What it pays
Government survey numbers — not estimates, not ads.
The work, task by task
These are the real jobs-to-be-done, not a wish list. Each task shows where we found it, and the prompt underneath is written for that exact task.
Simulate cyberattacks to evaluate security
+Plan and execute a red-team simulation of likely attacker paths against the corporate web portal and VPN,…
Simulate cyberattacks to evaluate security
+Perform security vulnerability assessments
+Run an automated vulnerability scan across the external IP range and the main application stack, validate…
Perform security vulnerability assessments
+Perform penetration tests
+Conduct time-boxed penetration testing of the public-facing APIs and authentication flows, attempt privilege…
Perform penetration tests
+Collect stakeholder data to evaluate risk and to develop mitigation strategies.
+Collect contact lists, system owners, network diagrams, authentication flows and recent incident summaries…
Collect stakeholder data to evaluate risk and to develop mitigation strategies.
+Configure information systems to incorporate principles of least functionality and least access.
+Harden the web and API environments: lock down service ports, remove unused daemons, enforce role-based…
Configure information systems to incorporate principles of least functionality and least access.
+Develop presentations on threat intelligence.
+Draft a 12-slide briefing for the CISO and three business unit heads summarising current threat actors,…
Develop presentations on threat intelligence.
+Update corporate policies to improve cyber security.
+Rewrite the acceptable use and remote access sections in the corporate cyber policy to require multi-factor…
Update corporate policies to improve cyber security.
+Document findings and generate detailed reports
+Compile the test evidence, risk ratings, exploited vectors and reproducible steps into a technical report,…
Document findings and generate detailed reports
+Recommend security improvements based on test results
+Produce a prioritized remediation plan listing code fixes, configuration changes and compensating controls…
Recommend security improvements based on test results
+Identify ICT system weaknesses
+Run a focused assessment of the corporate network and web applications to list exploitable misconfigurations,…
Identify ICT system weaknesses
+Tools for ICT test automation
+Build an automated test suite that runs credentialed scans, fuzzing against public endpoints, and privilege…
Tools for ICT test automation
+Perform follow-up tests to verify remediation
+Run the retest plan against the fixed web app and the patched API endpoints, confirm the original SQL…
Perform follow-up tests to verify remediation
+Support testing in cloud and virtualized environments
+Provision isolated ephemeral instances and the same application stack used in production, deploy the test…
Support testing in cloud and virtualized environments
+Determine target systems for testing
+Compile the target inventory from the asset register and live scans, prioritise internet-facing services,…
Determine target systems for testing
+Attain specific testing goals
+Translate the statement of work into measurable testing objectives: show where privilege escalation is…
Attain specific testing goals
+Identify ICT security risks
+Run threat modelling workshops with the app owners to list assets, likely attackers, attack paths and…
Identify ICT security risks
+Analyse the context of an organisation
+Interview the CTO and ops leads, review network diagrams and supplier contracts, map technology, data flows…
Analyse the context of an organisation
+Assess potential for unauthorized access
+Assess the likelihood of unauthorized access by reviewing access logs, misconfigurations, and default…
Assess potential for unauthorized access
+Identify vulnerabilities in computer systems
+Run a focused attack campaign against the corporate Windows and Linux hosts used by Finance and HR this week,…
Identify vulnerabilities in computer systems
+Analyze network traffic and security protocols
+Capture and analyse a full day of ingress and egress traffic across the London office gateway, map protocol…
Analyze network traffic and security protocols
+Says who?
These are the pages we read to build this. Open any of them and check us.
Activities this job lives in
The human activities behind the tasks — each with its honest AI ceiling.
The logs, files & records this job keeps
Shared with other careers — the same record means something different in each.
Related careers
Same family of work — each with its own tasks and prompts.
The rest of the map
Same library, five ways in.
Built on public evidence: O*NET®, ESCO, Wikipedia, U.S. Bureau of Labor Statistics, ILOSTAT. All sources & licenses