[
	{
		"title": "Chief Information Security Officer (CISO)",
		"alternative_titles": [
			"Cybersecurity Programme Director",
			"Information Security Officer (ISO)",
			"Information Security Manager",
			"Head of Information Security",
			"IT/ICT Security Officer"
		],
		"summary_statement": "Manages an organisation’s cybersecurity strategy and its implementation to ensure that digital systems, services and assets are adequately secure and protected.",
		"mission": "Defines, maintains and communicates the cybersecurity vision, strategy, policies and procedures. Manages the implementation of the cybersecurity policy across the organisation. Assures information exchange with external authorities and professional bodies.",
		"deliverables": [
			"Cybersecurity Strategy",
			"Cybersecurity Policy"
		],
		"main_tasks": [
			"Define, implement, communicate and maintain cybersecurity goals, requirements, strategies, policies, aligned with the business strategy to support the organisational objectives",
			"Prepare and present cybersecurity vision, strategies and policies for approval by the senior management of the organisation and ensure their execution",
			"Supervise the application and improvement of the Information Security Management System (ISMS)",
			"Educate senior management about cybersecurity risks, threats and their impact to the organisation",
			"Ensure the senior management approves the cybersecurity risks of the organisation",
			"Develop cybersecurity plans",
			"Develop relationships with cybersecurity-related authorities and communities",
			"Report cybersecurity incidents, risks, findings to the senior management",
			"Monitor advancement in cybersecurity",
			"Secure resources to implement the cybersecurity strategy",
			"Negotiate the cybersecurity budget with the senior management",
			"Ensure the organisation’s resiliency to cyber incidents",
			"Manage continuous capacity building within the organisation",
			"Review, plan and allocate appropriate cybersecurity resources"
		],
		"key_skills": [
			"Assess and enhance an organisation’s cybersecurity posture",
			"Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks",
			"Analyse and comply with cybersecurity-related laws, regulations and legislations",
			"Implement cybersecurity recommendations and best practices",
			"Manage cybersecurity resources",
			"Develop, champion and lead the execution of a cybersecurity strategy",
			"Influence an organisation’s cybersecurity culture",
			"Design, apply, monitor and review Information Security Management System (ISMS) either directly or by leading its outsourcing",
			"Review and enhance security documents, reports, SLAs and ensure the security objectives",
			"Identify and solve cybersecurity-related issues",
			"Establish a cybersecurity plan",
			"Communicate, coordinate and cooperate with internal and external stakeholders",
			"Anticipate required changes to the organisation’s information security strategy and formulate new plans",
			"Define and apply maturity models for cybersecurity management",
			"Anticipate cybersecurity threats, needs and upcoming challenges",
			"Motivate and encourage people"
		],
		"key_knowledge": [
			"Cybersecurity policies",
			"Cybersecurity standards, methodologies and frameworks",
			"Cybersecurity recommendations and best practices",
			"Cybersecurity related laws, regulations and legislations",
			"Cybersecurity-related certifications",
			"Ethical cybersecurity organisation requirements",
			"Cybersecurity maturity models",
			"Cybersecurity procedures",
			"Resource management",
			"Management practices",
			"Risk management standards, methodologies and frameworks"
		],
		"ecompetences": [
			[
				"A.7.",
				"Technology Trend Monitoring",
				4
			],
			[
				"D.1.",
				"Information Security Strategy Development",
				5
			],
			[
				"E.3.",
				"Risk Management",
				4
			],
			[
				"E.8.",
				"Information Security Management",
				4
			],
			[
				"E.9.",
				"IS-Governance",
				5
			]
		]
	},
	{
		"title": "Cyber Incident Responder",
		"alternative_titles": [
			"Cyber Incident Handler",
			"Cyber Crisis Expert",
			"Incident Response Engineer",
			"Security Operations Center (SOC) Analyst",
			"Cyber Fighter /Defender",
			"Security Operation Analyst (SOC Analyst)",
			"Cybersecurity SIEM Manager"
		],
		"summary_statement": "Monitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.",
		"mission": "Monitors and assesses systems’ cybersecurity state. Analyses, evaluates and mitigates the impact of cybersecurity incidents. Identifies cyber incidents root causes and malicious actors. According to the organisation’s Incident Response Plan, restores systems’ and processes’ functionalities to an operational state, collecting evidences and documenting actions taken.",
		"deliverables": [
			"Incident Response Plan",
			"Cyber Incident Report"
		],
		"main_tasks": [
			"Contribute to the development, maintenance and assessment of the Incident Response Plan",
			"Develop, implement and assess procedures related to incident handling",
			"Identify, analyse, mitigate and communicate cybersecurity incidents",
			"Assess and manage technical vulnerabilities",
			"Measure cybersecurity incidents detection and response effectiveness",
			"Evaluate the resilience of the cybersecurity controls and mitigation actions taken after a cybersecurity or data breach incident",
			"Adopt and develop incident handling testing techniques",
			"Establish procedures for incident results analysis and incident handling reporting",
			"Document incident results analysis and incident handling actions",
			"Cooperate with Secure Operation Centres (SOCs) and Computer Security Incident Response Teams (CSIRTs)",
			"Cooperate with key personnel for reporting of security incidents according to applicable legal framework"
		],
		"key_skills": [
			"Practice all technical, functional and operational aspects of cybersecurity incident handling and response",
			"Collect, analyse and correlate cyber threat information originating from multiple sources",
			"Work on operating systems, servers, clouds and relevant infrastructures",
			"Work under pressure",
			"Communicate, present and report to relevant stakeholders",
			"Manage and analyse log files"
		],
		"key_knowledge": [
			"Incident handling standards, methodologies and frameworks",
			"Incident handling recommendations and best practices",
			"Incident handling tools",
			"Incident handling communication procedures",
			"Operating systems security",
			"Computer networks security",
			"Cyber threats",
			"Cybersecurity attack procedures",
			"Computer systems vulnerabilities",
			"Cybersecurity-related certifications",
			"Cybersecurity related laws, regulations and legislations",
			"Secure Operation Centres (SOCs) operation",
			"Computer Security Incident Response Teams (CSIRTs) operation"
		],
		"ecompetences": [
			[
				"A.7.",
				"Technology Trend Monitoring",
				3
			],
			[
				"B.2.",
				"Component Integration",
				2
			],
			[
				"B.3.",
				"Testing",
				3
			],
			[
				"B.5.",
				"Documentation Production",
				3
			],
			[
				"C.4.",
				"Problem Management",
				4
			]
		]
	},
	{
		"title": "Cyber Legal, Policy & Compliance Officer",
		"alternative_titles": [
			"Data Protection Officer (DPO)",
			"Privacy Protection Officer",
			"Cyber Law Consultant",
			"Cyber Legal Advisor",
			"Information Governance Officer",
			"Data Compliance Officer",
			"Cybersecurity Legal Officer",
			"IT/ICT Compliance Manager",
			"Governance Risk Compliance (GRC) Consultant"
		],
		"summary_statement": "Manages compliance with cybersecurity-related standards, legal and regulatory frameworks based on the organisation’s strategy and legal requirements.",
		"mission": "Oversees and assures compliance with cybersecurity- and data-related legal, regulatory frameworks and policies in line with the organisation’s strategy and legal requirements. Contributes to the organisation’s data protection related actions. Provides legal advice in the development of the organisation’s cybersecurity governance processes and recommended remediation strategies/solutions to ensure compliance.",
		"deliverables": [
			"Compliance Manual",
			"Compliance Report"
		],
		"main_tasks": [
			"Ensure compliance with and provide legal advice and guidance on data privacy and data protection standards, laws and regulations",
			"Identify and document compliance gaps",
			"Conduct privacy impact assessments and develop, maintain, communicate and train upon the privacy policies, procedures",
			"Enforce and advocate organisation’s data privacy and protection program",
			"Ensure that data owners, holders, controllers, processors, subjects, internal or external partners and entities are informed about their data protection rights, obligations and responsibilities",
			"Act as a key contact point to handle queries and complaints regarding data processing",
			"Assist in designing, implementing, auditing and compliance testing activities in order to ensure cybersecurity and privacy compliance",
			"Monitor audits and data protection related training activities",
			"Cooperate and share information with authorities and professional groups",
			"Contribute to the development of the organisation’s cybersecurity strategy, policy and procedures",
			"Develop and propose staff awareness training to achieve compliance and foster a culture of data protection within the organization",
			"Manage legal aspects of information security responsibilities and third-party relations"
		],
		"key_skills": [
			"Comprehensive understanding of the business strategy, models and products and ability to factor into legal, regulatory and standards’ requirements",
			"Carry out working-life practices of the data protection and privacy issues involved in the implementation of the organisational processes, finance and business strategy",
			"Lead the development of appropriate cybersecurity and privacy policies and procedures that complement the business needs and legal requirements; further ensure its acceptance, comprehension and implementation and communicate it between the involved parties",
			"Conduct, monitor and review privacy impact assessments using standards, frameworks, acknowledged methodologies and tools",
			"Explain and communicate data protection and privacy topics to stakeholders and users",
			"Understand, practice and adhere to ethical requirements and standards",
			"Understand legal framework modifications implications to the organisation’s cybersecurity and data protection strategy and policies",
			"Collaborate with other team members and colleagues"
		],
		"key_knowledge": [
			"Cybersecurity related laws, regulations and legislations",
			"Cybersecurity standards, methodologies and frameworks",
			"Cybersecurity policies",
			"Legal, regulatory and legislative compliance requirements, recommendations and best practices",
			"Privacy impact assessment standards, methodologies and frameworks"
		],
		"ecompetences": [
			[
				"A.1.",
				"Information Systems and Business Strategy Alignment",
				4
			],
			[
				"D.1.",
				"Information Security Strategy Development",
				4
			],
			[
				"E.8.",
				"Information Security Management",
				3
			],
			[
				"E.9.",
				"IS-Governance",
				4
			]
		]
	},
	{
		"title": "Cyber Threat Intelligence Specialist",
		"alternative_titles": [
			"Cyber Intelligence Analyst",
			"Cyber Threat Modeller"
		],
		"summary_statement": "Collect, process, analyse data and information to produce actionable intelligence reports and disseminate them to target stakeholders.",
		"mission": "Manages cyber threat intelligence life cycle including cyber threat information collection, analysis and production of actionable intelligence and dissemination to security stakeholders and the CTI community, at a tactical, operational and strategic level. Identifies and monitors the Tactics, Techniques and Procedures (TTPs) used by cyber threat actors and their trends, track threat actors’ activities and observe how non-cyber events can influence cyber-related actions.",
		"deliverables": [
			"Cyber Threat Intelligence Manual",
			"Cyber Threat Report"
		],
		"main_tasks": [
			"Develop, implement and manage the organisation's cyber threat intelligence strategy",
			"Develop plans and procedures to manage threat intelligence",
			"Translate business requirements into Intelligence Requirements",
			"Implement threat intelligence collection, analysis and production of actionable intelligence and dissemination to security stakeholders",
			"Identify and assess cyber threat actors targeting the organisation",
			"Identify, monitor and assess the Tactics, Techniques and Procedures (TTPs) used by cyber threat actors by analysing open-source and proprietary data, information and intelligence",
			"Produce actionable reports based on threat intelligence data",
			"Elaborate and advise on mitigation plans at the tactical, operational and strategic level",
			"Coordinate with stakeholders to share and consume intelligence on relevant cyber threats",
			"Leverage intelligence data to support and assist with threat modelling, recommendations for Risk Mitigation and cyber threat hunting",
			"Articulate and communicate intelligence openly and publicly at all levels",
			"Convey the proper security severity by explaining the risk exposure and its consequences to non-technical stakeholders"
		],
		"key_skills": [
			"Collaborate with other team members and colleagues",
			"Collect, analyse and correlate cyber threat information originating from multiple sources",
			"Identify threat actors TTPs and campaigns",
			"Automate threat intelligence management procedures",
			"Conduct technical analysis and reporting",
			"Identify non-cyber events with implications on cyber-related activities",
			"Model threats, actors and TTPs",
			"Communicate, coordinate and cooperate with internal and external stakeholders",
			"Communicate, present and report to relevant stakeholders",
			"Use and apply CTI platforms and tools"
		],
		"key_knowledge": [
			"Operating systems security",
			"Computer networks security",
			"Cybersecurity controls and solutions",
			"Computer programming",
			"Cyber Threat Intelligence (CTI) sharing standards, methodologies and frameworks",
			"Responsible information disclosure procedures",
			"Cross-domain and border-domain knowledge related to cybersecurity",
			"Cyber threats",
			"Cyber threat actors",
			"Cybersecurity attack procedures",
			"Advanced and persistent cyber threats (APT)",
			"Threat actors Tactics, Techniques and Procedures (TTPs)",
			"Cybersecurity-related certifications"
		],
		"ecompetences": [
			[
				"B.5.",
				"Documentation Production",
				3
			],
			[
				"D.7.",
				"Data Science and Analytics",
				4
			],
			[
				"D.10.",
				"Information and Knowledge Management",
				4
			],
			[
				"E.4.",
				"Relationship Management",
				3
			],
			[
				"E.8.",
				"Information Security Management",
				4
			]
		]
	},
	{
		"title": "Cybersecurity Architect",
		"alternative_titles": [
			"Cybersecurity Solutions Architect",
			"Cybersecurity Designer",
			"Data Security Architect"
		],
		"summary_statement": "Plans and designs security-by-design solutions (infrastructures, systems, assets, software, hardware and services) and cybersecurity controls.",
		"mission": "Designs solutions based on security-by-design and privacy-by-design principles. Creates and continuously improves architectural models and develops appropriate architectural documentation and specifications. Coordinate secure development, integration and maintenance of cybersecurity components in line with standards and other related requirements.",
		"deliverables": [
			"Cybersecurity Architecture Diagram",
			"Cybersecurity Requirements Report"
		],
		"main_tasks": [
			"Design and propose a secure architecture to implement the organisation’s strategy",
			"Develop organisation’s cybersecurity architecture to address security and privacy requirements",
			"Produce architectural documentation and specifications",
			"Present high-level security architecture design to stakeholders",
			"Establish a secure environment during the development lifecycle of systems, services and products",
			"Coordinate the development, integration and maintenance of cybersecurity components ensuring the cybersecurity specifications",
			"Analyse and evaluate the cybersecurity of the organisation’s architecture",
			"Assure the security of the solution architectures through security reviews and certification",
			"Collaborate with other teams and colleagues",
			"Evaluate the impact of cybersecurity solutions on the design and performance of the organisation’s architecture",
			"Adapt the organisation’s architecture to emerging threats",
			"Assess the implemented architecture to maintain an appropriate level of security"
		],
		"key_skills": [
			"Conduct user and business security requirements analysis",
			"Draw cybersecurity architectural and functional specifications",
			"Decompose and analyse systems to develop security and privacy requirements and identify effective solutions",
			"Design systems and architectures based on security and privacy by design and by defaults cybersecurity principles",
			"Guide and communicate with implementers and IT/OT personnel",
			"Communicate, present and report to relevant stakeholders",
			"Propose cybersecurity architectures based on stakeholder’s needs and budget",
			"Select appropriate specifications, procedures and controls",
			"Build resilience against points of failure across the architecture",
			"Coordinate the integration of security solutions"
		],
		"key_knowledge": [
			"Cybersecurity-related certifications",
			"Cybersecurity recommendations and best practices",
			"Cybersecurity standards, methodologies and frameworks",
			"Cybersecurity-related requirements analysis",
			"Secure development lifecycle",
			"Security architecture reference models",
			"Cybersecurity-related technologies",
			"Cybersecurity controls and solutions",
			"Cybersecurity risks",
			"Cyber threats",
			"Cybersecurity trends",
			"Legal, regulatory and legislative compliance requirements, recommendations and best practices",
			"Legacy cybersecurity procedures",
			"Privacy-Enhancing Technologies (PET)",
			"Privacy-by-design standards, methodologies and frameworks"
		],
		"ecompetences": [
			[
				"A.5.",
				"Architecture Design",
				5
			],
			[
				"A.6.",
				"Application Design",
				3
			],
			[
				"B.1.",
				"Application Development",
				3
			],
			[
				"B.3.",
				"Testing",
				3
			],
			[
				"B.6.",
				"ICT Systems Engineering",
				4
			]
		]
	},
	{
		"title": "Cybersecurity Auditor",
		"alternative_titles": [
			"Information Security Auditor (IT or Legal Auditor)",
			"Governance Risk Compliance (GRC) Auditor",
			"Cybersecurity Audit Manager",
			"Cybersecurity Procedures and Processes Auditor",
			"Information Security Risk and Compliance Auditor",
			"Data Protection Assessment Analyst"
		],
		"summary_statement": "Perform cybersecurity audits on the organisation’s ecosystem. Ensuring compliance with statutory, regulatory, policy information, security requirements, industry standards and best practices.",
		"mission": "Conducts independent reviews to assess the effectiveness of processes and controls and the overall compliance with the organisation's legal and regulatory frameworks policies. Evaluates, tests and verifies cybersecurity-related products (systems, hardware, software and services), functions and policies ensuring, compliance with guidelines, standards and regulations.",
		"deliverables": [
			"Cybersecurity Audit Plan",
			"Cybersecurity Audit Report"
		],
		"main_tasks": [
			"Develop the organisation's auditing policy, procedures, standards and guidelines",
			"Establish the methodologies and practices used for systems auditing",
			"Establish the target environment and manage auditing activities",
			"Define audit scope, objectives and criteria to audit against",
			"Develop an audit plan describing the frameworks, standards, methodology, procedures and auditing tests",
			"Review target of evaluation, security objectives and requirements based on the risk profile",
			"Audit compliance with cybersecurity-related applicable laws and regulations",
			"Audit conformity with cybersecurity-related applicable standards",
			"Execute the audit plan and collect evidence and measurements",
			"Maintain and protect the integrity of audit records",
			"Develop and communicate conformity assessment, assurance, audit, certification and maintenance reports",
			"Monitor risk remediation activities"
		],
		"key_skills": [
			"Organise and work in a systematic and deterministic way based on evidence",
			"Follow and practice auditing frameworks, standards and methodologies",
			"Apply auditing tools and techniques",
			"Analyse business processes, assess and review software or hardware security, as well as technical and organisational controls",
			"Decompose and analyse systems to identify weaknesses and ineffective controls",
			"Communicate, explain and adapt legal and regulatory requirements and business needs",
			"Collect, evaluate, maintain and protect auditing information",
			"Audit with integrity, being impartial and independent"
		],
		"key_knowledge": [
			"Cybersecurity controls and solutions",
			"Legal, regulatory and legislative compliance requirements, recommendations and best practices",
			"Monitoring, testing and evaluating cybersecurity controls' effectiveness",
			"Conformity assessment standards, methodologies and frameworks",
			"Auditing standards, methodologies and frameworks",
			"Cybersecurity standards, methodologies and frameworks",
			"Auditing-related certification",
			"Cybersecurity-related certifications"
		],
		"ecompetences": [
			[
				"B.3.",
				"Testing",
				4
			],
			[
				"B.5.",
				"Documentation Production",
				3
			],
			[
				"E.3.",
				"Risk Management",
				4
			],
			[
				"E.6.",
				"ICT Quality Management",
				4
			],
			[
				"E.8.",
				"Information Security Management",
				4
			]
		]
	},
	{
		"title": "Cybersecurity Educator",
		"alternative_titles": [
			"Cybersecurity Awareness Specialist",
			"Cybersecurity Trainer",
			"Faculty in Cybersecurity (Professor, Lecturer)"
		],
		"summary_statement": "Improves cybersecurity knowledge, skills and competencies of humans.",
		"mission": "Designs, develops and conducts awareness, training and educational programmes in cybersecurity and data protection-related topics. Uses appropriate teaching and training methods, techniques and instruments to communicate and enhance the cybersecurity culture, capabilities, knowledge and skills of human resources. Promotes the importance of cybersecurity and consolidates it into the organisation.",
		"deliverables": [
			"Cybersecurity Awareness Program",
			"Cybersecurity Training Material"
		],
		"main_tasks": [
			"Develop, update and deliver cybersecurity and data protection curricula and educational material for training and awareness based on content, method, tools, trainees need",
			"Organise, design and deliver cybersecurity and data protection awareness-raising activities, seminars, courses, practical training",
			"Monitor, evaluate and report training effectiveness",
			"Evaluate and report trainee’s performance",
			"Finding new approaches for education, training and awareness-raising",
			"Design, develop and deliver cybersecurity simulations, virtual labs or cyber range environments",
			"Provide guidance on cybersecurity certification programs for individuals",
			"Continuously maintain and enhance expertise; encourage and empower continuous enhancement of cybersecurity capacities and capabilities building"
		],
		"key_skills": [
			"Identify needs in cybersecurity awareness, training and education",
			"Design, develop and deliver learning programmes to cover cybersecurity needs",
			"Develop cybersecurity exercises including simulations using cyber range environments",
			"Provide training towards cybersecurity and data protection professional certifications",
			"Utilise existing cybersecurity-related training resources",
			"Develop evaluation programs for the awareness, training and education activities",
			"Communicate, present and report to relevant stakeholders",
			"Identify and select appropriate pedagogical approaches for the intended audience",
			"Motivate and encourage people"
		],
		"key_knowledge": [
			"Pedagogical standards, methodologies and frameworks",
			"Cybersecurity awareness, education and training programme development",
			"Cybersecurity-related certifications",
			"Cybersecurity education and training standards, methodologies and frameworks",
			"Cybersecurity related laws, regulations and legislations",
			"Cybersecurity recommendations and best practices",
			"Cybersecurity standards, methodologies and frameworks",
			"Cybersecurity controls and solutions"
		],
		"ecompetences": [
			[
				"D.3.",
				"Education and Training Provision",
				3
			],
			[
				"D.9.",
				"Personnel Development",
				3
			],
			[
				"E.8.",
				"Information Security Management",
				3
			]
		]
	},
	{
		"title": "Cybersecurity Implementer",
		"alternative_titles": [
			"Information Security Implementer",
			"Cybersecurity Solutions Expert",
			"Cybersecurity Developer",
			"Cybersecurity Engineer",
			"Development, Security & Operations (DevSecOps) Engineer"
		],
		"summary_statement": "Develop, deploy and operate cybersecurity solutions (systems, assets, software, controls and services) on infrastructures and products.",
		"mission": "Provides cybersecurity-related technical development, integration, testing, implementation, operation, maintenance, monitoring and support of cybersecurity solutions. Ensures adherence to specifications and conformance requirements, assures sound performance and resolves technical issues required in the organisation’s cybersecurity-related solutions (systems, assets, software, controls and services), infrastructures and products.",
		"deliverables": [
			"Cybersecurity Solutions"
		],
		"main_tasks": [
			"Develop, implement, maintain, upgrade, test cybersecurity products",
			"Provide cybersecurity-related support to users and customers",
			"Integrate cybersecurity solutions and ensure their sound operation",
			"Securely configure systems, services and products",
			"Maintain and upgrade the security of systems, services and products",
			"Implement cybersecurity procedures and controls",
			"Monitor and assure the performance of the implemented cybersecurity controls",
			"Document and report on the security of systems, services and products",
			"Work close with the IT/OT personnel on cybersecurity-related actions",
			"Implement, apply and manage patches to products to address technical vulnerabilities"
		],
		"key_skills": [
			"Communicate, present and report to relevant stakeholders",
			"Integrate cybersecurity solutions to the organisation’s infrastructure",
			"Configure solutions according to the organisation’s security policy",
			"Assess the security and performance of solutions",
			"Develop code, scripts and programmes",
			"Identify and solve cybersecurity-related issues",
			"Collaborate with other team members and colleagues"
		],
		"key_knowledge": [
			"Secure development lifecycle",
			"Computer programming",
			"Operating systems security",
			"Computer networks security",
			"Cybersecurity controls and solutions",
			"Offensive and defensive security practices",
			"Secure coding recommendations and best practices",
			"Cybersecurity recommendations and best practices",
			"Testing standards, methodologies and frameworks",
			"Testing procedures",
			"Cybersecurity-related technologies"
		],
		"ecompetences": [
			[
				"A.5.",
				"Architecture Design",
				3
			],
			[
				"A.6.",
				"Application Design",
				3
			],
			[
				"B.1.",
				"Application Development",
				3
			],
			[
				"B.3.",
				"Testing",
				3
			],
			[
				"B.6.",
				"ICT Systems Engineering",
				4
			]
		]
	},
	{
		"title": "Cybersecurity Researcher",
		"alternative_titles": [
			"Cybersecurity Research Engineer",
			"Chief Research Officer (CRO) in cybersecurity",
			"Senior Research Officer in cybersecurity",
			"Research and Development (R&D) Officer in cybersecurity",
			"Scientific Staff in cybersecurity",
			"Research and Innovation Officer/Expert in cybersecurity",
			"Research Fellow in cybersecurity"
		],
		"summary_statement": "Research the cybersecurity domain and incorporate results in cybersecurity solutions.",
		"mission": "Conducts fundamental/basic and applied research and facilitates innovation in the cybersecurity domain through cooperation with other stakeholders. Analyses trends and scientific findings in cybersecurity.",
		"deliverables": [
			"Publication in Cybersecurity"
		],
		"main_tasks": [
			"Analyse and assess cybersecurity technologies, solutions, developments and processes",
			"Conduct research, innovation and development work in cybersecurity-related topics",
			"Manifest and generate research and innovation ideas",
			"Advance the current state-of-the-art in cybersecurity-related topics",
			"Assist in the development of innovative cybersecurity-related solutions",
			"Conduct experiments and develop a proof of concept, pilots and prototypes for cybersecurity solutions",
			"Select and apply frameworks, methods, standards, tools and protocols including a building and testing a proof of concept to support projects",
			"Contributes towards cutting-edge cybersecurity business ideas, services and solutions",
			"Assist in cybersecurity-related capacity building including awareness, theoretical training, practical training, testing, mentoring, supervising and sharing",
			"Identify cross-sectoral cybersecurity achievements and apply them in a different context or propose innovative approaches and solutions",
			"Lead or participate in the innovation processes and projects including project management and budgeting",
			"Publish and present scientific works and research and development results"
		],
		"key_skills": [
			"Generate new ideas and transfer theory into practice",
			"Decompose and analyse systems to identify weaknesses and ineffective controls",
			"Decompose and analyse systems to develop security and privacy requirements and identify effective solutions",
			"Monitor new advancements in cybersecurity-related technologies",
			"Communicate, present and report to relevant stakeholders",
			"Identify and solve cybersecurity-related issues",
			"Collaborate with other team members and colleagues"
		],
		"key_knowledge": [
			"Cybersecurity-related research, development and innovation (RDI)",
			"Cybersecurity standards, methodologies and frameworks",
			"Legal, regulatory and legislative requirements on releasing or using cybersecurity related technologies",
			"Multidiscipline aspect of cybersecurity",
			"Responsible information disclosure procedures"
		],
		"ecompetences": [
			[
				"A.7.",
				"Technology Trend Monitoring",
				5
			],
			[
				"A.9.",
				"Innovating",
				5
			],
			[
				"D.7.",
				"Data Science and Analytics",
				4
			],
			[
				"C.4.",
				"Problem Management",
				3
			],
			[
				"D.10.",
				"Information and Knowledge Management",
				3
			]
		]
	},
	{
		"title": "Cybersecurity Risk Manager",
		"alternative_titles": [
			"Information Security Risk Analyst",
			"Cybersecurity Risk Assurance Consultant",
			"Cybersecurity Risk Assessor",
			"Cybersecurity Impact Analyst",
			"Cyber Risk Manager"
		],
		"summary_statement": "Manage the organisation's cybersecurity-related risks aligned to the organisation’s strategy. Develop, maintain and communicate the risk management processes and reports.",
		"mission": "Continuously manages (identifies, analyses, assesses, estimates, mitigates) the cybersecurity-related risks of ICT infrastructures, systems and services by planning, applying, reporting and communicating risk analysis, assessment and treatment. Establishes a risk management strategy for the organisation and ensures that risks remain at an acceptable level for the organisation by selecting mitigation actions and controls.",
		"deliverables": [
			"Cybersecurity Risk Assessment Report",
			"Cybersecurity Risk Remediation Action Plan"
		],
		"main_tasks": [
			"Develop an organisation’s cybersecurity risk management strategy",
			"Manage an inventory of organisation’s assets",
			"Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems",
			"Identification of threat landscape including attackers’ profiles and estimation of attacks’ potential",
			"Assess cybersecurity risks and propose most appropriate risk treatment options, including security controls and risk mitigation and avoidance that best address the organisation’s strategy",
			"Monitor effectiveness of cybersecurity controls and risk levels",
			"Ensure that all cybersecurity risks remain at an acceptable level for the organisation’s assets",
			"Develop, maintain, report and communicate complete risk management cycle"
		],
		"key_skills": [
			"Implement cybersecurity risk management frameworks, methodologies and guidelines and ensure compliance with regulations and standards",
			"Analyse and consolidate organisation’s quality and risk management practices",
			"Enable business assets owners, executives and other stakeholders to make risk-informed decisions to manage and mitigate risks",
			"Build a cybersecurity risk-aware environment",
			"Communicate, present and report to relevant stakeholders",
			"Propose and manage risk-sharing options"
		],
		"key_knowledge": [
			"Risk management standards, methodologies and frameworks",
			"Risk management tools",
			"Risk management recommendations and best practices",
			"Cyber threats",
			"Computer systems vulnerabilities",
			"Cybersecurity controls and solutions",
			"Cybersecurity risks",
			"Monitoring, testing and evaluating cybersecurity controls' effectiveness",
			"Cybersecurity-related certifications",
			"Cybersecurity-related technologies"
		],
		"ecompetences": [
			[
				"E.3.",
				"Risk Management",
				4
			],
			[
				"E.5.",
				"Process Improvement",
				3
			],
			[
				"E.7.",
				"Business Change Management",
				4
			],
			[
				"E.9.",
				"IS-Governance",
				4
			]
		]
	},
	{
		"title": "Digital Forensics Investigator",
		"alternative_titles": [
			"Digital Forensics Analyst",
			"Cybersecurity & Forensic Specialist",
			"Computer Forensics Consultant"
		],
		"summary_statement": "Ensure the cybercriminal investigation reveals all digital evidence to prove the malicious activity.",
		"mission": "Connects artefacts to natural persons, captures, recovers, identifies and preserves data, including manifestations, inputs, outputs and processes of digital systems under investigation. Provides analysis, reconstruction and interpretation of the digital evidence based on a qualitative opinion. Presents an unbiased qualitative view without interpreting the resultant findings.",
		"deliverables": [
			"Digital Forensics Analysis Results",
			"Electronic Evidence"
		],
		"main_tasks": [
			"Develop digital forensics investigation policy, plans and procedures",
			"Identify, recover, extract, document and analyse digital evidence",
			"Preserve and protect digital evidence and make it available to authorised stakeholders",
			"Inspect environments for evidence of unauthorised and unlawful actions",
			"Systematically and deterministic document, report and present digital forensic analysis findings and results",
			"Select and customise forensics testing, analysing and reporting techniques"
		],
		"key_skills": [
			"Work ethically and independently; not influenced and biased by internal or external actors",
			"Collect information while preserving its integrity",
			"Identify, analyse and correlate cybersecurity events",
			"Explain and present digital evidence in a simple, straightforward and easy to understand way",
			"Develop and communicate, detailed and reasoned investigation reports"
		],
		"key_knowledge": [
			"Digital forensics recommendations and best practices",
			"Digital forensics standards, methodologies and frameworks",
			"Digital forensics analysis procedures",
			"Testing procedures",
			"Criminal investigation procedures, standards, methodologies and frameworks",
			"Cybersecurity related laws, regulations and legislations",
			"Malware analysis tools",
			"Cyber threats",
			"Computer systems vulnerabilities",
			"Cybersecurity attack procedures",
			"Operating systems security",
			"Computer networks security",
			"Cybersecurity-related certifications"
		],
		"ecompetences": [
			[
				"A.7.",
				"Technology Trend Monitoring",
				3
			],
			[
				"B.3.",
				"Testing",
				4
			],
			[
				"B.5.",
				"Documentation Production",
				3
			],
			[
				"E.3.",
				"Risk Management",
				3
			]
		]
	},
	{
		"title": "Penetration Tester",
		"alternative_titles": [
			"Pentester",
			"Ethical Hacker",
			"Vulnerability Analyst",
			"Cybersecurity Tester",
			"Offensive Cybersecurity Expert",
			"Defensive Cybersecurity Expert",
			"Red Team Expert",
			"Red Teamer"
		],
		"summary_statement": "Assess the effectiveness of security controls, reveals and utilise cybersecurity vulnerabilities, assessing their criticality if exploited by threat actors.",
		"mission": "Plans, designs, implements and executes penetration testing activities and attack scenarios to evaluate the effectiveness of deployed or planned security measures. Identifies vulnerabilities or failures on technical and organisational controls that affect the confidentiality, integrity and availability of ICT products (e.g. systems, hardware, software and services).",
		"deliverables": [
			"Vulnerability Assessment Results Report",
			"Penetration Testing Report"
		],
		"main_tasks": [
			"Identify, analyse and assess technical and organisational cybersecurity vulnerabilities",
			"Identify attack vectors, uncover and demonstrate exploitation of technical cybersecurity vulnerabilities",
			"Test systems and operations compliance with regulatory standards",
			"Select and develop appropriate penetration testing techniques",
			"Organise test plans and procedures for penetration testing",
			"Establish procedures for penetration testing result analysis and reporting",
			"Document and report penetration testing results to stakeholders",
			"Deploy penetration testing tools and test programs"
		],
		"key_skills": [
			"Develop codes, scripts and programmes",
			"Perform social engineering",
			"Identify and exploit vulnerabilities",
			"Conduct ethical hacking",
			"Think creatively and outside the box",
			"Identify and solve cybersecurity-related issues",
			"Communicate, present and report to relevant stakeholders",
			"Use penetration testing tools effectively",
			"Conduct technical analysis and reporting",
			"Decompose and analyse systems to identify weaknesses and ineffective controls",
			"Review codes assess their security"
		],
		"key_knowledge": [
			"Cybersecurity attack procedures",
			"Information technology (IT) and operational technology (OT) appliances",
			"Offensive and defensive security procedures",
			"Operating systems security",
			"Computer networks security",
			"Penetration testing procedures",
			"Penetration testing standards, methodologies and frameworks",
			"Penetration testing tools",
			"Computer programming",
			"Computer systems vulnerabilities",
			"Cybersecurity recommendations and best practices",
			"Cybersecurity-related certifications"
		],
		"ecompetences": [
			[
				"B.2.",
				"Component Integration",
				4
			],
			[
				"B.3.",
				"Testing",
				4
			],
			[
				"B.4.",
				"Solution Deployment",
				2
			],
			[
				"B.5.",
				"Documentation Production",
				3
			],
			[
				"E.3.",
				"Risk Management",
				4
			]
		]
	}
]