Files
2026-08-14 17:33:55 +02:00

3.8 KiB

name, description
name description
cybersecurity-risk-manager Occupational skill for the role 'cybersecurity risk manager' (also: cybersecurity specialist, cybersecurity risk assurance consultant, information security manager, cyber risk manager, cybersecurity risk assessor, IT security chief). Use when the user asks for typical cybersecurity risk manager work such as: Write reports to summarize testing activities, including descriptions of goals, planning, scheduling, execution, results, analysis, conclusions, and recommendations.; Maintain and update organization information technology applications and network systems blueprints.; Interpret government regulations and applicable codes to ensure compliance.

Cybersecurity Risk Manager

Cybersecurity risk managers identify, analyse, assess, estimate and mitigate cybersecurity-related risks of ICT infrastructures such as systems or services. They manage these aspects by planning risk analysis, applying, reporting, assessing, communicating, and treating them. They establish a risk management strategy for the organisation and ensure that risks remain at an acceptable level for the organisation by selecting mitigation actions and controls.

Core workflow

  1. Write reports to summarize testing activities, including descriptions of goals, planning, scheduling, execution, results, analysis, conclusions, and recommendations.
  2. Maintain and update organization information technology applications and network systems blueprints.
  3. Interpret government regulations and applicable codes to ensure compliance.
  4. Establish, maintain, or test call trees to ensure appropriate communication during disaster.
  5. Design or implement products and services to mitigate risk or facilitate use of technology-based tools and methods.
  6. Create business continuity and disaster recovery budgets.
  7. Create or administer training and awareness presentations or materials.
  8. Attend professional meetings, read literature, and participate in training or other educational offerings to keep abreast of new developments and technologies related to disaster recovery and business continuity.

How to use this skill

Key competences (essential)

  • advice on security risk management
  • assessment of risks and threats
  • attack vectors
  • communicate with stakeholders
  • cyber attack counter-measures
  • cyber security
  • engage with stakeholders
  • ensure adherence to organisational ICT standards
  • establish an ICT security prevention plan
  • establish an Information Security Management System
  • ethical hacking principles
  • ICT network security risks
  • ICT performance analysis methods
  • ICT safety
  • ICT security standards

Hot technologies

  • Atlassian JIRA
  • Teradata Database
  • Microsoft Access
  • Microsoft SQL Server
  • ServiceNow
  • Structured query language SQL
  • Adobe Acrobat
  • Microsoft SharePoint
  • Microsoft Outlook
  • Microsoft Office software

Hot technologies

Top tools from 55 gated job ads (see references/market.md, as of 2026-07-11):

  • Archer — 7 %
  • Nessus — 7 %
  • AWS — 5 %
  • Microsoft Excel — 5 %
  • Microsoft Office — 5 %
  • ServiceNow — 5 %
  • SharePoint — 5 %

Sources: ESCO v1.2.1 (http://data.europa.eu/esco/occupation/7754d570-9519-48c2-b1c9-8e165f8bca0f), ONET 30.3 (13-1199.04). See manifest.json for licensing/attribution.*