ICT security administratortoICT resilience manager
A ICT security administrator already meets 35% of what the ICT resilience manager role asks for. The move turns on 13 required skills not yet in the profile.
35%
68.3/ 100
1 Share of the ICT resilience manager role’s weighted skill requirement already met by the ICT security administrator profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A ICT resilience manager role treats 7 of its required skills as things a ICT security administrator already does. These are the ones it depends on most.
- cyber security
- execute ICT audits
- lead disaster recovery exercises
- manage IT security compliances
- organisational resilience
- security engineering
What stands in the way is 13 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 15 skills that carry over, these are the ones fewest other occupations ask for. A ICT resilience manager role needs them, and most people applying for one will not have them already. This is the part of a ICT security administrator background worth leading with.
- already held respond to incidents in cloud communication, collaboration and creativity
- already held lead disaster recovery exercises management skills
- already held system backup best practice information and communication technologies (icts)
- already held ICT safety working with computers
- already held ethical hacking principles information and communication technologies (icts)
- already held manage keys for data protection working with computers
All 15 carried skills, including the 7 the ICT resilience manager role treats as required.
Table 3 · What you would need to learn
The 27 missing skills fall into 7 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held identify ICT security risks required
- required, not held implement ICT risk management required
- required, not held analyse business processes required
- required, not held analyse the context of an organisation required
- optional, not held analyse business requirements optional
- optional, not held provide cost benefit analysis reports optional
- required, not held implement ICT recovery system required
- required, not held manage system security required
- required, not held perform ICT security testing required
- required, not held develop contingency plans for emergencies required
- required, not held manage disaster recovery plans required
- optional, not held coordinate technological activities optional
- optional, not held define security policies optional
- optional, not held implement a management system optional
- optional, not held manage budgets optional
- optional, not held perform project management optional
- required, not held develop information security strategy required
- required, not held comply with legal regulations required
- required, not held ICT recovery techniques required
- optional, not held ICT process quality models optional
- optional, not held ICT system user requirements optional
- optional, not held core banking software optional
- optional, not held human-computer interaction optional
- required, not held internal risk management policy required
- optional, not held business process modelling optional
1 further area in the appendix
Table 4 · Where to start
The 3 entries a ICT resilience manager role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 ICT recovery techniques knowledge · sector specific
- 02 develop contingency plans for emergencies skill · sector specific
- 03 develop information security strategy skill · sector specific
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 15 skills that carry over
- already held cyber security knowledge
- already held execute ICT audits skill
- already held lead disaster recovery exercises skill
- already held manage IT security compliances skill
- already held organisational resilience knowledge
- already held security engineering knowledge
- already held system backup best practice knowledge
- already held ICT network security risks knowledge
- already held ICT safety skill
- already held build business relationships skill
- already held cloud security and compliance knowledge
- already held ethical hacking principles knowledge
- already held manage keys for data protection skill
- already held respond to incidents in cloud skill
- already held train employees skill
The 1 learning area not shown above
- optional, not held advise on strengthening security optional
- optional, not held perform procurement processes optional
14 supplementary skills, helpful but not required
- optional, not held ICT process quality models optional
- optional, not held ICT system user requirements optional
- optional, not held advise on strengthening security optional
- optional, not held business process modelling optional
- optional, not held coordinate technological activities optional
- optional, not held core banking software optional
- optional, not held define security policies optional
- optional, not held human-computer interaction optional
- optional, not held analyse business requirements optional
- optional, not held implement a management system optional
- optional, not held manage budgets optional
- optional, not held perform procurement processes optional
- optional, not held perform project management optional
- optional, not held provide cost benefit analysis reports optional
44 held skills the ICT resilience manager role does not ask for
- not needed by the target role ICT encryption knowledge
- not needed by the target role ICT infrastructure knowledge
- not needed by the target role ICT security legislation knowledge
- not needed by the target role ICT security standards knowledge
- not needed by the target role Internet of Things knowledge
- not needed by the target role address problems critically skill
- not needed by the target role apply company policies skill
- not needed by the target role assess ICT knowledge skill
- not needed by the target role attend to ICT systems quality skill
- not needed by the target role cloud monitoring and reporting knowledge
- not needed by the target role computer forensics knowledge
- not needed by the target role cyber attack counter-measures knowledge
- not needed by the target role database development tools knowledge
- not needed by the target role ensure proper document management skill
- not needed by the target role execute software tests skill
- not needed by the target role identify ICT system weaknesses skill
- not needed by the target role implement ICT security policies skill
- not needed by the target role implement a firewall skill
- not needed by the target role implement a virtual private network skill
- not needed by the target role implement anti-virus software skill
- not needed by the target role implement cloud security and compliance skill
- not needed by the target role information confidentiality knowledge
- not needed by the target role information security strategy knowledge
- not needed by the target role internet governance knowledge
- not needed by the target role interpret technical texts skill
- not needed by the target role maintain ICT identity management skill
- not needed by the target role maintain database security skill
- not needed by the target role manage ICT data architecture skill
- not needed by the target role manage ICT virtualisation environments skill
- not needed by the target role manage cloud data and storage skill
- not needed by the target role manage database skill
- not needed by the target role mobile device management knowledge
- not needed by the target role network standards knowledge
- not needed by the target role operating systems knowledge
- not needed by the target role perform ICT troubleshooting skill
- not needed by the target role perform backups skill
- not needed by the target role protect personal data and privacy skill
- not needed by the target role quality assurance methodologies knowledge
- not needed by the target role remove computer virus or malware from a computer skill
- not needed by the target role solve ICT system problems skill
4 further entries not listed here
7 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held ICT recovery techniques required
- required, not held internal risk management policy required
- optional, not held ICT process quality models optional
- optional, not held ICT system user requirements optional
- optional, not held business process modelling optional
- optional, not held core banking software optional
- optional, not held human-computer interaction optional
Other moves recorded from ICT security administrator
- director of compliance and information security 50% covered · moderate
- ethical hacker 42% covered · substantial
- cybersecurity risk manager 39% covered · substantial
- cyber incident responder 36% covered · substantial
- ICT system administrator 35% covered · substantial
- chief ICT security officer 34% covered · career change
- embedded systems security engineer 33% covered · substantial
- cloud engineer 32% covered · career change
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.