ICT security administratortoethical hacker
A ICT security administrator already meets 42% of what the ethical hacker role asks for. The move turns on 20 required skills not yet in the profile.
42%
70.7/ 100
1 Share of the ethical hacker role’s weighted skill requirement already met by the ICT security administrator profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A ethical hacker role treats 16 of its required skills as things a ICT security administrator already does. These are the ones it depends on most.
- ICT infrastructure
- ICT network security risks
- ICT security standards
- address problems critically
- computer forensics
- cyber attack counter-measures
What stands in the way is 20 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 29 skills that carry over, these are the ones fewest other occupations ask for. A ethical hacker role needs them, and most people applying for one will not have them already. This is the part of a ICT security administrator background worth leading with.
- already held computer forensics information and communication technologies (icts)
- already held web application security threats information and communication technologies (icts)
- already held ethical hacking principles information and communication technologies (icts)
- already held operating systems information and communication technologies (icts)
- already held ICT safety working with computers
- already held identify ICT system weaknesses working with computers
All 29 carried skills, including the 16 the ethical hacker role treats as required.
Table 3 · What you would need to learn
The 45 missing skills fall into 9 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held ICT system integration required
- required, not held attack vectors required
- required, not held penetration testing tool required
- required, not held software anomalies required
- required, not held tools for ICT test automation required
- required, not held computer programming required
- optional, not held Aircrack (penetration testing tool) optional
- optional, not held Backbox (penetration testing tool) optional
- optional, not held BlackArch optional
- optional, not held Cain and Abel (penetration testing tool) optional
- optional, not held John The Ripper (penetration testing tool) optional
- optional, not held Kali Linux optional
- optional, not held Maltego optional
- optional, not held Metasploit optional
- optional, not held Nessus optional
- optional, not held Nexpose optional
- optional, not held OWASP ZAP optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held Parrot Security OS optional
- optional, not held Samurai Web Testing Framework optional
- optional, not held WhiteHat Sentinel optional
- optional, not held Wireshark optional
- optional, not held hybrid model optional
- optional, not held levels of software testing optional
- optional, not held proxy servers optional
- optional, not held service-oriented modelling optional
- required, not held conduct ICT code review required
- required, not held develop code exploits required
- required, not held manage system security required
- required, not held perform ICT security testing required
- optional, not held maintain ICT server optional
- required, not held execute social engineering tests required
- required, not held identify ICT security risks required
- required, not held implement ICT risk management required
- required, not held analyse the context of an organisation required
- required, not held communicate with stakeholders required
- required, not held engage with stakeholders required
- optional, not held set up cybersecurity training programmes optional
- required, not held ethics required
- required, not held legal requirements of ICT products required
3 further areas in the appendix
Table 4 · Where to start
The 3 entries a ethical hacker role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 ICT system integration knowledge · sector specific
- 02 attack vectors knowledge · sector specific
- 03 building systems monitoring technology knowledge · sector specific
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 29 skills that carry over
- already held ICT infrastructure knowledge
- already held ICT network security risks knowledge
- already held ICT security standards knowledge
- already held address problems critically skill
- already held computer forensics knowledge
- already held cyber attack counter-measures knowledge
- already held cyber security knowledge
- already held ethical hacking principles knowledge
- already held execute ICT audits skill
- already held execute software tests skill
- already held identify ICT system weaknesses skill
- already held information security strategy knowledge
- already held operating systems knowledge
- already held security engineering knowledge
- already held use scripting programming skill
- already held web application security threats knowledge
- already held ICT encryption knowledge
- already held ICT safety skill
- already held ICT security legislation knowledge
- already held Internet of Things knowledge
- already held implement ICT security policies skill
- already held implement a firewall skill
- already held information confidentiality knowledge
- already held internet governance knowledge
- already held manage IT security compliances skill
- already held manage cloud data and storage skill
- already held organisational resilience knowledge
- already held remove computer virus or malware from a computer skill
- already held solve ICT system problems skill
The 3 learning areas not shown above
- required, not held monitor system performance required
- required, not held building systems monitoring technology required
- optional, not held define security policies optional
- optional, not held perform project management optional
25 supplementary skills, helpful but not required
- optional, not held Aircrack (penetration testing tool) optional
- optional, not held Backbox (penetration testing tool) optional
- optional, not held BlackArch optional
- optional, not held Cain and Abel (penetration testing tool) optional
- optional, not held John The Ripper (penetration testing tool) optional
- optional, not held Kali Linux optional
- optional, not held Maltego optional
- optional, not held Metasploit optional
- optional, not held Nessus optional
- optional, not held Nexpose optional
- optional, not held OWASP ZAP optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held Parrot Security OS optional
- optional, not held Samurai Web Testing Framework optional
- optional, not held WhiteHat Sentinel optional
- optional, not held Wireshark optional
- optional, not held define security policies optional
- optional, not held hybrid model optional
- optional, not held levels of software testing optional
- optional, not held maintain ICT server optional
- optional, not held proxy servers optional
- optional, not held service-oriented modelling optional
- optional, not held set up cybersecurity training programmes optional
- optional, not held perform project management optional
30 held skills the ethical hacker role does not ask for
- not needed by the target role apply company policies skill
- not needed by the target role assess ICT knowledge skill
- not needed by the target role attend to ICT systems quality skill
- not needed by the target role build business relationships skill
- not needed by the target role cloud monitoring and reporting knowledge
- not needed by the target role cloud security and compliance knowledge
- not needed by the target role database development tools knowledge
- not needed by the target role ensure proper document management skill
- not needed by the target role implement a virtual private network skill
- not needed by the target role implement anti-virus software skill
- not needed by the target role implement cloud security and compliance skill
- not needed by the target role interpret technical texts skill
- not needed by the target role lead disaster recovery exercises skill
- not needed by the target role maintain ICT identity management skill
- not needed by the target role maintain database security skill
- not needed by the target role manage ICT data architecture skill
- not needed by the target role manage ICT virtualisation environments skill
- not needed by the target role manage database skill
- not needed by the target role manage keys for data protection skill
- not needed by the target role mobile device management knowledge
- not needed by the target role network standards knowledge
- not needed by the target role perform ICT troubleshooting skill
- not needed by the target role perform backups skill
- not needed by the target role protect personal data and privacy skill
- not needed by the target role quality assurance methodologies knowledge
- not needed by the target role respond to incidents in cloud skill
- not needed by the target role store digital data and systems skill
- not needed by the target role system backup best practice knowledge
- not needed by the target role telecom regulations knowledge
- not needed by the target role train employees skill
30 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held ICT system integration required
- required, not held attack vectors required
- required, not held building systems monitoring technology required
- required, not held penetration testing tool required
- required, not held software anomalies required
- required, not held tools for ICT test automation required
- required, not held computer programming required
- required, not held ethics required
- required, not held legal requirements of ICT products required
- optional, not held Aircrack (penetration testing tool) optional
- optional, not held Backbox (penetration testing tool) optional
- optional, not held BlackArch optional
- optional, not held Cain and Abel (penetration testing tool) optional
- optional, not held John The Ripper (penetration testing tool) optional
- optional, not held Kali Linux optional
- optional, not held Maltego optional
- optional, not held Metasploit optional
- optional, not held Nessus optional
- optional, not held Nexpose optional
- optional, not held OWASP ZAP optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held Parrot Security OS optional
- optional, not held Samurai Web Testing Framework optional
- optional, not held WhiteHat Sentinel optional
- optional, not held Wireshark optional
- optional, not held hybrid model optional
- optional, not held levels of software testing optional
- optional, not held proxy servers optional
- optional, not held service-oriented modelling optional
Other moves recorded from ICT security administrator
- director of compliance and information security 50% covered · moderate
- cybersecurity risk manager 39% covered · substantial
- cyber incident responder 36% covered · substantial
- ICT resilience manager 35% covered · substantial
- ICT system administrator 35% covered · substantial
- chief ICT security officer 34% covered · career change
- embedded systems security engineer 33% covered · substantial
- cloud engineer 32% covered · career change
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.