feat: cybersecurity-risk-manager skill package v0.1.0

This commit is contained in:
skillfactor-pipeline
2026-08-14 17:33:55 +02:00
commit 331e895cea
9 changed files with 838 additions and 0 deletions

31
PROVENANCE.md Normal file
View File

@@ -0,0 +1,31 @@
# Data provenance — cybersecurity-risk-manager
Where the content of this skill package comes from, counted by
content items (tasks, competences, tools, evidence entries, curated
knowledge). Rendered live by Gitea:
```mermaid
%%{init: {'theme':'base','themeVariables':{'pie1':'#f9a825','pie2':'#1e88e5','pie3':'#ff355e','pie4':'#d97757','pie5':'#8e24aa','pieOuterStrokeWidth':'0px','pieSectionTextColor':'#fff'}}}%%
pie showData
title Content sources — cybersecurity-risk-manager
"ESCO (occupation & competences)" : 73
"O*NET (tasks & tools)" : 80
"Job boards (market evidence)" : 104
"Anthropic official Claude skills" : 9
"External AI skill packs (mapped)" : 110
```
| Source | Items | Share | Files |
|---|---|---|---|
| ESCO (occupation & competences) | 73 | 19.4 % | references/profile.md, references/skills.md |
| O*NET (tasks & tools) | 80 | 21.3 % | references/tasks.md, references/tools.md |
| Job boards (market evidence) | 104 | 27.7 % | references/market.md (full report) + "Market evidence" headline sections |
| Wikipedia & AI expert curation | 0 | 0.0 % | glossary, literature, usecases, intake, quality, evals/ |
| Anthropic official Claude skills | 9 | 2.4 % | references/ai-skills.md, section "anthropics/skills" (official Claude Code skills) |
| External AI skill packs (mapped) | 110 | 29.3 % | references/ai-skills.md (per-source attribution inside) |
| Stack Exchange practitioner Q&A (CC-BY-SA) | 0 | 0.0 % | references/practitioner-qa.md (per-entry attribution inside) |
Licensing: O*NET (USDOL/ETA, CC BY 4.0) · ESCO (© European Union) ·
job-ad evidence via official APIs (JSearch/Adzuna) · Wikipedia content
paraphrased with source URLs — never copied · external AI skills are
linked, not copied (Apache-2.0/MIT/source-available, see ai-skills.md).

78
SKILL.md Normal file
View File

@@ -0,0 +1,78 @@
---
name: cybersecurity-risk-manager
description: "Occupational skill for the role 'cybersecurity risk manager' (also: cybersecurity specialist, cybersecurity risk assurance consultant, information security manager, cyber risk manager, cybersecurity risk assessor, IT security chief). Use when the user asks for typical cybersecurity risk manager work such as: Write reports to summarize testing activities, including descriptions of goals, planning, scheduling, execution, results, analysis, conclusions, and recommendations.; Maintain and update organization information technology applications and network systems blueprints.; Interpret government regulations and applicable codes to ensure compliance."
---
# Cybersecurity Risk Manager
Cybersecurity risk managers identify, analyse, assess, estimate and mitigate cybersecurity-related risks of ICT infrastructures such as systems or services. They manage these aspects by planning risk analysis, applying, reporting, assessing, communicating, and treating them. They establish a risk management strategy for the organisation and ensure that risks remain at an acceptable level for the organisation by selecting mitigation actions and controls.
## Core workflow
1. Write reports to summarize testing activities, including descriptions of goals, planning, scheduling, execution, results, analysis, conclusions, and recommendations.
2. Maintain and update organization information technology applications and network systems blueprints.
3. Interpret government regulations and applicable codes to ensure compliance.
4. Establish, maintain, or test call trees to ensure appropriate communication during disaster.
5. Design or implement products and services to mitigate risk or facilitate use of technology-based tools and methods.
6. Create business continuity and disaster recovery budgets.
7. Create or administer training and awareness presentations or materials.
8. Attend professional meetings, read literature, and participate in training or other educational offerings to keep abreast of new developments and technologies related to disaster recovery and business continuity.
## How to use this skill
- Read [references/profile.md](references/profile.md) for the occupation profile and scope.
- Consult [references/tasks.md](references/tasks.md) for the full task and activity inventory.
- Check [references/skills.md](references/skills.md) for essential vs. optional competences.
- Check [references/tools.md](references/tools.md) for the software commonly used in this role.
- See [references/ai-skills.md](references/ai-skills.md) — matched external AI agent skills (per-source attribution).
## Key competences (essential)
- advice on security risk management
- assessment of risks and threats
- attack vectors
- communicate with stakeholders
- cyber attack counter-measures
- cyber security
- engage with stakeholders
- ensure adherence to organisational ICT standards
- establish an ICT security prevention plan
- establish an Information Security Management System
- ethical hacking principles
- ICT network security risks
- ICT performance analysis methods
- ICT safety
- ICT security standards
## Hot technologies
- Atlassian JIRA
- Teradata Database
- Microsoft Access
- Microsoft SQL Server
- ServiceNow
- Structured query language SQL
- Adobe Acrobat
- Microsoft SharePoint
- Microsoft Outlook
- Microsoft Office software
<!-- hot-tech -->
## Hot technologies
Top tools from 55 gated job ads (see references/market.md, as of 2026-07-11):
- Archer — 7 %
- Nessus — 7 %
- AWS — 5 %
- Microsoft Excel — 5 %
- Microsoft Office — 5 %
- ServiceNow — 5 %
- SharePoint — 5 %
<!-- hot-tech -->
---
*Sources: ESCO v1.2.1 (http://data.europa.eu/esco/occupation/7754d570-9519-48c2-b1c9-8e165f8bca0f), O*NET 30.3 (13-1199.04). See manifest.json for licensing/attribution.*

148
manifest.json Normal file
View File

@@ -0,0 +1,148 @@
{
"name": "cybersecurity-risk-manager",
"title": "cybersecurity risk manager",
"version": "0.1.0",
"layer": "core",
"language": "en",
"generated": "2026-07-07",
"ids": {
"esco_uri": "http://data.europa.eu/esco/occupation/7754d570-9519-48c2-b1c9-8e165f8bca0f",
"esco_code": "2529.8",
"isco_group": "2529",
"onet_soc": "13-1199.04",
"crosswalk_match": "closeMatch"
},
"sources": [
{
"name": "ESCO",
"version": "1.2.1",
"url": "https://esco.ec.europa.eu/"
},
{
"name": "O*NET",
"version": "30.3",
"url": "https://www.onetcenter.org/",
"license": "CC BY 4.0"
}
],
"attribution": "This package includes information from the O*NET Database (v30.3) by the U.S. Department of Labor, Employment and Training Administration (USDOL/ETA), CC BY 4.0. skillfactor is not endorsed by USDOL/ETA. ESCO data (v1.2.1) (c) European Union, used per the ESCO download conditions: https://esco.ec.europa.eu/en/use-esco/download",
"counts": {
"tasks": 21,
"dwas": 20,
"skills_essential": 22,
"skills_optional": 50,
"software": 38
},
"enrichment_ai_skills": {
"generated": "2026-07-14",
"method": "deterministic mapping (ISCO prefix + title/competence keywords)",
"sources": {
"anthropics/skills": {
"repo": "https://github.com/anthropics/skills",
"commit": "f6656c1",
"license": "Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available \u2014 see the LICENSE.txt in the upstream skill folder",
"skills": 6
},
"obra/superpowers": {
"repo": "https://github.com/obra/superpowers",
"commit": "d884ae0",
"license": "MIT (c) Jesse Vincent",
"skills": 12
},
"wshobson/agents": {
"repo": "https://github.com/wshobson/agents",
"commit": "6fd3247",
"license": "MIT (c) Seth Hobson",
"skills": 12
},
"NVIDIA/skills": {
"repo": "https://github.com/NVIDIA/skills",
"commit": "153b14b",
"license": "CC-BY-4.0 (skills/docs), Apache-2.0 (code)",
"skills": 12
},
"veniceai/skills": {
"repo": "https://github.com/veniceai/skills",
"commit": "de089fa",
"license": "MIT",
"skills": 5
},
"czlonkowski/n8n-skills": {
"repo": "https://github.com/czlonkowski/n8n-skills",
"commit": "9ea3aa5",
"license": "MIT",
"skills": 12
},
"a5c-ai/babysitter": {
"repo": "https://github.com/a5c-ai/babysitter",
"commit": "44a5d58b",
"license": "MIT",
"skills": 9
},
"mukul975/Anthropic-Cybersecurity-Skills": {
"repo": "https://github.com/mukul975/Anthropic-Cybersecurity-Skills",
"commit": "673da1f",
"license": "Apache-2.0",
"skills": 5
},
"Sushegaad/Claude-Skills-Governance-Risk-and-Compliance": {
"repo": "https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance",
"commit": "71d8920",
"license": "MIT",
"skills": 3
},
"davila7/claude-code-templates": {
"repo": "https://github.com/davila7/claude-code-templates",
"commit": "fa79251",
"license": "MIT",
"skills": 1
},
"samber/cc-skills-golang": {
"repo": "https://github.com/samber/cc-skills-golang",
"commit": "4881c01",
"license": "MIT",
"skills": 1
},
"vibeeval/vibecosystem": {
"repo": "https://github.com/vibeeval/vibecosystem",
"commit": "cea9462",
"license": "MIT",
"skills": 1
},
"itsmostafa/aws-agent-skills": {
"repo": "https://github.com/itsmostafa/aws-agent-skills",
"commit": "4ab904a",
"license": "MIT",
"skills": 1
}
},
"total_skills": 80,
"tiers": {
"core": 35,
"adjacent": 45
}
},
"provenance": {
"items": {
"esco": 73,
"onet": 80,
"jobads": 104,
"wiki_ai": 0,
"anthropic": 9,
"ai_skills": 110,
"stackx": 0
},
"share_percent": {
"esco": 19.4,
"onet": 21.3,
"jobads": 27.7,
"wiki_ai": 0.0,
"anthropic": 2.4,
"ai_skills": 29.3,
"stackx": 0.0
},
"method": "content items per source category"
},
"collar": "white",
"computer_work": true
}

202
references/ai-skills.md Normal file
View File

@@ -0,0 +1,202 @@
# External AI agent skills — cybersecurity-risk-manager
Proven, publicly available AI agent skills mapped to this occupation.
Nothing is copied from the sources: every entry is a name, a one-line
summary and a link to the upstream skill package. Each section names
its source repository, commit, license and retrieval date.
**Tiers:** `core` = the skill directly exercises a top market hard
skill, tool or method (from gated job-ad evidence) or an essential
ESCO competence of this occupation; `adjacent` =
plausibly useful, secondary. Entries are capped at 12 per source
and 80 in total per occupation (core first,
strongest matches survive); everything beyond the caps is excluded
and logged in the pipeline audit trail, not in this package.
_Matched deterministically (ISCO group + title/competence keywords,
tiered against market evidence + ESCO essentials) by
`pipeline/p5_enrich_ai_skills.py` on 2026-07-14._
## Source: anthropics/skills
- Repository: [https://github.com/anthropics/skills](https://github.com/anthropics/skills) (commit `f6656c1`, retrieved 2026-07-14)
- License: Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available — see the LICENSE.txt in the upstream skill folder
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `docx` | adjacent | Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to … | [source](https://github.com/anthropics/skills/tree/main/skills/docx) |
| `skill-creator` | adjacent | Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with … | [source](https://github.com/anthropics/skills/tree/main/skills/skill-creator) |
| `claude-api` | adjacent | Reference for the Claude API / Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model migration. TRIGGER — read BEFORE opening the target file; don't skip because it "looks like a … | [source](https://github.com/anthropics/skills/tree/main/skills/claude-api) |
| `mcp-builder` | adjacent | Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python … | [source](https://github.com/anthropics/skills/tree/main/skills/mcp-builder) |
| `pdf` | adjacent | Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text/tables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating … | [source](https://github.com/anthropics/skills/tree/main/skills/pdf) |
| `webapp-testing` | adjacent | Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs. | [source](https://github.com/anthropics/skills/tree/main/skills/webapp-testing) |
## Source: obra/superpowers
- Repository: [https://github.com/obra/superpowers](https://github.com/obra/superpowers) (commit `d884ae0`, retrieved 2026-07-14)
- License: MIT (c) Jesse Vincent
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `executing-plans` | adjacent | Use when you have a written implementation plan to execute in a separate session with review checkpoints | [source](https://github.com/obra/superpowers/tree/main/skills/executing-plans) |
| `finishing-a-development-branch` | adjacent | Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup | [source](https://github.com/obra/superpowers/tree/main/skills/finishing-a-development-branch) |
| `subagent-driven-development` | adjacent | Use when executing implementation plans with independent tasks in the current session | [source](https://github.com/obra/superpowers/tree/main/skills/subagent-driven-development) |
| `test-driven-development` | adjacent | Use when implementing any feature or bugfix, before writing implementation code | [source](https://github.com/obra/superpowers/tree/main/skills/test-driven-development) |
| `brainstorming` | adjacent | You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation. | [source](https://github.com/obra/superpowers/tree/main/skills/brainstorming) |
| `dispatching-parallel-agents` | adjacent | Use when facing 2+ independent tasks that can be worked on without shared state or sequential dependencies | [source](https://github.com/obra/superpowers/tree/main/skills/dispatching-parallel-agents) |
| `receiving-code-review` | adjacent | Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation | [source](https://github.com/obra/superpowers/tree/main/skills/receiving-code-review) |
| `requesting-code-review` | adjacent | Use when completing tasks, implementing major features, or before merging to verify work meets requirements | [source](https://github.com/obra/superpowers/tree/main/skills/requesting-code-review) |
| `systematic-debugging` | adjacent | Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes | [source](https://github.com/obra/superpowers/tree/main/skills/systematic-debugging) |
| `using-git-worktrees` | adjacent | Use when starting feature work that needs isolation from current workspace or before executing implementation plans - ensures an isolated workspace exists via native tools or git worktree fallback | [source](https://github.com/obra/superpowers/tree/main/skills/using-git-worktrees) |
| `verification-before-completion` | adjacent | Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims; evidence before assertions always | [source](https://github.com/obra/superpowers/tree/main/skills/verification-before-completion) |
| `writing-plans` | adjacent | Use when you have a spec or requirements for a multi-step task, before touching code | [source](https://github.com/obra/superpowers/tree/main/skills/writing-plans) |
## Source: wshobson/agents
- Repository: [https://github.com/wshobson/agents](https://github.com/wshobson/agents) (commit `6fd3247`, retrieved 2026-07-14)
- License: MIT (c) Seth Hobson
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `comprehensive-review-security-auditor (agent)` | core | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and … | [source](https://github.com/wshobson/agents/tree/main/plugins/comprehensive-review/agents/security-auditor.md) |
| `frontend-mobile-security-frontend-developer (agent)` | core | Build React components, implement responsive layouts, and handle client-side state management. Masters React 19, Next.js 15, and modern frontend architecture. Optimizes performance and ensures accessibility. Use PROACTIVELY when creating … | [source](https://github.com/wshobson/agents/tree/main/plugins/frontend-mobile-security/agents/frontend-developer.md) |
| `security-compliance-security-auditor (agent)` | core | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and … | [source](https://github.com/wshobson/agents/tree/main/plugins/security-compliance/agents/security-auditor.md) |
| `auth-implementation-patterns` | core | Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues. | [source](https://github.com/wshobson/agents/tree/main/plugins/developer-essentials/skills/auth-implementation-patterns) |
| `stride-analysis-patterns` | core | Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/stride-analysis-patterns) |
| `attack-tree-construction` | core | Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-construction) |
| `code-documentation-code-reviewer (agent)` | core | Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with … | [source](https://github.com/wshobson/agents/tree/main/plugins/code-documentation/agents/code-reviewer.md) |
| `code-refactoring-code-reviewer (agent)` | core | Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with … | [source](https://github.com/wshobson/agents/tree/main/plugins/code-refactoring/agents/code-reviewer.md) |
| `codebase-cleanup-code-reviewer (agent)` | core | Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with … | [source](https://github.com/wshobson/agents/tree/main/plugins/codebase-cleanup/agents/code-reviewer.md) |
| `comprehensive-review-code-reviewer (agent)` | core | Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with … | [source](https://github.com/wshobson/agents/tree/main/plugins/comprehensive-review/agents/code-reviewer.md) |
| `dependency-management-legacy-modernizer (agent)` | core | Refactor legacy codebases, migrate outdated frameworks, and implement gradual modernization. Handles technical debt, dependency updates, and backward compatibility. Use PROACTIVELY for legacy system updates, framework migrations, or … | [source](https://github.com/wshobson/agents/tree/main/plugins/dependency-management/agents/legacy-modernizer.md) |
| `git-pr-workflows-code-reviewer (agent)` | core | Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with … | [source](https://github.com/wshobson/agents/tree/main/plugins/git-pr-workflows/agents/code-reviewer.md) |
## Source: a5c-ai/babysitter
- Repository: [https://github.com/a5c-ai/babysitter](https://github.com/a5c-ai/babysitter) (commit `44a5d58b`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `risk-mitigation-planning` | core | Develop comprehensive risk management plans for collections and cultural venues including disaster preparedness, security protocols, and insurance coordination | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/social-sciences-humanities/arts-culture/skills/risk-mitigation-planning) |
| `bug-bounty` | core | Bug bounty program management and security disclosure expertise for smart contracts. Covers program setup on Immunefi, vulnerability triage, responsible disclosure coordination, bounty payments, and post-disclosure analysis. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/bug-bounty) |
| `multi-cloud-security-posture` | core | Unified cloud security posture management across AWS, Azure, and GCP with normalized metrics and CIS benchmark comparison | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-compliance/skills/multi-cloud-security-posture) |
| `security-sandbox` | core | Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage Docker-based analysis containers, and capture filesystem and … | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-research/skills/security-sandbox) |
| `vendor-risk-monitor` | core | Continuous vendor security monitoring for security ratings, breach notifications, and risk change detection | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-compliance/skills/vendor-risk-monitor) |
| `vendor-security-questionnaire` | core | Automated vendor security assessment through questionnaire generation, response parsing, and risk scoring | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-compliance/skills/vendor-security-questionnaire) |
| `vulnerability-scanner` | core | Security vulnerability scanning for dependencies and code, with CVE database checking and risk assessment | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/code-migration-modernization/skills/vulnerability-scanner) |
| `echidna-fuzzer` | core | Property-based testing and fuzzing using Echidna for smart contracts. Includes invariant definition, corpus management, coverage analysis, and CI/CD integration for comprehensive security testing. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/echidna-fuzzer) |
| `iso14971-risk-analyzer` | core | Comprehensive risk management skill implementing ISO 14971:2019 methodology for medical device risk analysis | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/science/biomedical-engineering/skills/iso14971-risk-analyzer) |
## Source: davila7/claude-code-templates
- Repository: [https://github.com/davila7/claude-code-templates](https://github.com/davila7/claude-code-templates) (commit `fa79251`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `senior-secops` | core | Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security scanning, vulnerability assessment, compliance checking, and security automation. Use when … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/senior-secops) |
## Source: itsmostafa/aws-agent-skills
- Repository: [https://github.com/itsmostafa/aws-agent-skills](https://github.com/itsmostafa/aws-agent-skills) (commit `4ab904a`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `ec2` | core | AWS EC2 virtual machine management — instances, security groups, key pairs, AMIs, EBS volumes, Auto Scaling Groups, Spot Instances, Session Manager, placement groups, and instance lifecycle automation. Trigger on ANY of these, even when … | [source](https://github.com/itsmostafa/aws-agent-skills/tree/4ab904a/skills/ec2) |
## Source: mukul975/Anthropic-Cybersecurity-Skills
- Repository: [https://github.com/mukul975/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills) (commit `673da1f`, retrieved 2026-07-14)
- License: Apache-2.0
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `executing-nist-rmf-authorization-to-operate` | core | Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP 800-53 Rev 5), Implement, Assess (SP … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/executing-nist-rmf-authorization-to-operate) |
| `implementing-api-security-posture-management` | core | Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle. | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-api-security-posture-management) |
| `deploying-palo-alto-prisma-access-zero-trust` | core | Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management. | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/deploying-palo-alto-prisma-access-zero-trust) |
| `performing-phishing-simulation-with-gophish` | core | GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-phishing-simulation-with-gophish) |
| `implementing-iec-62443-security-zones` | core | This skill covers designing and implementing security zones and conduits for industrial automation and control systems (IACS) per IEC 62443-3-2. It addresses zone partitioning based on risk assessment, assigning Security Level targets … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-iec-62443-security-zones) |
## Source: samber/cc-skills-golang
- Repository: [https://github.com/samber/cc-skills-golang](https://github.com/samber/cc-skills-golang) (commit `4881c01`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `golang-security` | core | Security best practices and vulnerability prevention for Golang. Covers injection (SQL, command, XSS), cryptography, filesystem safety, network security, cookies, secrets management, memory safety, and logging. Apply when writing, … | [source](https://github.com/samber/cc-skills-golang/tree/4881c01/skills/golang-security) |
## Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
- Repository: [https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) (commit `71d8920`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `nist-csf` | core | Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), … | [source](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/71d8920/plugins/nist-csf/skills/nist-csf) |
| `dora` | core | Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident … | [source](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/71d8920/plugins/dora/skills/dora) |
| `nist-ai-rmf` | core | Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four functions: GOVERN, MAP, MEASURE, MANAGE. Use this skill whenever a user asks about NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP … | [source](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/71d8920/plugins/nist-ai-rmf/skills/nist-ai-rmf) |
## Source: vibeeval/vibecosystem
- Repository: [https://github.com/vibeeval/vibecosystem](https://github.com/vibeeval/vibecosystem) (commit `cea9462`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `differential-review` | core | Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format. Adapted from Trail of Bits. Use when reviewing PRs, commits, or code … | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/differential-review) |
## Source: czlonkowski/n8n-skills
- Repository: [https://github.com/czlonkowski/n8n-skills](https://github.com/czlonkowski/n8n-skills) (commit `9ea3aa5`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `n8n-mcp-tools-expert` | adjacent | Expert guide for using n8n-mcp MCP tools effectively. Use when searching for nodes, validating configurations, accessing templates, managing workflows, managing credentials, auditing instance security, or using any n8n-mcp tool. Provides … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-mcp-tools-expert) |
| `n8n-agents` | adjacent | Design n8n AI agents the right way. Use when building or editing any @n8n/n8n-nodes-langchain.* AI node — an AI Agent, LLM chain, Text Classifier, or Information Extractor — and whenever the user mentions AI agents, LLM with tools, tool … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-agents) |
| `n8n-workflow-patterns` | adjacent | Proven workflow architectural patterns from real n8n workflows. Use when building new workflows, designing workflow structure, choosing workflow patterns, planning workflow architecture, or asking about webhook processing, HTTP API … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-workflow-patterns) |
| `n8n-self-hosting` | adjacent | Deploy a production self-hosted n8n end-to-end to a fresh Linux VM over SSH, using Docker Compose behind a Caddy reverse proxy with automatic HTTPS. Use whenever the user wants to self-host, install, set up, provision, or deploy n8n on … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-self-hosting) |
| `n8n-binary-and-data` | adjacent | Handle files and binary data in n8n correctly. Use when working with files, images, PDFs, attachments, uploads or downloads, base64, vision/multimodal input, or when an AI agent needs a file as tool input or output — and whenever the user … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-binary-and-data) |
| `n8n-code-javascript` | adjacent | Write JavaScript code in n8n Code nodes. Use when writing JavaScript in n8n, using $input/$json/$node syntax, making HTTP requests with this.helpers / the $helpers global, working with dates using DateTime, troubleshooting Code node … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-code-javascript) |
| `n8n-code-python` | adjacent | Write Python code in n8n Code nodes. Use when writing Python in n8n, using _input/_json/_node syntax, working with standard library, or need to understand Python limitations in n8n Code nodes. Use this skill when the user specifically … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-code-python) |
| `n8n-code-tool` | adjacent | Write JavaScript or Python for the n8n Custom Code Tool (@n8n/n8n-nodes-langchain.toolCode) — the AI-agent-callable tool, NOT the workflow Code node. Use when building a Code Tool attached to an AI Agent, writing code that an LLM will … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-code-tool) |
| `n8n-error-handling` | adjacent | Wire n8n error handling so failures are loud, structured, and recoverable. Use when building any webhook/API workflow, a scheduled or unattended workflow, or any path where a silent failure would drop user-visible work — and whenever the … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-error-handling) |
| `n8n-expression-syntax` | adjacent | Validate n8n expression syntax and fix common errors. Use when writing n8n expressions, using {{}} syntax, accessing $json/$node variables, troubleshooting expression errors, mapping data between nodes, or referencing webhook data in … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-expression-syntax) |
| `n8n-multi-instance` | adjacent | Use when an n8n-mcp account targets more than one n8n instance — i.e. the `n8n_instances` tool is available, the user mentions multiple n8n instances or environments (prod vs staging, several teams or clients), a workflow / datatable / … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-multi-instance) |
| `n8n-node-configuration` | adjacent | Operation-aware node configuration guidance. Use when configuring nodes, understanding property dependencies, determining required fields, choosing between get_node detail levels, or learning common configuration patterns by node type. … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-node-configuration) |
## Source: NVIDIA/skills
- Repository: [https://github.com/NVIDIA/skills](https://github.com/NVIDIA/skills) (commit `153b14b`, retrieved 2026-07-14)
- License: CC-BY-4.0 (skills/docs), Apache-2.0 (code)
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `hsb-app` | core | Discover and run Holoscan Sensor Bridge example applications on a connected devkit. Filters available apps by the user's platform, HSB software version, board type, and sensors. Supports timed execution, failure analysis, code-edit … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/hsb-app) |
| `nemo-mbridge-perf-moe-optimization-workflow` | adjacent | Systematic workflow for MoE training optimization in Megatron Bridge, based on the Megatron-Core MoE paper. Covers the Three Walls framework, parallel folding, recompute strategy, dispatcher choice, and CUDA-graph bring-up. | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/nemo-mbridge-perf-moe-optimization-workflow) |
| `tao-run-platform` | adjacent | TAO Execution SDK for submitting and monitoring GPU training jobs on supported platforms (Brev, SLURM, local Docker, Kubernetes). Use when the user wants to run TAO jobs through the SDK, get job tracking, S3 I/O wrapping, multi-node … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/tao-run-platform) |
| `launch-nemo-rl` | adjacent | Playbook for launching, monitoring, stopping, and debugging NeMo-RL recipes on a Kubernetes cluster via the nrl-k8s CLI. Covers ephemeral vs long-lived RayCluster modes, iterating on runs, and debugging hung or failed training jobs. | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/launch-nemo-rl) |
| `deepstream-dev` | adjacent | NVIDIA DeepStream SDK 9.0 development with Python pyservicemaker API. Use when building video analytics pipelines, GStreamer-based video processing, TensorRT inference integration, object detection/tracking, or Kafka/message broker … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/deepstream-dev) |
| `tilegym-converting-cutile-to-julia` | adjacent | Converts cuTile Python GPU kernels (@ct.kernel) to cuTile.jl Julia equivalents. Handles kernel syntax translation, 0-indexed to 1-indexed conversion, broadcasting differences, memory layout (row-major to column-major), type system mapping, … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/tilegym-converting-cutile-to-julia) |
| `digital-health-clinical-asr-finetune` | adjacent | Stage 4 of the Clinical ASR Flywheel. Use when priority KER is above 0.3 to run stock NeMo SFT on Parakeet TDT v2 and offline cycle N+1 re-eval. NOT for generic word boosting (use /finetune-asr). | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/digital-health-clinical-asr-finetune) |
| `nemo-mbridge-recipe-recommender` | adjacent | Recommend and customize Megatron Bridge recipes for a user's model, GPU count, and training goal. Indexes library recipes (pretrain/SFT/PEFT) and performance recipes. | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/nemo-mbridge-recipe-recommender) |
| `nemo-rl-docs` | adjacent | Documentation conventions for NeMo-RL. Covers docs/index.md updates and docstring format. Do NOT use for: bug fixes, test fixes, dependency bumps, refactoring, CI/CD changes, performance tuning, or any task that does not involve writing or … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/nemo-rl-docs) |
| `nemo-rl-session-memory` | adjacent | Manage durable working-session memory for coding agents. Use when a user asks to preserve or recover agent context across disconnects, VS Code restarts, long-running work, handoffs, or any session where important state should be written … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/nemo-rl-session-memory) |
| `nemotron-retrieval-recipes` | adjacent | Use when planning, debugging, tuning, evaluating, exporting, or deploying public Nemotron `embed`/`rerank` retrieval recipes. | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/nemotron-retrieval-recipes) |
| `rag-blueprint` | adjacent | NVIDIA RAG Blueprint — deploy, configure, troubleshoot, and manage. Handles any RAG action: deploy, install, start, enable, disable, toggle, change, configure, troubleshoot, debug, fix, shutdown, stop, or tear down any RAG feature or … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/rag-blueprint) |
## Source: veniceai/skills
- Repository: [https://github.com/veniceai/skills](https://github.com/veniceai/skills) (commit `de089fa`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `venice-api-overview` | core | High-level map of the Venice.ai API - base URL, authentication modes, endpoint categories, response headers, pricing model, error shape, and versioning. Load this first when starting any Venice integration. | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-api-overview) |
| `venice-api-keys` | adjacent | Manage Venice API keys. Covers GET/POST/PATCH/DELETE /api_keys, GET /api_keys/{id}, GET /api_keys/rate_limits, GET /api_keys/rate_limits/log, the two-step /api_keys/generate_web3_key wallet flow, INFERENCE vs ADMIN key types, and per-key … | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-api-keys) |
| `venice-responses` | adjacent | Use Venice's Alpha POST /responses endpoint - an OpenAI-compatible Responses API with typed output blocks (reasoning, message, function_call, web_search_call). Covers request shape, streaming, differences from /chat/completions, supported … | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-responses) |
| `venice-auth` | adjacent | Authenticate to the Venice API with a Bearer API key or with an x402 / SIWE wallet. Covers header formats, the SIWE message fields, TTL and nonce rules, the venice-x402-client SDK, and how to choose between the two modes. | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-auth) |
| `venice-errors` | adjacent | Handle Venice API errors correctly. Covers the StandardError / DetailedError / ContentViolationError / X402InferencePaymentRequired body shapes, every meaningful status code (400, 401, 402, 403, 415, 422, 429, 500, 503, 504), the 402 … | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-errors) |

156
references/market.md Normal file
View File

@@ -0,0 +1,156 @@
# Market evidence report — cybersecurity-risk-manager
Source: **55 real job ads** (JSearch API, countries: us 55), extracted into the MSSQL evidence store; as of 2026-07-11.
This report contains extracted, aggregated facts only — no ad text is
reproduced (copyright / platform terms).
## Seniority distribution
| Seniority | Ads | Share |
|---|---|---|
| mid | 29 | 53 % |
| senior | 16 | 29 % |
| lead | 8 | 15 % |
| junior | 1 | 2 % |
| n/a | 1 | 2 % |
## Tools — full market ranking
| # | Item | Ads | Share |
|---|---|---|---|
| 1 | Archer | 4 | 7 % |
| 2 | Nessus | 4 | 7 % |
| 3 | AWS | 3 | 5 % |
| 4 | Microsoft Excel | 3 | 5 % |
| 5 | Microsoft Office | 3 | 5 % |
| 6 | ServiceNow | 3 | 5 % |
| 7 | SharePoint | 3 | 5 % |
## Hard skills — full market ranking
| # | Item | Ads | Share |
|---|---|---|---|
| 1 | risk assessment | 24 | 44 % |
| 2 | risk management | 14 | 25 % |
| 3 | cybersecurity risk management | 13 | 24 % |
| 4 | incident response | 9 | 16 % |
| 5 | continuous monitoring | 8 | 15 % |
| 6 | data analysis | 8 | 15 % |
| 7 | policy development | 8 | 15 % |
| 8 | data protection | 6 | 11 % |
| 9 | regulatory compliance | 6 | 11 % |
| 10 | vulnerability management | 6 | 11 % |
| 11 | cybersecurity | 5 | 9 % |
| 12 | compliance monitoring | 4 | 7 % |
| 13 | cybersecurity risk assessment | 4 | 7 % |
| 14 | vulnerability analysis | 4 | 7 % |
| 15 | compliance | 3 | 5 % |
| 16 | disaster recovery planning | 3 | 5 % |
| 17 | firmware reverse engineering | 3 | 5 % |
| 18 | governance | 3 | 5 % |
| 19 | project management | 3 | 5 % |
| 20 | risk analysis | 3 | 5 % |
| 21 | system security plan development | 3 | 5 % |
## Methods — full market ranking
| # | Item | Ads | Share |
|---|---|---|---|
| 1 | risk management framework (RMF) | 11 | 20 % |
| 2 | ISO 27001 | 7 | 13 % |
| 3 | nist framework | 6 | 11 % |
| 4 | NIST CSF | 5 | 9 % |
| 5 | pci dss | 4 | 7 % |
| 6 | fedramp | 3 | 5 % |
| 7 | mitre attack framework | 3 | 5 % |
| 8 | nist 800-53 | 3 | 5 % |
| 9 | nist risk management framework (rmf) | 3 | 5 % |
| 10 | zero trust architecture | 3 | 5 % |
## Responsibilities — full market ranking
| # | Item | Ads | Share |
|---|---|---|---|
| 1 | stakeholder communication | 5 | 9 % |
| 2 | risk assessment | 4 | 7 % |
| 3 | risk mitigation | 4 | 7 % |
| 4 | team leadership | 4 | 7 % |
| 5 | policy implementation | 3 | 5 % |
| 6 | risk identification | 3 | 5 % |
## Regional breakdown
> **Corpus note:** 55 relevant ads in total — below the 100-ad target for a fully reliable ranking. Percentages above should be read as indicative.
### US (us)
55 ads.
**Top hard skills:**
- risk assessment — 44 % (24 ads)
- risk management — 25 % (14 ads)
- cybersecurity risk management — 24 % (13 ads)
- incident response — 16 % (9 ads)
- continuous monitoring — 15 % (8 ads)
- data analysis — 15 % (8 ads)
- policy development — 15 % (8 ads)
- data protection — 11 % (6 ads)
- regulatory compliance — 11 % (6 ads)
- vulnerability management — 11 % (6 ads)
**Top tools:**
- Archer — 7 % (4 ads)
- Nessus — 7 % (4 ads)
- AWS — 5 % (3 ads)
- Microsoft Excel — 5 % (3 ads)
- Microsoft Office — 5 % (3 ads)
- ServiceNow — 5 % (3 ads)
- SharePoint — 5 % (3 ads)
- AWS Security Hub — 4 % (2 ads)
- CSAM — 4 % (2 ads)
- eMASS — 4 % (2 ads)
**Seniority:** mid 53 % · senior 29 % · lead 15 % · junior 2 % · n/a 2 %
### UK (gb)
**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
### EU/DACH (de, at, ch, nl)
**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
## Job title variants in the market
| Title | Ads |
|---|---|
| Cybersecurity Specialist | 6 |
| Cyber Security Product Risk Manager (Space Systems) | 2 |
| Cybersecurity Risk Analyst | 2 |
| Manager, Cyber Risk & Analysis | 2 |
| 1674 - Senior Cybersecurity Specialist | 1 |
| Advanced Cybersecurity 3rd Party Risk Management | 1 |
| Analyst II, Cybersecurity- Information Risk Management | 1 |
| Cyber Data Protection Manager | 1 |
| Cyber Governance and Risk Management, Cyber Tool Assessor - Principal Associate | 1 |
| Cyber Governance and Risk Management, Cyber Tool Assessor - Principal Associate | McLean, VA, USA | 1 |
| Cyber Risk Management Lead: Strategy | 1 |
| Cyber Security Manager (Remote) | 1 |
| Cyber Security Product RISK Manager | 1 |
| Cyber Security Specialist | 1 |
| Cybersecurity Application RIsk Manager | 1 |
| Cybersecurity Manager of Compliance | 1 |
| Cybersecurity Risk Management Analyst | 1 |
| Cybersecurity Risk Management Director | 1 |
| Cybersecurity Risk Manager | 1 |
| Cybersecurity Specialist - Mid/Senior - SBG REMOTE | 1 |
| Cybersecurity Specialist 1 | 1 |
| Cybersecurity Strategy & Compliance Advisor-Public Trust Clearance required | 1 |
| Director, Security Risk Management | 1 |
| Director, Technology & Cyber Risk Metrics | 1 |
| Enterprise Cybersecurity and IT Risk Management Operations Lead | 1 |
Methodology: entities extracted per ad ({hard_skills, tools, methods, responsibilities, seniority}), normalized, counted as DISTINCT ads per entity; report threshold ≥ 3 ads. Headline sections in skills.md/tools.md use the stricter ≥ 20 % threshold.

30
references/profile.md Normal file
View File

@@ -0,0 +1,30 @@
# Occupation profile — cybersecurity risk manager
- **ESCO URI:** http://data.europa.eu/esco/occupation/7754d570-9519-48c2-b1c9-8e165f8bca0f
- **ESCO code:** 2529.8
- **ISCO-08 group:** 2529 — Database and network professionals not elsewhere classified
- **O*NET-SOC:** 13-1199.04 — Business Continuity Planners (match: closeMatch)
## Description (ESCO)
Cybersecurity risk managers identify, analyse, assess, estimate and mitigate cybersecurity-related risks of ICT infrastructures such as systems or services. They manage these aspects by planning risk analysis, applying, reporting, assessing, communicating, and treating them. They establish a risk management strategy for the organisation and ensure that risks remain at an acceptable level for the organisation by selecting mitigation actions and controls.
## Definition
nan
## Alternative labels
- cybersecurity specialist
- cybersecurity risk assurance consultant
- information security manager
- cyber risk manager
- cybersecurity risk assessor
- IT security chief
- ICT security chief
- ICT security manager
- ICT technical security expert
- security coordinator
- cybersecurity impact analyst
- IT security manager
- information security risk analyst

99
references/skills.md Normal file
View File

@@ -0,0 +1,99 @@
# Competences — cybersecurity risk manager
Source: ESCO v1.2.1 occupation-skill relations (http://data.europa.eu/esco/occupation/7754d570-9519-48c2-b1c9-8e165f8bca0f).
## Essential
- **advice on security risk management** (skill/competence)
- **assessment of risks and threats** (knowledge)
- **attack vectors** (knowledge)
- **communicate with stakeholders** (skill/competence)
- **cyber attack counter-measures** (knowledge)
- **cyber security** (knowledge)
- **engage with stakeholders** (skill/competence)
- **ensure adherence to organisational ICT standards** (skill/competence)
- **establish an ICT security prevention plan** (skill/competence)
- **establish an Information Security Management System** (skill/competence)
- **ethical hacking principles** (knowledge)
- **ICT network security risks** (knowledge)
- **ICT performance analysis methods** (knowledge)
- **ICT safety** (nan)
- **ICT security standards** (knowledge)
- **implement ICT risk management** (skill/competence)
- **information security strategy** (knowledge)
- **internal risk management policy** (knowledge)
- **manage system security** (skill/competence)
- **risk management** (knowledge)
- **security engineering** (knowledge)
- **security threats** (knowledge)
## Optional
- audit techniques (knowledge)
- cloud monitoring and reporting (knowledge)
- cloud security and compliance (knowledge)
- computer forensics (knowledge)
- decision support systems (knowledge)
- define security policies (skill/competence)
- define technology strategy (skill/competence)
- design for organisational complexity (skill/competence)
- develop information security strategy (skill/competence)
- develop with cloud services (skill/competence)
- domain name service (knowledge)
- execute ICT audits (skill/competence)
- hybrid model (knowledge)
- ICT encryption (knowledge)
- ICT problem management techniques (knowledge)
- ICT process quality models (knowledge)
- ICT project management (knowledge)
- ICT quality policy (knowledge)
- ICT recovery techniques (knowledge)
- ICT security legislation (knowledge)
- ICT system user requirements (knowledge)
- identify ICT security risks (skill/competence)
- implement a firewall (skill/competence)
- implement a virtual private network (skill/competence)
- implement anti-virus software (skill/competence)
- implement cloud security and compliance (skill/competence)
- implement ICT security policies (skill/competence)
- implement spam protection (skill/competence)
- information confidentiality (knowledge)
- internet governance (knowledge)
- Internet of Things (knowledge)
- investment analysis (knowledge)
- lead disaster recovery exercises (skill/competence)
- legal requirements of ICT products (knowledge)
- levels of software testing (knowledge)
- manage disaster recovery plans (skill/competence)
- manage keys for data protection (skill/competence)
- mobile device management (knowledge)
- Open source model (knowledge)
- organisational resilience (knowledge)
- Outsourcing model (knowledge)
- remove computer virus or malware from a computer (skill/competence)
- service-oriented modelling (knowledge)
- solve ICT system problems (skill/competence)
- systems development life-cycle (knowledge)
- tools for ICT test automation (knowledge)
- use an application-specific interface (skill/competence)
- use back-up and recovery tools (skill/competence)
- use ICT ticketing system (skill/competence)
- web application security threats (knowledge)
<!-- market-evidence -->
## Market evidence (job-ad analysis, 55 ads, as of 2026-07-11)
Share of analyzed job ads mentioning the item (threshold ≥ 20 %). Source: JSearch/Adzuna APIs.
### Hard skills
- risk assessment — **44 %**
- risk management — **25 %**
- cybersecurity risk management — **24 %**
### Methods
- risk management framework (RMF) — **20 %**
<!-- market-evidence -->

50
references/tasks.md Normal file
View File

@@ -0,0 +1,50 @@
# Tasks & work activities — cybersecurity risk manager
Source: O*NET 30.3, occupation 13-1199.04 (Business Continuity Planners).
## Task statements
- **[Core]** Write reports to summarize testing activities, including descriptions of goals, planning, scheduling, execution, results, analysis, conclusions, and recommendations.
- **[Core]** Maintain and update organization information technology applications and network systems blueprints.
- **[Core]** Interpret government regulations and applicable codes to ensure compliance.
- **[Core]** Establish, maintain, or test call trees to ensure appropriate communication during disaster.
- **[Core]** Design or implement products and services to mitigate risk or facilitate use of technology-based tools and methods.
- **[Core]** Create business continuity and disaster recovery budgets.
- **[Core]** Create or administer training and awareness presentations or materials.
- **[Core]** Attend professional meetings, read literature, and participate in training or other educational offerings to keep abreast of new developments and technologies related to disaster recovery and business continuity.
- **[Core]** Test documented disaster recovery strategies and plans.
- **[Core]** Review existing disaster recovery, crisis management, or business continuity plans.
- **[Core]** Recommend or implement methods to monitor, evaluate, or enable resolution of safety, operations, or compliance interruptions.
- **[Core]** Prepare reports summarizing operational results, financial performance, or accomplishments of specified objectives, goals, or plans.
- **[Core]** Analyze impact on, and risk to, essential business functions or information systems to identify acceptable recovery time periods and resource requirements.
- **[Core]** Identify opportunities for strategic improvement or mitigation of business interruption and other risks caused by business, regulatory, or industry-specific change initiatives.
- **[Core]** Develop disaster recovery plans for physical locations with critical assets, such as data centers.
- **[Core]** Create scenarios to reestablish operations from various types of business disruptions.
- **[Core]** Conduct or oversee contingency plan integration and operation.
- **[Core]** Develop emergency management plans for recovery decision making and communications, continuity of critical departmental processes, or temporary shut-down of non-critical departments to ensure continuity of operation and governance.
- **[Core]** Analyze corporate intelligence data to identify trends, patterns, or warnings indicating threats to security of people, assets, information, or infrastructure.
- **[Supplemental]** Identify individual or transaction targets to direct intelligence collection.
- **[Supplemental]** Conduct or oversee collection of corporate intelligence to avoid fraud, financial crime, cyber attack, terrorism, and infrastructure failure.
## Detailed work activities
- Advise others on analytical techniques.
- Analyze budgetary or accounting data.
- Analyze business or financial data.
- Apply mathematical models of financial or business conditions.
- Assess risks to business operations.
- Develop business or financial information systems.
- Develop contingency plans to deal with organizational emergencies.
- Develop emergency response plans or procedures.
- Develop training materials.
- Evaluate applicable laws and regulations to determine impact on organizational activities.
- Gather organizational performance information.
- Identify strategic business investment opportunities.
- Investigate legal issues.
- Maintain data in information systems or databases.
- Monitor organizational compliance with regulations.
- Oversee business processes.
- Prepare operational reports.
- Prepare research reports.
- Train personnel in organizational or compliance procedures.
- Update professional knowledge.

44
references/tools.md Normal file
View File

@@ -0,0 +1,44 @@
# Tools & technology — cybersecurity risk manager
Source: O*NET 30.3 'Software Skills' for 13-1199.04.
| Software | Category | Hot technology |
|---|---|---|
| Atlassian JIRA | Content workflow software | yes |
| Teradata Database | Data base management system software | yes |
| Microsoft Access | Data base user interface and query software | yes |
| Microsoft SQL Server | Data base user interface and query software | yes |
| ServiceNow | Data base user interface and query software | yes |
| Structured query language SQL | Data base user interface and query software | yes |
| Adobe Acrobat | Document management software | yes |
| Microsoft SharePoint | Document management software | yes |
| Microsoft Outlook | Electronic mail software | yes |
| Microsoft Office software | Office suite software | yes |
| Microsoft PowerPoint | Presentation software | yes |
| Microsoft Visio | Process mapping and design software | yes |
| Atlassian Confluence | Project management software | yes |
| Microsoft Project | Project management software | yes |
| Oracle Primavera Enterprise Project Portfolio Management | Project management software | yes |
| Microsoft Excel | Spreadsheet software | yes |
| Microsoft Word | Word processing software | yes |
| Enterprise backup systems | Backup or archival software | |
| Actuate BIRT | Business intelligence and data analysis software | |
| Jaspersoft Business Intelligence Suite | Business intelligence and data analysis software | |
| Emergency notification system software | Communications server software | |
| MIR3 Intelligent Notification | Communications server software | |
| SAP Crystal Reports | Data base reporting software | |
| Microsoft SharePoint Server | Document management software | |
| Business continuity software | Enterprise resource planning ERP software | |
| CA Clarity PPM | Enterprise resource planning ERP software | |
| COOP Systems myCOOP | Enterprise resource planning ERP software | |
| EMC RSA Archer Business Continuity Management | Enterprise resource planning ERP software | |
| Oracle JD Edwards EnterpriseOne | Enterprise resource planning ERP software | |
| RecoveryPlanner RPX | Enterprise resource planning ERP software | |
| Strategic BCP ResilienceONE | Enterprise resource planning ERP software | |
| Sungard Assurance | Enterprise resource planning ERP software | |
| Virtual Corporation Sustainable Planner | Enterprise resource planning ERP software | |
| Web browser software | Internet browser software | |
| Local area network LAN software | LAN software | |
| SunGard NotiFind | Network operation system software | |
| Computer operating systems | Operating system software | |
| Mentimeter | Presentation software | |