Career Overlap Transition record Edition 1 · ESCO v1.2.1
Table 1Transition record

IT auditortodirector of compliance and information security

A IT auditor already meets 42% of what the director of compliance and information security role asks for. The move turns on 7 required skills not yet in the profile.

From IT auditor
42%
Overlap1
To director of compliance and information security
5 Skills carried over
7 Required, not held
49.7 Difficulty2
adjacent 0–30
moderate 30–55
substantial 55–75
career change 75–100
this move, 49.7

This move: 49.7 of 100 · moderate

1 Share of the director of compliance and information security role’s weighted skill requirement already met by the IT auditor profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.

Table 2

Table 2 · What you already bring

Of the 5 skills that carry over, these are the ones fewest other occupations ask for. A director of compliance and information security role needs them, and most people applying for one will not have them already. This is the part of a IT auditor background worth leading with.

Skill the target role also needs Area
  • already held manage IT security compliances working with computers
  • already held ICT security standards information and communication technologies (icts)
  • already held information security strategy information and communication technologies (icts)
  • already held cyber security services
  • already held ICT security legislation business, administration and law

All 5 carried skills, including the 5 the director of compliance and information security role treats as required.

Table 3

Table 3 · What you would need to learn

The 7 missing skills fall into 5 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.

Skill to acquire Tier
01 information skills 2 required
  • required, not held implement ICT risk management required
  • required, not held keep up-to-date with regulations required
02 management skills 2 required
  • required, not held ensure compliance with policies required
  • required, not held lead a team required
03 assisting and caring 1 required
  • required, not held ensure compliance with legal requirements required
04 communication, collaboration and creativity 1 required
  • required, not held cooperate with colleagues required
05 working with computers 1 required
  • required, not held implement ICT security policies required
Table 4

Table 4 · Where to start

The 3 entries a director of compliance and information security role is least likely to hire without. The ordering is computed from the skill data, not from what pays.

Each entry opens a course search for that skill. Career Overlap earns nothing from these links.

Appendix

Appendix · The rest of the record

All 5 skills that carry over
Skill Type
  • already held ICT security legislation knowledge
  • already held ICT security standards knowledge
  • already held cyber security knowledge
  • already held information security strategy knowledge
  • already held manage IT security compliances skill
0 supplementary skills, helpful but not required
Skill to acquire Tier
32 held skills the director of compliance and information security role does not ask for
Skill Type
  • not needed by the target role ICT accessibility standards knowledge
  • not needed by the target role ICT network security risks knowledge
  • not needed by the target role ICT process quality models knowledge
  • not needed by the target role ICT project management knowledge
  • not needed by the target role ICT quality policy knowledge
  • not needed by the target role World Wide Web Consortium standards knowledge
  • not needed by the target role analyse ICT system skill
  • not needed by the target role apply information security policies skill
  • not needed by the target role audit techniques knowledge
  • not needed by the target role cloud technologies knowledge
  • not needed by the target role communicate analytical insights skill
  • not needed by the target role define organisational standards skill
  • not needed by the target role develop ICT workflow skill
  • not needed by the target role develop audit plan skill
  • not needed by the target role develop documentation in accordance with legal requirements skill
  • not needed by the target role engineering processes knowledge
  • not needed by the target role ensure adherence to organisational ICT standards skill
  • not needed by the target role execute ICT audits skill
  • not needed by the target role identify ICT security risks skill
  • not needed by the target role identify legal requirements skill
  • not needed by the target role improve business processes skill
  • not needed by the target role inform on workplace safety standards skill
  • not needed by the target role legal requirements of ICT products knowledge
  • not needed by the target role monitor technology trends skill
  • not needed by the target role organisational resilience knowledge
  • not needed by the target role perform ICT security testing skill
  • not needed by the target role perform quality audits skill
  • not needed by the target role prepare financial auditing reports skill
  • not needed by the target role product life-cycle knowledge
  • not needed by the target role protect personal data and privacy skill
  • not needed by the target role quality standards knowledge
  • not needed by the target role systems development life-cycle knowledge
Index
Note

How this record was compiled

Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.