Files
2026-08-14 17:33:39 +02:00

3.7 KiB
Raw Permalink Blame History

name, description
name description
cyber-incident-responder Occupational skill for the role 'cyber incident responder' (also: ICT security consultant, cyber crisis expert, information technology security consultant, security operations center analyst, cyber incident handler, information communications technology security consultant). Use when the user asks for typical cyber incident responder work such as: Train users and promote security awareness to ensure system security and to improve server and network efficiency.; Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.; Confer with users to discuss issues such as computer data access needs, security violations, and programming changes.

Cyber Incident Responder

Cyber incident responders monitor and assess cybersecurity state systems, analysing, evaluating, and mitigating the impact of cybersecurity incidents. Moreover, they identify malicious actors and cyber incidents root causes. According to the organisations Incident Response Plan, they restore systems and process functionalities to an operational state, collecting evidence and documenting actions taken.

Core workflow

  1. Train users and promote security awareness to ensure system security and to improve server and network efficiency.
  2. Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
  3. Confer with users to discuss issues such as computer data access needs, security violations, and programming changes.
  4. Monitor current reports of computer viruses to determine when to update virus protection systems.
  5. Modify computer security files to incorporate new software, correct errors, or change individual access status.
  6. Coordinate implementation of computer system plan with establishment personnel and outside vendors.
  7. Monitor use of data files and regulate access to safeguard information in computer files.
  8. Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures.

How to use this skill

Key competences (essential)

  • attack vectors
  • building systems monitoring technology
  • collect cyber defence data
  • communicate with stakeholders
  • create incident reports
  • cyber attack counter-measures
  • cyber security
  • engage with stakeholders
  • ethical hacking principles
  • GDPR
  • handle cybersecurity incidents
  • ICT network security risks
  • ICT safety
  • ICT security legislation
  • ICT security standards

Hot technologies

  • SAS
  • The MathWorks MATLAB
  • Docker
  • GitHub
  • Red Hat OpenShift
  • Apache Spark
  • Tableau
  • Amazon Web Services AWS CloudFormation
  • Splunk Enterprise
  • Chef

Hot technologies

Top tools from 48 gated job ads (see references/market.md, as of 2026-07-11):

  • Splunk — 23 %
  • SIEM — 21 %
  • Wireshark — 12 %
  • AWS — 8 %
  • EDR — 8 %
  • Microsoft Excel — 8 %
  • Remedy — 8 %
  • Crowdstrike — 6 %
  • Python — 6 %

Sources: ESCO v1.2.1 (http://data.europa.eu/esco/occupation/0ce5a9f4-e00a-4bbe-b255-3c63407167a4), ONET 30.3 (15-1212.00). See manifest.json for licensing/attribution.*