A cybersecurity risk manager role needs them, and most people applying for one will not have them already. This is the part of a ethical hacker background worth leading with.

Skill the target role also needs Area
  • already held computer forensics information and communication technologies (icts)
  • already held engage with stakeholders communication, collaboration and creativity
  • already held define security policies management skills
  • already held web application security threats information and communication technologies (icts)
  • already held ICT safety working with computers
  • already held ethical hacking principles information and communication technologies (icts)

All 35 carried skills, including the 13 the cybersecurity risk manager role treats as required.

Table 3

Table 3 · What you would need to learn

The 37 missing skills fall into 8 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.

Skill to acquire Tier
01 information and communication technologies (icts) 2 required, 10 supplementary
  • required, not held ICT performance analysis methods required
  • required, not held assessment of risks and threats required
  • optional, not held ICT problem management techniques optional
  • optional, not held ICT process quality models optional
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held decision support systems optional
  • optional, not held domain name service optional
  • optional, not held mobile device management optional
  • optional, not held systems development life-cycle optional
02 business, administration and law 2 required, 4 supplementary
  • required, not held internal risk management policy required
  • required, not held risk management required
  • optional, not held ICT project management optional
  • optional, not held ICT quality policy optional
  • optional, not held investment analysis optional
  • optional, not held audit techniques optional
03 assisting and caring 2 required, 1 supplementary
  • required, not held ensure adherence to organisational ICT standards required
  • required, not held establish an Information Security Management System required
  • optional, not held develop information security strategy optional
04 management skills 1 required, 3 supplementary
  • required, not held establish an ICT security prevention plan required
  • optional, not held define technology strategy optional
  • optional, not held lead disaster recovery exercises optional
  • optional, not held manage disaster recovery plans optional
05 information skills 1 required, 1 supplementary
  • required, not held advice on security risk management required
  • optional, not held implement cloud security and compliance optional
06 services 1 required
  • required, not held security threats required

2 further areas in the appendix

Table 4

Table 4 · Where to start

The 3 entries a cybersecurity risk manager role is least likely to hire without. The ordering is computed from the skill data, not from what pays.

Each entry opens a course search for that skill. Career Overlap earns nothing from these links.

Appendix

Appendix · The rest of the record

All 35 skills that carry over
Skill Type
  • already held ICT network security risks knowledge
  • already held ICT safety skill
  • already held ICT security standards knowledge
  • already held attack vectors knowledge
  • already held communicate with stakeholders skill
  • already held cyber attack counter-measures knowledge
  • already held cyber security knowledge
  • already held engage with stakeholders skill
  • already held ethical hacking principles knowledge
  • already held implement ICT risk management skill
  • already held information security strategy knowledge
  • already held manage system security skill
  • already held security engineering knowledge
  • already held ICT encryption knowledge
  • already held ICT security legislation knowledge
  • already held Internet of Things knowledge
  • already held Open source model knowledge
  • already held Outsourcing model knowledge
  • already held computer forensics knowledge
  • already held define security policies skill
  • already held execute ICT audits skill
  • already held hybrid model knowledge
  • already held identify ICT security risks skill
  • already held implement ICT security policies skill
  • already held implement a firewall skill
  • already held information confidentiality knowledge
  • already held internet governance knowledge
  • already held legal requirements of ICT products knowledge
  • already held levels of software testing knowledge
  • already held organisational resilience knowledge
  • already held remove computer virus or malware from a computer skill
  • already held service-oriented modelling knowledge
  • already held solve ICT system problems skill
  • already held tools for ICT test automation knowledge
  • already held web application security threats knowledge
The 2 learning areas not shown above
Skill to acquire Tier
07 working with computers 8 supplementary
  • optional, not held develop with cloud services optional
  • optional, not held implement a virtual private network optional
  • optional, not held implement anti-virus software optional
  • optional, not held implement spam protection optional
  • optional, not held manage keys for data protection optional
  • optional, not held use an application-specific interface optional
  • optional, not held use ICT ticketing system optional
  • optional, not held use back-up and recovery tools optional
08 communication, collaboration and creativity 1 supplementary
  • optional, not held design for organisational complexity optional
28 supplementary skills, helpful but not required
Skill to acquire Tier
  • optional, not held ICT problem management techniques optional
  • optional, not held ICT process quality models optional
  • optional, not held ICT project management optional
  • optional, not held ICT quality policy optional
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held decision support systems optional
  • optional, not held define technology strategy optional
  • optional, not held design for organisational complexity optional
  • optional, not held develop information security strategy optional
  • optional, not held develop with cloud services optional
  • optional, not held domain name service optional
  • optional, not held implement a virtual private network optional
  • optional, not held implement anti-virus software optional
  • optional, not held implement cloud security and compliance optional
  • optional, not held implement spam protection optional
  • optional, not held investment analysis optional
  • optional, not held lead disaster recovery exercises optional
  • optional, not held manage keys for data protection optional
  • optional, not held mobile device management optional
  • optional, not held use an application-specific interface optional
  • optional, not held audit techniques optional
  • optional, not held manage disaster recovery plans optional
  • optional, not held systems development life-cycle optional
  • optional, not held use ICT ticketing system optional
  • optional, not held use back-up and recovery tools optional
39 held skills the cybersecurity risk manager role does not ask for
Skill Type
  • not needed by the target role Aircrack (penetration testing tool) knowledge
  • not needed by the target role Backbox (penetration testing tool) knowledge
  • not needed by the target role BlackArch knowledge
  • not needed by the target role Cain and Abel (penetration testing tool) knowledge
  • not needed by the target role ICT infrastructure knowledge
  • not needed by the target role ICT system integration knowledge
  • not needed by the target role John The Ripper (penetration testing tool) knowledge
  • not needed by the target role Kali Linux knowledge
  • not needed by the target role Maltego knowledge
  • not needed by the target role Metasploit knowledge
  • not needed by the target role Nessus knowledge
  • not needed by the target role Nexpose knowledge
  • not needed by the target role OWASP ZAP knowledge
  • not needed by the target role Parrot Security OS knowledge
  • not needed by the target role Samurai Web Testing Framework knowledge
  • not needed by the target role WhiteHat Sentinel knowledge
  • not needed by the target role Wireshark knowledge
  • not needed by the target role address problems critically skill
  • not needed by the target role analyse the context of an organisation skill
  • not needed by the target role building systems monitoring technology knowledge
  • not needed by the target role computer programming knowledge
  • not needed by the target role conduct ICT code review skill
  • not needed by the target role develop code exploits skill
  • not needed by the target role ethics knowledge
  • not needed by the target role execute social engineering tests skill
  • not needed by the target role execute software tests skill
  • not needed by the target role identify ICT system weaknesses skill
  • not needed by the target role maintain ICT server skill
  • not needed by the target role manage IT security compliances skill
  • not needed by the target role manage cloud data and storage skill
  • not needed by the target role monitor system performance skill
  • not needed by the target role operating systems knowledge
  • not needed by the target role penetration testing tool knowledge
  • not needed by the target role perform ICT security testing skill
  • not needed by the target role perform project management skill
  • not needed by the target role proxy servers knowledge
  • not needed by the target role set up cybersecurity training programmes skill
  • not needed by the target role software anomalies knowledge
  • not needed by the target role use scripting programming skill
19 gaps that are knowledge rather than practice

Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.

Skill to acquire Tier
  • required, not held ICT performance analysis methods required
  • required, not held internal risk management policy required
  • required, not held assessment of risks and threats required
  • required, not held risk management required
  • required, not held security threats required
  • optional, not held ICT problem management techniques optional
  • optional, not held ICT process quality models optional
  • optional, not held ICT project management optional
  • optional, not held ICT quality policy optional
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held decision support systems optional
  • optional, not held domain name service optional
  • optional, not held investment analysis optional
  • optional, not held mobile device management optional
  • optional, not held audit techniques optional
  • optional, not held systems development life-cycle optional
Index
Note

How this record was compiled

Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.