ethical hackertodirector of compliance and information security
A ethical hacker already meets 58% of what the director of compliance and information security role asks for. The move turns on 5 required skills not yet in the profile.
58%
35.1/ 100
1 Share of the director of compliance and information security role’s weighted skill requirement already met by the ethical hacker profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A director of compliance and information security role treats 7 of its required skills as things a ethical hacker already does. These are the ones it depends on most.
- ICT security legislation
- ICT security standards
- cyber security
- implement ICT risk management
- implement ICT security policies
- information security strategy
What stands in the way is 5 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 7 skills that carry over, these are the ones fewest other occupations ask for. A director of compliance and information security role needs them, and most people applying for one will not have them already. This is the part of a ethical hacker background worth leading with.
- already held manage IT security compliances working with computers
- already held implement ICT risk management information skills
- already held ICT security standards information and communication technologies (icts)
- already held information security strategy information and communication technologies (icts)
- already held cyber security services
- already held ICT security legislation business, administration and law
All 7 carried skills, including the 7 the director of compliance and information security role treats as required.
Table 3 · What you would need to learn
The 5 missing skills fall into 4 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held ensure compliance with policies required
- required, not held lead a team required
- required, not held ensure compliance with legal requirements required
- required, not held cooperate with colleagues required
- required, not held keep up-to-date with regulations required
Table 4 · Where to start
The 3 entries a director of compliance and information security role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 cooperate with colleagues skill · cross sector
- 02 ensure compliance with legal requirements skill · cross sector
- 03 ensure compliance with policies skill · cross sector
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 7 skills that carry over
- already held ICT security legislation knowledge
- already held ICT security standards knowledge
- already held cyber security knowledge
- already held implement ICT risk management skill
- already held implement ICT security policies skill
- already held information security strategy knowledge
- already held manage IT security compliances skill
0 supplementary skills, helpful but not required
67 held skills the director of compliance and information security role does not ask for
- not needed by the target role Aircrack (penetration testing tool) knowledge
- not needed by the target role Backbox (penetration testing tool) knowledge
- not needed by the target role BlackArch knowledge
- not needed by the target role Cain and Abel (penetration testing tool) knowledge
- not needed by the target role ICT encryption knowledge
- not needed by the target role ICT infrastructure knowledge
- not needed by the target role ICT network security risks knowledge
- not needed by the target role ICT safety skill
- not needed by the target role ICT system integration knowledge
- not needed by the target role Internet of Things knowledge
- not needed by the target role John The Ripper (penetration testing tool) knowledge
- not needed by the target role Kali Linux knowledge
- not needed by the target role Maltego knowledge
- not needed by the target role Metasploit knowledge
- not needed by the target role Nessus knowledge
- not needed by the target role Nexpose knowledge
- not needed by the target role OWASP ZAP knowledge
- not needed by the target role Open source model knowledge
- not needed by the target role Outsourcing model knowledge
- not needed by the target role Parrot Security OS knowledge
- not needed by the target role Samurai Web Testing Framework knowledge
- not needed by the target role WhiteHat Sentinel knowledge
- not needed by the target role Wireshark knowledge
- not needed by the target role address problems critically skill
- not needed by the target role analyse the context of an organisation skill
- not needed by the target role attack vectors knowledge
- not needed by the target role building systems monitoring technology knowledge
- not needed by the target role communicate with stakeholders skill
- not needed by the target role computer forensics knowledge
- not needed by the target role computer programming knowledge
- not needed by the target role conduct ICT code review skill
- not needed by the target role cyber attack counter-measures knowledge
- not needed by the target role define security policies skill
- not needed by the target role develop code exploits skill
- not needed by the target role engage with stakeholders skill
- not needed by the target role ethical hacking principles knowledge
- not needed by the target role ethics knowledge
- not needed by the target role execute ICT audits skill
- not needed by the target role execute social engineering tests skill
- not needed by the target role execute software tests skill
27 further entries not listed here
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.