feat: director-of-compliance-and-information-security skill package v0.1.0

This commit is contained in:
skillfactor-pipeline
2026-08-14 16:21:35 +02:00
commit d8423cf1e1
9 changed files with 848 additions and 0 deletions

31
PROVENANCE.md Normal file
View File

@@ -0,0 +1,31 @@
# Data provenance — director-of-compliance-and-information-security
Where the content of this skill package comes from, counted by
content items (tasks, competences, tools, evidence entries, curated
knowledge). Rendered live by Gitea:
```mermaid
%%{init: {'theme':'base','themeVariables':{'pie1':'#f9a825','pie2':'#1e88e5','pie3':'#ff355e','pie4':'#d97757','pie5':'#8e24aa','pieOuterStrokeWidth':'0px','pieSectionTextColor':'#fff'}}}%%
pie showData
title Content sources — director-of-compliance-and-information-security
"ESCO (occupation & competences)" : 13
"O*NET (tasks & tools)" : 136
"Job boards (market evidence)" : 48
"Anthropic official Claude skills" : 7
"External AI skill packs (mapped)" : 136
```
| Source | Items | Share | Files |
|---|---|---|---|
| ESCO (occupation & competences) | 13 | 3.8 % | references/profile.md, references/skills.md |
| O*NET (tasks & tools) | 136 | 40.0 % | references/tasks.md, references/tools.md |
| Job boards (market evidence) | 48 | 14.1 % | references/market.md (full report) + "Market evidence" headline sections |
| Wikipedia & AI expert curation | 0 | 0.0 % | glossary, literature, usecases, intake, quality, evals/ |
| Anthropic official Claude skills | 7 | 2.1 % | references/ai-skills.md, section "anthropics/skills" (official Claude Code skills) |
| External AI skill packs (mapped) | 136 | 40.0 % | references/ai-skills.md (per-source attribution inside) |
| Stack Exchange practitioner Q&A (CC-BY-SA) | 0 | 0.0 % | references/practitioner-qa.md (per-entry attribution inside) |
Licensing: O*NET (USDOL/ETA, CC BY 4.0) · ESCO (© European Union) ·
job-ad evidence via official APIs (JSearch/Adzuna) · Wikipedia content
paraphrased with source URLs — never copied · external AI skills are
linked, not copied (Apache-2.0/MIT/source-available, see ai-skills.md).

50
SKILL.md Normal file
View File

@@ -0,0 +1,50 @@
---
name: director-of-compliance-and-information-security
description: "Occupational skill for the role 'director of compliance and information security' (also: cybersecurity compliance director, IT compliance manager, manager of compliance and information security, cyber legal advisor, compliance and information security manager, compliance and information security director). Use when the user asks for typical director of compliance and information security work such as: typical director of compliance and information security responsibilities"
---
# Director Of Compliance And Information Security
Directors of compliance and information security follow the regulatory compliance and oversee information security to ensure security of all information technology associated.
## Core workflow
## How to use this skill
- Read [references/profile.md](references/profile.md) for the occupation profile and scope.
- Consult [references/tasks.md](references/tasks.md) for the full task and activity inventory.
- Check [references/skills.md](references/skills.md) for essential vs. optional competences.
- Check [references/tools.md](references/tools.md) for the software commonly used in this role.
- See [references/ai-skills.md](references/ai-skills.md) — matched external AI agent skills (per-source attribution).
## Key competences (essential)
- cooperate with colleagues
- cyber security
- ensure compliance with legal requirements
- ensure compliance with policies
- ICT security legislation
- ICT security standards
- implement ICT risk management
- implement ICT security policies
- information security strategy
- keep up-to-date with regulations
- lead a team
- manage IT security compliances
## Hot technologies
- Adobe Acrobat
- Apple Safari
- Microsoft Access
- Microsoft Excel
- Microsoft Office software
- Microsoft Outlook
- Microsoft PowerPoint
- Microsoft Project
- Microsoft SharePoint
- Microsoft Visio
---
*Sources: ESCO v1.2.1 (http://data.europa.eu/esco/occupation/b1ed68f8-8d51-4bcc-8825-bd554859480f), O*NET 30.3 (11-9199.02, manual nearest match). See manifest.json for licensing/attribution.*

196
manifest.json Normal file
View File

@@ -0,0 +1,196 @@
{
"name": "director-of-compliance-and-information-security",
"title": "director of compliance and information security",
"version": "0.1.0",
"layer": "core",
"language": "en",
"generated": "2026-07-07",
"ids": {
"esco_uri": "http://data.europa.eu/esco/occupation/b1ed68f8-8d51-4bcc-8825-bd554859480f",
"esco_code": "1213.9",
"isco_group": "1213",
"onet_soc": "11-9199.02",
"crosswalk_match": "manual nearest via ISCO 1213 (Compliance Managers)"
},
"sources": [
{
"name": "ESCO",
"version": "1.2.1",
"url": "https://esco.ec.europa.eu/"
},
{
"name": "O*NET",
"version": "30.3",
"url": "https://www.onetcenter.org/",
"license": "CC BY 4.0"
}
],
"attribution": "This package includes information from the O*NET Database (v30.3) by the U.S. Department of Labor, Employment and Training Administration (USDOL/ETA), CC BY 4.0. skillfactor is not endorsed by USDOL/ETA. ESCO data (v1.2.1) (c) European Union, used per the ESCO download conditions: https://esco.ec.europa.eu/en/use-esco/download",
"counts": {
"tasks": 0,
"dwas": 0,
"skills_essential": 12,
"skills_optional": 0,
"software": 0
},
"enrichment_ai_skills": {
"generated": "2026-07-14",
"method": "deterministic mapping (ISCO prefix + title/competence keywords)",
"sources": {
"anthropics/skills": {
"repo": "https://github.com/anthropics/skills",
"commit": "f6656c1",
"license": "Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available \u2014 see the LICENSE.txt in the upstream skill folder",
"skills": 4
},
"wshobson/agents": {
"repo": "https://github.com/wshobson/agents",
"commit": "6fd3247",
"license": "MIT (c) Seth Hobson",
"skills": 12
},
"ConardLi/garden-skills": {
"repo": "https://github.com/ConardLi/garden-skills",
"commit": "fbd6453",
"license": "MIT",
"skills": 1
},
"alirezarezvani/claude-skills": {
"repo": "https://github.com/alirezarezvani/claude-skills",
"commit": "0241f43",
"license": "MIT",
"skills": 2
},
"mukul975/Anthropic-Cybersecurity-Skills": {
"repo": "https://github.com/mukul975/Anthropic-Cybersecurity-Skills",
"commit": "673da1f",
"license": "Apache-2.0",
"skills": 12
},
"jeremylongshore/claude-code-plugins-plus-skills": {
"repo": "https://github.com/jeremylongshore/claude-code-plugins-plus-skills",
"commit": "e112938a",
"license": "MIT",
"skills": 12
},
"davila7/claude-code-templates": {
"repo": "https://github.com/davila7/claude-code-templates",
"commit": "fa79251",
"license": "MIT",
"skills": 4
},
"nWave-ai/nWave": {
"repo": "https://github.com/nWave-ai/nWave",
"commit": "1d0f13c",
"license": "MIT",
"skills": 1
},
"a5c-ai/babysitter": {
"repo": "https://github.com/a5c-ai/babysitter",
"commit": "44a5d58b",
"license": "MIT",
"skills": 12
},
"vibeeval/vibecosystem": {
"repo": "https://github.com/vibeeval/vibecosystem",
"commit": "cea9462",
"license": "MIT",
"skills": 5
},
"samber/cc-skills-golang": {
"repo": "https://github.com/samber/cc-skills-golang",
"commit": "4881c01",
"license": "MIT",
"skills": 1
},
"zxkane/aws-skills": {
"repo": "https://github.com/zxkane/aws-skills",
"commit": "68530c6",
"license": "MIT",
"skills": 1
},
"mohitagw15856/pm-claude-skills": {
"repo": "https://github.com/mohitagw15856/pm-claude-skills",
"commit": "876fa30",
"license": "MIT",
"skills": 1
},
"zebbern/claude-code-guide": {
"repo": "https://github.com/zebbern/claude-code-guide",
"commit": "d2c5280",
"license": "MIT",
"skills": 1
},
"trailofbits/skills": {
"repo": "https://github.com/trailofbits/skills",
"commit": "cfe5d7b",
"license": "custom (see upstream LICENSE)",
"skills": 5
},
"Sushegaad/Claude-Skills-Governance-Risk-and-Compliance": {
"repo": "https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance",
"commit": "71d8920",
"license": "MIT",
"skills": 1
},
"bitwize-music-studio/claude-ai-music-skills": {
"repo": "https://github.com/bitwize-music-studio/claude-ai-music-skills",
"commit": "96446de",
"license": "custom (see upstream LICENSE)",
"skills": 1
},
"alirezarezvani/claude-code-skill-factory": {
"repo": "https://github.com/alirezarezvani/claude-code-skill-factory",
"commit": "ba18b31",
"license": "MIT",
"skills": 1
},
"avelikiy/great_cto": {
"repo": "https://github.com/avelikiy/great_cto",
"commit": "4fe1e39",
"license": "MIT",
"skills": 1
},
"rsmdt/the-startup": {
"repo": "https://github.com/rsmdt/the-startup",
"commit": "ff6a0be",
"license": "MIT",
"skills": 1
},
"brycewang-stanford/Auto-Empirical-Research-Skills": {
"repo": "https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills",
"commit": "85bf545",
"license": "CC-BY-4.0",
"skills": 1
}
},
"total_skills": 80,
"tiers": {
"core": 73,
"adjacent": 7
}
},
"provenance": {
"items": {
"esco": 13,
"onet": 136,
"jobads": 48,
"wiki_ai": 0,
"anthropic": 7,
"ai_skills": 136,
"stackx": 0
},
"share_percent": {
"esco": 3.8,
"onet": 40.0,
"jobads": 14.1,
"wiki_ai": 0.0,
"anthropic": 2.1,
"ai_skills": 40.0,
"stackx": 0.0
},
"method": "content items per source category"
},
"collar": "white",
"computer_work": true
}

266
references/ai-skills.md Normal file
View File

@@ -0,0 +1,266 @@
# External AI agent skills — director-of-compliance-and-information-security
Proven, publicly available AI agent skills mapped to this occupation.
Nothing is copied from the sources: every entry is a name, a one-line
summary and a link to the upstream skill package. Each section names
its source repository, commit, license and retrieval date.
**Tiers:** `core` = the skill directly exercises a top market hard
skill, tool or method (from gated job-ad evidence) or an essential
ESCO competence of this occupation; `adjacent` =
plausibly useful, secondary. Entries are capped at 12 per source
and 80 in total per occupation (core first,
strongest matches survive); everything beyond the caps is excluded
and logged in the pipeline audit trail, not in this package.
_Matched deterministically (ISCO group + title/competence keywords,
tiered against market evidence + ESCO essentials) by
`pipeline/p5_enrich_ai_skills.py` on 2026-07-14._
## Source: anthropics/skills
- Repository: [https://github.com/anthropics/skills](https://github.com/anthropics/skills) (commit `f6656c1`, retrieved 2026-07-14)
- License: Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available — see the LICENSE.txt in the upstream skill folder
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `docx` | adjacent | Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to … | [source](https://github.com/anthropics/skills/tree/main/skills/docx) |
| `pdf` | adjacent | Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text/tables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating … | [source](https://github.com/anthropics/skills/tree/main/skills/pdf) |
| `pptx` | adjacent | Use this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even … | [source](https://github.com/anthropics/skills/tree/main/skills/pptx) |
| `skill-creator` | adjacent | Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with … | [source](https://github.com/anthropics/skills/tree/main/skills/skill-creator) |
## Source: wshobson/agents
- Repository: [https://github.com/wshobson/agents](https://github.com/wshobson/agents) (commit `6fd3247`, retrieved 2026-07-14)
- License: MIT (c) Seth Hobson
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `security-compliance-security-auditor (agent)` | core | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and … | [source](https://github.com/wshobson/agents/tree/main/plugins/security-compliance/agents/security-auditor.md) |
| `frontend-mobile-security-frontend-developer (agent)` | core | Build React components, implement responsive layouts, and handle client-side state management. Masters React 19, Next.js 15, and modern frontend architecture. Optimizes performance and ensures accessibility. Use PROACTIVELY when creating … | [source](https://github.com/wshobson/agents/tree/main/plugins/frontend-mobile-security/agents/frontend-developer.md) |
| `stride-analysis-patterns` | core | Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/stride-analysis-patterns) |
| `threat-mitigation-mapping` | core | Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mapping) |
| `incident-runbook-templates` | core | Create structured incident response runbooks with step-by-step procedures, escalation paths, and recovery actions. Use this skill when building a service outage runbook for a payment processing system; creating database incident procedures … | [source](https://github.com/wshobson/agents/tree/main/plugins/incident-response/skills/incident-runbook-templates) |
| `anti-reversing-techniques` | core | Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when implementing anti-debugging protections for CTF challenges, when reverse … | [source](https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniques) |
| `postmortem-writing` | core | Write effective blameless postmortems with root cause analysis, timelines, and action items. Use when conducting incident reviews, writing postmortem documents, or improving incident response processes. | [source](https://github.com/wshobson/agents/tree/main/plugins/incident-response/skills/postmortem-writing) |
| `protocol-reverse-engineering` | core | Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication. | [source](https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/protocol-reverse-engineering) |
| `memory-forensics` | core | Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from … | [source](https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/memory-forensics) |
| `binary-analysis-patterns` | core | Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries. | [source](https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/binary-analysis-patterns) |
| `backend-api-security-backend-architect (agent)` | adjacent | Expert backend architect specializing in scalable API design, microservices architecture, and distributed systems. Masters REST/GraphQL/gRPC APIs, event-driven architectures, service mesh patterns, and modern backend frameworks. Handles … | [source](https://github.com/wshobson/agents/tree/main/plugins/backend-api-security/agents/backend-architect.md) |
| `sast-configuration` | adjacent | Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automating code vulnerability detection. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/sast-configuration) |
## Source: ConardLi/garden-skills
- Repository: [https://github.com/ConardLi/garden-skills](https://github.com/ConardLi/garden-skills) (commit `fbd6453`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `kb-retriever` | adjacent | 面向本地知识库目录的检索和问答助手。核心流程:(1)分层索引导航 (2)遇到PDF/Excel时必须先读取references学习处理方法 (3)处理文件后再检索。按文件类型组合使用 grep、Read、pdfplumber、pandas 进行渐进式检索,避免整文件加载。用户问题涉及"从知识库目录回答问题/检索信息/查资料"时使用。 | [source](https://github.com/ConardLi/garden-skills/tree/fbd6453/skills/kb-retriever) |
## Source: a5c-ai/babysitter
- Repository: [https://github.com/a5c-ai/babysitter](https://github.com/a5c-ai/babysitter) (commit `44a5d58b`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `bug-bounty` | core | Bug bounty program management and security disclosure expertise for smart contracts. Covers program setup on Immunefi, vulnerability triage, responsible disclosure coordination, bounty payments, and post-disclosure analysis. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/bug-bounty) |
| `security-sandbox` | core | Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage Docker-based analysis containers, and capture filesystem and … | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-research/skills/security-sandbox) |
| `echidna-fuzzer` | core | Property-based testing and fuzzing using Echidna for smart contracts. Includes invariant definition, corpus management, coverage analysis, and CI/CD integration for comprehensive security testing. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/echidna-fuzzer) |
| `gdpr-compliance-automator` | core | GDPR compliance assessment and automation for data mapping, consent management, DSAR handling, and privacy impact assessments | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-compliance/skills/gdpr-compliance-automator) |
| `policy-management` | core | Manage corporate policy lifecycle from drafting through compliance | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/business/legal/skills/policy-management) |
| `cloud-security-testing` | core | Multi-cloud security assessment and penetration testing capabilities. Execute Prowler/ScoutSuite assessments, analyze IAM policies, identify cloud misconfigurations, test permissions, and enumerate cloud resources across AWS/GCP/Azure. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-research/skills/cloud-security-testing) |
| `openzeppelin` | core | Expert usage of OpenZeppelin Contracts library for secure smart contract development. Covers access control, token standards, governance, upgrades, and security utilities. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/openzeppelin) |
| `regulatory-compliance-assessment` | core | Evaluate organizational compliance with healthcare regulations including HIPAA, CMS Conditions of Participation, and accreditation standards through gap analysis and audit procedures | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/social-sciences-humanities/healthcare/skills/regulatory-compliance-assessment) |
| `constitution-creation` | core | Establish project governing principles including dev guidelines, code quality standards, testing policies, UX requirements, performance benchmarks, and security constraints. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/methodologies/spec-kit/skills/constitution-creation) |
| `solidity-dev` | core | Deep expertise in Solidity language features, patterns, and best practices for secure smart contract development. Covers ERC standards, gas optimization, upgradeable contracts, and security patterns. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/solidity-dev) |
| `Static Analysis Tools Skill` | core | Integration with security-focused static analysis tools | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-research/skills/static-analysis-tools) |
| `code-review-patterns` | core | Multi-dimensional code assessment across security, quality, performance, and maintainability with confidence-gated reporting (>=80%) and Router Contract generation. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/methodologies/cc10x/skills/code-review-patterns) |
## Source: alirezarezvani/claude-code-skill-factory
- Repository: [https://github.com/alirezarezvani/claude-code-skill-factory](https://github.com/alirezarezvani/claude-code-skill-factory) (commit `ba18b31`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `tech-stack-evaluator` | core | Comprehensive technology stack evaluation and comparison tool with TCO analysis, security assessment, and intelligent recommendations for engineering teams | [source](https://github.com/alirezarezvani/claude-code-skill-factory/tree/ba18b31/generated-skills/tech-stack-evaluator) |
## Source: alirezarezvani/claude-skills
- Repository: [https://github.com/alirezarezvani/claude-skills](https://github.com/alirezarezvani/claude-skills) (commit `0241f43`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `ciso-advisor` | core | Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when … | [source](https://github.com/alirezarezvani/claude-skills/tree/0241f43/c-level-advisor/skills/ciso-advisor) |
| `iso42001-specialist` | core | ISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits. Three decisions: (1) Where are the gaps against Clauses 4-10 and what do we close first? (2) What goes in the AI risk register and … | [source](https://github.com/alirezarezvani/claude-skills/tree/0241f43/ra-qm-team/compliance-team-iso42001/skills/iso42001-specialist) |
## Source: avelikiy/great_cto
- Repository: [https://github.com/avelikiy/great_cto](https://github.com/avelikiy/great_cto) (commit `4fe1e39`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `well-architected` | core | 6-pillar architecture review framework. Adapted from AWS Well-Architected for use by great_cto's architect agent on every non-nano ARCH document. Forces explicit answers across operational excellence, security, reliability, performance, … | [source](https://github.com/avelikiy/great_cto/tree/4fe1e39/skills/well-architected) |
## Source: bitwize-music-studio/claude-ai-music-skills
- Repository: [https://github.com/bitwize-music-studio/claude-ai-music-skills](https://github.com/bitwize-music-studio/claude-ai-music-skills) (commit `96446de`, retrieved 2026-07-14)
- License: custom (see upstream LICENSE)
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `researchers-security` | core | Researches malware analysis, CVEs, attribution reports, and hacker community sources. Use when the album subject involves cybersecurity incidents or threat actors. | [source](https://github.com/bitwize-music-studio/claude-ai-music-skills/tree/96446de/skills/researchers-security) |
## Source: brycewang-stanford/Auto-Empirical-Research-Skills
- Repository: [https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills) (commit `85bf545`, retrieved 2026-07-14)
- License: CC-BY-4.0
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `cs-skills` | core | 10 computer science skills. Trigger: algorithms, systems research, software engineering, security papers. Design: theory, complexity analysis, code-centric research, and security methods. | [source](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills/tree/85bf545/skills/43-wentorai-research-plugins/skills/domains/cs) |
## Source: davila7/claude-code-templates
- Repository: [https://github.com/davila7/claude-code-templates](https://github.com/davila7/claude-code-templates) (commit `fa79251`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `security-compliance` | core | Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/security-compliance) |
| `Data Privacy Compliance` | core | Data privacy and regulatory compliance specialist for GDPR, CCPA, HIPAA, and international data protection laws. Use when implementing privacy controls, conducting data protection impact assessments, ensuring regulatory compliance, or … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/enterprise-communication/data-privacy-compliance) |
| `gdpr-dsgvo-expert` | core | Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact assessments, data protection auditing, and compliance verification. Use for GDPR compliance … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/enterprise-communication/gdpr-dsgvo-expert) |
| `laravel-expert` | core | Senior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+). | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/laravel-expert) |
## Source: jeremylongshore/claude-code-plugins-plus-skills
- Repository: [https://github.com/jeremylongshore/claude-code-plugins-plus-skills](https://github.com/jeremylongshore/claude-code-plugins-plus-skills) (commit `e112938a`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `cursor-compliance-audit` | core | Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. Triggers on "cursor compliance", "cursor audit", "cursor security review", "cursor soc2", "cursor gdpr", "cursor … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/cursor-pack/skills/cursor-compliance-audit) |
| `generating-compliance-reports` | core | Generate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance report', 'compliance status', or 'audit compliance'. | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/security/compliance-report-generator/skills/generating-compliance-reports) |
| `plugin-auditor` | core | Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. specific to AI … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/examples/jeremy-plugin-tool/skills/plugin-auditor) |
| `instantly-data-handling` | core | Implement Instantly.ai lead data management, GDPR/CAN-SPAM compliance, and list operations. Use when handling lead imports, managing block lists, implementing unsubscribe flows, or ensuring compliance with email regulations. Trigger with … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/instantly-pack/skills/instantly-data-handling) |
| `supabase-data-handling` | core | Implement GDPR/CCPA compliance with Supabase: RLS for data isolation, user deletion via auth.admin.deleteUser(), data export via SQL, PII column management, backup/restore workflows, and retention policies. Use when handling sensitive … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/supabase-pack/skills/supabase-data-handling) |
| `flexport-data-handling` | core | Implement data handling for Flexport supply chain data including PII redaction, shipment data retention, GDPR compliance, and secure document management. Trigger: "flexport data handling", "flexport PII", "flexport GDPR", "flexport data … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/flexport-pack/skills/flexport-data-handling) |
| `twinmind-data-handling` | core | Handle TwinMind meeting data with GDPR compliance: transcript storage, memory vault management, data export, and deletion policies. Use when implementing data handling, or managing TwinMind meeting AI operations. Trigger with phrases like … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/twinmind-pack/skills/twinmind-data-handling) |
| `apollo-data-handling` | core | Apollo.io data management and compliance. Use when handling contact data, implementing GDPR compliance, or managing data exports and retention. Trigger with phrases like "apollo data", "apollo gdpr", "apollo compliance", "apollo data … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/apollo-pack/skills/apollo-data-handling) |
| `posthog-data-handling` | core | PostHog PII handling, GDPR compliance, consent management, data deletion, property sanitization, and privacy-safe analytics configuration. Trigger: "posthog data", "posthog PII", "posthog GDPR", "posthog data retention", "posthog privacy", … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/posthog-pack/skills/posthog-data-handling) |
| `canva-data-handling` | core | Implement Canva Connect API data handling, PII protection, and GDPR/CCPA compliance. Use when handling user design data, implementing data retention policies, or ensuring privacy compliance for Canva integrations. Trigger with phrases like … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/canva-pack/skills/canva-data-handling) |
| `clay-data-handling` | core | Implement GDPR/CCPA-compliant data handling for Clay enrichment pipelines. Use when handling PII from enrichments, implementing data retention policies, or ensuring regulatory compliance for Clay-enriched lead data. Trigger with phrases … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/clay-pack/skills/clay-data-handling) |
| `figma-policy-guardrails` | core | Enforce security policies and coding standards for Figma API integrations. Use when setting up linting rules for Figma tokens, preventing accidental credential leaks, or enforcing API usage best practices. Trigger with phrases like "figma … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/figma-pack/skills/figma-policy-guardrails) |
## Source: mohitagw15856/pm-claude-skills
- Repository: [https://github.com/mohitagw15856/pm-claude-skills](https://github.com/mohitagw15856/pm-claude-skills) (commit `876fa30`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `compliance-checklist` | core | Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any … | [source](https://github.com/mohitagw15856/pm-claude-skills/tree/876fa30/plugins/pm-legal/skills/compliance-checklist) |
## Source: mukul975/Anthropic-Cybersecurity-Skills
- Repository: [https://github.com/mukul975/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills) (commit `673da1f`, retrieved 2026-07-14)
- License: Apache-2.0
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `achieving-cmmc-level-2-compliance` | core | Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/achieving-cmmc-level-2-compliance) |
| `implementing-iso-27001-information-security-management` | core | ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-iso-27001-information-security-management) |
| `implementing-azure-defender-for-cloud` | core | Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-azure-defender-for-cloud) |
| `hardening-linux-endpoint-with-cis-benchmark` | core | Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Linux servers, remediating audit … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/hardening-linux-endpoint-with-cis-benchmark) |
| `hardening-windows-endpoint-with-cis-benchmark` | core | Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/hardening-windows-endpoint-with-cis-benchmark) |
| `implementing-aws-security-hub-compliance` | core | Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-aws-security-hub-compliance) |
| `implementing-aws-security-hub` | core | This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-aws-security-hub) |
| `auditing-cloud-with-cis-benchmarks` | core | This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/auditing-cloud-with-cis-benchmarks) |
| `prioritizing-vulnerabilities-with-cvss-scoring` | core | The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/prioritizing-vulnerabilities-with-cvss-scoring) |
| `securing-kubernetes-on-cloud` | core | This skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring. It addresses … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/securing-kubernetes-on-cloud) |
| `auditing-foundry-smart-contract-security` | core | Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/auditing-foundry-smart-contract-security) |
| `detecting-spearphishing-with-email-gateway` | core | Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint, | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/detecting-spearphishing-with-email-gateway) |
## Source: nWave-ai/nWave
- Repository: [https://github.com/nWave-ai/nWave](https://github.com/nWave-ai/nWave) (commit `1d0f13c`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `nw-security-and-governance` | core | Database security (encryption, access control, injection prevention), data governance (lineage, quality, MDM), and compliance frameworks (GDPR, CCPA, HIPAA) | [source](https://github.com/nWave-ai/nWave/tree/1d0f13c/nWave/skills/nw-security-and-governance) |
## Source: rsmdt/the-startup
- Repository: [https://github.com/rsmdt/the-startup](https://github.com/rsmdt/the-startup) (commit `ff6a0be`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `code-quality-review` | core | Unified code review skill for correctness, design, readability, security, performance, testability, accessibility, and error-handling conventions. Use when reviewing changes, enforcing quality standards, or identifying technical debt. | [source](https://github.com/rsmdt/the-startup/tree/ff6a0be/plugins/team/skills/quality/code-quality-review) |
## Source: samber/cc-skills-golang
- Repository: [https://github.com/samber/cc-skills-golang](https://github.com/samber/cc-skills-golang) (commit `4881c01`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `golang-security` | core | Security best practices and vulnerability prevention for Golang. Covers injection (SQL, command, XSS), cryptography, filesystem safety, network security, cookies, secrets management, memory safety, and logging. Apply when writing, … | [source](https://github.com/samber/cc-skills-golang/tree/4881c01/skills/golang-security) |
## Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
- Repository: [https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) (commit `71d8920`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `gdpr-compliance` | core | Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, … | [source](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/71d8920/plugins/gdpr-compliance/skills/gdpr-compliance) |
## Source: trailofbits/skills
- Repository: [https://github.com/trailofbits/skills](https://github.com/trailofbits/skills) (commit `cfe5d7b`, retrieved 2026-07-14)
- License: custom (see upstream LICENSE)
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `c-review` | core | Performs comprehensive C/C++ security review for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities. Use when auditing native C/C++ applications, reviewing daemons or services for memory safety, or … | [source](https://github.com/trailofbits/skills/tree/cfe5d7b/plugins/c-review/skills/c-review) |
| `rust-review` | core | Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes. Use when auditing Rust crates, services, or … | [source](https://github.com/trailofbits/skills/tree/cfe5d7b/plugins/rust-review/skills/rust-review) |
| `secure-workflow-guide` | core | Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for … | [source](https://github.com/trailofbits/skills/tree/cfe5d7b/plugins/building-secure-contracts/skills/secure-workflow-guide) |
| `audit-prep-assistant` | core | Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user … | [source](https://github.com/trailofbits/skills/tree/cfe5d7b/plugins/building-secure-contracts/skills/audit-prep-assistant) |
| `entry-point-analyzer` | core | Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level (public, admin, role-restricted, contract-only), and … | [source](https://github.com/trailofbits/skills/tree/cfe5d7b/plugins/entry-point-analyzer/skills/entry-point-analyzer) |
## Source: vibeeval/vibecosystem
- Repository: [https://github.com/vibeeval/vibecosystem](https://github.com/vibeeval/vibecosystem) (commit `cea9462`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `compliance-patterns` | core | GDPR data handling, audit logging, data classification, retention policies, and consent management for regulatory compliance. | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/compliance-patterns) |
| `kvkk-compliance` | core | KVKK and GDPR compliance patterns - consent management, right to erasure, breach notification, audit logging, cookie consent, and data classification. | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/kvkk-compliance) |
| `saas-launch-checklist` | core | Pre-launch verification across infrastructure, security, legal, payment, email, analytics, and performance. Day-1 monitoring, rollback plan, incident response skeleton, and post-launch week-1 checklist. | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/saas-launch-checklist) |
| `gdpr-compliance` | core | GDPR compliance - data subject rights, lawful basis, DPIA, privacy by design, breach notification, consent management, cross-border transfers, PII masking | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/gdpr-compliance) |
| `hipaa-compliance` | core | HIPAA compliance - PHI protection, technical/administrative/physical safeguards, minimum necessary standard, BAA requirements, de-identification, access logging | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/hipaa-compliance) |
## Source: zebbern/claude-code-guide
- Repository: [https://github.com/zebbern/claude-code-guide](https://github.com/zebbern/claude-code-guide) (commit `d2c5280`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `regulatory-audit-generator` | core | Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like \"run … | [source](https://github.com/zebbern/claude-code-guide/tree/d2c5280/skills/regulatory-audit-generator) |
## Source: zxkane/aws-skills
- Repository: [https://github.com/zxkane/aws-skills](https://github.com/zxkane/aws-skills) (commit `68530c6`, retrieved 2026-07-14)
- License: MIT
| Skill | Tier | What it adds | Upstream |
|---|---|---|---|
| `aws-cost-operations` | core | AWS cost optimization, monitoring, and operational excellence expert. Use when analyzing AWS bills, estimating costs, setting up CloudWatch alarms, querying logs, auditing CloudTrail activity, or assessing security posture. Essential when … | [source](https://github.com/zxkane/aws-skills/tree/68530c6/plugins/aws-cost-ops/skills/aws-cost-operations) |

90
references/market.md Normal file
View File

@@ -0,0 +1,90 @@
# Market evidence report — director-of-compliance-and-information-security
Source: **22 real job ads** (JSearch API, countries: us 22), extracted into the MSSQL evidence store; as of 2026-07-11.
This report contains extracted, aggregated facts only — no ad text is
reproduced (copyright / platform terms).
## Seniority distribution
| Seniority | Ads | Share |
|---|---|---|
| mid | 8 | 36 % |
| senior | 8 | 36 % |
| lead | 6 | 27 % |
## Tools — full market ranking
| # | Item | Ads | Share |
|---|---|---|---|
## Hard skills — full market ranking
| # | Item | Ads | Share |
|---|---|---|---|
| 1 | risk management | 11 | 50 % |
| 2 | incident response | 7 | 32 % |
| 3 | risk assessment | 5 | 23 % |
| 4 | regulatory compliance | 4 | 18 % |
| 5 | vulnerability management | 4 | 18 % |
| 6 | policy development | 3 | 14 % |
| 7 | security assessment | 3 | 14 % |
## Methods — full market ranking
| # | Item | Ads | Share |
|---|---|---|---|
| 1 | iso 27001 | 6 | 27 % |
| 2 | fedramp | 3 | 14 % |
| 3 | Risk Management Framework (RMF) | 3 | 14 % |
## Responsibilities — full market ranking
| # | Item | Ads | Share |
|---|---|---|---|
| 1 | project leadership | 3 | 14 % |
| 2 | team leadership | 3 | 14 % |
## Regional breakdown
> **Corpus note:** 22 relevant ads in total — below the 100-ad target for a fully reliable ranking. Percentages above should be read as indicative.
### US (us)
**Insufficient evidence** — 22 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
### UK (gb)
**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
### EU/DACH (de, at, ch, nl)
**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
## Job title variants in the market
| Title | Ads |
|---|---|
| Director, Security Compliance | 2 |
| BISO Compliance Manager AI-Driven Security & Audit Lead | 1 |
| Cyber - SAP Security and GRC Access & Process Control Manager | 1 |
| Cyber Strategy, Risk & Compliance - AI Engineering for Cybersecurity - Senior Manager | 1 |
| Cybersecurity AI Risk and Governance Director, Global | 1 |
| Cybersecurity Compliance Lead | 1 |
| Cybersecurity Compliance Lead - Active Top-Secret Clearance | 1 |
| Director of Cybersecurity, Governance, Risk and Compliance | 1 |
| Director, Cyber Security Practice | 1 |
| Director, Cybersecurity Compliance | 1 |
| Director, Information Security Audit & Compliance (Global) | 1 |
| Information Security Compliance Lead | 1 |
| Manager of Information Security and Compliance | 1 |
| Manager, Information Risk & Compliance | 1 |
| Manager, IT Risk & Compliance | 1 |
| Security Governance Risk and Compliance Manager | 1 |
| Senior Cybersecurity Compliance Manager | 1 |
| Senior Director Cyber Security & Innovation | 1 |
| Senior Information Security Manager - DoD/IC RMF Expert | 1 |
| Sr Mgr, Cyber Technical Compliance | 1 |
| Sr. Manager Cyber Security (CMMC Compliance) | 1 |
Methodology: entities extracted per ad ({hard_skills, tools, methods, responsibilities, seniority}), normalized, counted as DISTINCT ads per entity; report threshold ≥ 3 ads. Headline sections in skills.md/tools.md use the stricter ≥ 20 % threshold.

25
references/profile.md Normal file
View File

@@ -0,0 +1,25 @@
# Occupation profile — director of compliance and information security
- **ESCO URI:** http://data.europa.eu/esco/occupation/b1ed68f8-8d51-4bcc-8825-bd554859480f
- **ESCO code:** 1213.9
- **ISCO-08 group:** 1213 — Policy and planning managers
## Description (ESCO)
Directors of compliance and information security follow the regulatory compliance and oversee information security to ensure security of all information technology associated.
## Definition
nan
## Alternative labels
- cybersecurity compliance director
- IT compliance manager
- manager of compliance and information security
- cyber legal advisor
- compliance and information security manager
- compliance and information security director
- cybersecurity legal officer
- cyber law consultant
- ICT compliance manager

40
references/skills.md Normal file
View File

@@ -0,0 +1,40 @@
# Competences — director of compliance and information security
Source: ESCO v1.2.1 occupation-skill relations (http://data.europa.eu/esco/occupation/b1ed68f8-8d51-4bcc-8825-bd554859480f).
## Essential
- **cooperate with colleagues** (skill/competence)
- **cyber security** (knowledge)
- **ensure compliance with legal requirements** (skill/competence)
- **ensure compliance with policies** (skill/competence)
- **ICT security legislation** (knowledge)
- **ICT security standards** (knowledge)
- **implement ICT risk management** (skill/competence)
- **implement ICT security policies** (skill/competence)
- **information security strategy** (knowledge)
- **keep up-to-date with regulations** (skill/competence)
- **lead a team** (skill/competence)
- **manage IT security compliances** (skill/competence)
## Optional
<!-- market-evidence -->
## Market evidence (job-ad analysis, 22 ads, as of 2026-07-11)
Share of analyzed job ads mentioning the item (threshold ≥ 20 %). Source: JSearch/Adzuna APIs.
### Hard skills
- risk management — **50 %**
- incident response — **32 %**
- risk assessment — **23 %**
- regulatory compliance — **18 %**
- vulnerability management — **18 %**
### Methods
- iso 27001 — **27 %**
<!-- market-evidence -->

69
references/tasks.md Normal file
View File

@@ -0,0 +1,69 @@
# Tasks & work activities — director of compliance and information security
Source: O*NET 30.3, occupation 11-9199.02 (Compliance Managers) — manual nearest-occupation mapping via ISCO group 1213; the official ESCO crosswalk has no entry for this ESCO occupation.
## Task statements
- **[Supplemental]** Verify that software technology is in place to adequately provide oversight and monitoring in all required areas.
- **[Core]** Serve as a confidential point of contact for employees to communicate with management, seek clarification on issues or dilemmas, or report irregularities.
- **[Core]** Maintain documentation of compliance activities, such as complaints received or investigation outcomes.
- **[Core]** Consult with corporate attorneys as necessary to address difficult legal compliance issues.
- **[Core]** Collaborate with human resources departments to ensure the implementation of consistent disciplinary action strategies in cases of compliance standard violations.
- **[Core]** Advise internal management or business partners on the implementation or operation of compliance programs.
- **[Supplemental]** Review communications such as securities sales advertising to ensure there are no violations of standards or regulations.
- **[Core]** Provide employee training on compliance related topics, policies, or procedures.
- **[Core]** Report violations of compliance or regulatory standards to duly authorized enforcement agencies as appropriate or required.
- **[Core]** Provide assistance to internal or external auditors in compliance reviews.
- **[Core]** Prepare management reports regarding compliance operations and progress.
- **[Core]** Monitor compliance systems to ensure their effectiveness.
- **[Core]** Identify compliance issues that require follow-up or investigation.
- **[Core]** Disseminate written policies and procedures related to compliance activities.
- **[Core]** File appropriate compliance reports with regulatory agencies.
- **[Core]** Design or implement improvements in communication, monitoring, or enforcement of compliance standards.
- **[Core]** Conduct periodic internal reviews or audits to ensure that compliance procedures are followed.
- **[Core]** Conduct or direct the internal investigation of compliance issues.
- **[Supplemental]** Advise technical professionals on the development or use of environmental compliance or reporting tools.
- **[Supplemental]** Conduct environmental audits to ensure adherence to environmental standards.
- **[Supplemental]** Direct environmental programs, such as air or water compliance, aboveground or underground storage tanks, spill prevention or control, hazardous waste or materials management, solid waste recycling, medical waste management, indoor air quality, integrated pest management, employee training, or disaster preparedness.
- **[Supplemental]** Evaluate testing procedures to meet the specifications of environmental monitoring programs.
- **[Supplemental]** Review or modify policies or operating guidelines to comply with changes to environmental standards or regulations.
- **[Core]** Discuss emerging compliance issues to ensure that management and employees are informed about compliance reporting systems, policies, and practices.
- **[Core]** Verify that all regulatory policies and procedures have been documented, implemented, and communicated.
- **[Core]** Keep informed regarding pending industry changes, trends, or best practices.
- **[Core]** Direct the development or implementation of policies and procedures related to compliance throughout an organization.
- **[Supplemental]** Develop risk management strategies based on assessment of product, compliance, or operational risks.
- **[Supplemental]** Oversee internal reporting systems, such as corporate compliance hotlines.
## Detailed work activities
- Advise others on business or operational matters.
- Advise others on legal or regulatory compliance matters.
- Analyze risks to minimize losses or damages.
- Collaborate on research activities with scientists or technical specialists.
- Communicate organizational policies and procedures.
- Communicate with government agencies.
- Conduct employee training programs.
- Conduct environmental audits.
- Conduct financial or regulatory audits.
- Confer with organizational members to accomplish work activities.
- Coordinate reporting or editing activities.
- Determine operational compliance with regulations or standards.
- Develop computer or information systems.
- Develop emergency response plans or procedures.
- Develop operating strategies, plans, or procedures.
- Develop organizational policies or programs.
- Evaluate green operations or programs for compliance with standards or regulations.
- Examine marketing materials to ensure compliance with policies or regulations.
- Identify actions needed to bring properties or facilities into compliance with regulations.
- Implement organizational process or policy changes.
- Liaise between departments or other groups to improve function or communication.
- Maintain knowledge of current developments in area of expertise.
- Maintain regulatory or compliance documentation.
- Manage control system activities in organizations.
- Manage environmental sustainability projects.
- Monitor organizational compliance with regulations.
- Monitor organizational procedures to ensure proper functioning.
- Prepare reports related to compliance matters.
- Stay informed about current developments in field of specialization.
- Update knowledge about emerging industry or technology trends.
- Verify accuracy of records.

81
references/tools.md Normal file
View File

@@ -0,0 +1,81 @@
# Tools & technology — director of compliance and information security
Source: O*NET 30.3, occupation 11-9199.02 (Compliance Managers) — manual nearest-occupation mapping via ISCO group 1213; the official ESCO crosswalk has no entry for this ESCO occupation.
| Software | Category | Hot technology |
|---|---|---|
| Adobe Acrobat | Document management software | yes |
| Apple Safari | Internet browser software | yes |
| Microsoft Access | Data base user interface and query software | yes |
| Microsoft Excel | Spreadsheet software | yes |
| Microsoft Office software | Office suite software | yes |
| Microsoft Outlook | Electronic mail software | yes |
| Microsoft PowerPoint | Presentation software | yes |
| Microsoft Project | Project management software | yes |
| Microsoft SharePoint | Document management software | yes |
| Microsoft Visio | Process mapping and design software | yes |
| Microsoft Windows | Operating system software | yes |
| Microsoft Word | Word processing software | yes |
| Mozilla Firefox | Internet browser software | yes |
| 80-20 Software Leaders4 | Compliance software | |
| Actimize Brokerage Compliance Solutions | Compliance software | |
| Agiliance Compliance Manager | Compliance software | |
| Aline GRC | Compliance software | |
| ARC Logics Sword | Compliance software | |
| Archer Compliance Management | Compliance software | |
| AssurX CATSWeb | Compliance software | |
| AssurX Financial Services Compliance Management System | Compliance software | |
| Audit2 AdaptiveGRC | Compliance software | |
| Axentis Compliance Management | Compliance software | |
| BPS Compliance | Compliance software | |
| BWise Compliance Management | Compliance software | |
| CMO Compliance Regulatory Compliance Solution | Compliance software | |
| Compliance 360 | Compliance software | |
| Compliance11 Supervisory Suite | Compliance software | |
| ComplianceBridge Total Compliance | Compliance software | |
| ControlCase Compliance Manager | Compliance software | |
| Cura Software Solutions Cura for Compliance Management | Compliance software | |
| Data analysis software | Analytical or scientific software | |
| Database management software | Data base management system software | |
| DoubleCheck GRC&T Platform | Compliance software | |
| Email software | Electronic mail software | |
| EtQ Environmental Health and Safety Software | Compliance software | |
| EtQ FDA cGxP Compliance Software for Life Sciences | Compliance software | |
| Fidessa Compliance Manager | Compliance software | |
| FRSGlobal RegPro | Compliance software | |
| Governance, risk, and compliance GRC software | Compliance software | |
| Guideline Risk Technologies RUBI | Compliance software | |
| Healthcare common procedure coding system HCPCS | Medical software | |
| Horwath Software Magique | Analytical or scientific software | |
| Human resource information system (HRIS) | Human resources software | |
| IBM Notes | Electronic mail software | |
| Keane SCORE | Compliance software | |
| LexisNexis | Information retrieval or search software | |
| LRN Ethics and Compliance Alliance | Compliance software | |
| MasterControl MD | Risk management data and analysis software | |
| MasterControl TotalPharma | Risk management data and analysis software | |
| MediRegs ComplyTrack | Compliance software | |
| Methodware ERA | Compliance software | |
| MetricStream Compliance Management | Compliance software | |
| MetricStream Enterprise Compliance Platform | Compliance software | |
| MetricStream Regulatory Reporting | Compliance software | |
| Microsoft Internet Explorer | Internet browser software | |
| Modulo Risk Manager | Compliance software | |
| MyComplianceOffice Compliance Operations Management System | Compliance software | |
| Neohapsis Certus GRC | Compliance software | |
| Oracle Enterprise Governance, Risk, and Compliance Manager | Compliance software | |
| Oracle Insurance Compliance Tracker | Compliance software | |
| policyIQ | Compliance software | |
| Protiviti Governance Portal | Compliance software | |
| QUMAS quality management solution software | Compliance software | |
| Resolve Legislative Compliance Management | Compliance software | |
| RVR Systems Compliance | Compliance software | |
| SAP BEx Report Designer | Data base reporting software | |
| Scheduling software | Calendar and scheduling software | |
| StataCorp Stata | Analytical or scientific software | |
| Sword Achiever Compliance Portal Dashboard | Compliance software | |
| Tax accounting software | Tax preparation software | |
| Tax software | Accounting software | |
| The Garland Group RiskKey | Compliance software | |
| Thomson Reuters Paisley Enterprise GRC | Compliance software | |
| Web browser software | Internet browser software | |