Every career profile on this site is aligned to the NIST NICE Framework. This page shows exactly which NICE element each profile maps to, and why. It is published in full so that teachers, students and anyone else can check the mapping for themselves.
↓ Download crosswalk (XLSX) ↓ Download crosswalk (CSV)
Each profile is written around a job title as students and teachers actually encounter it. Each profile is then aligned to the single NICE element that best describes the work the page covers. Element identifiers and names are taken from the official NICE Framework Components spreadsheet published by NIST.
NICE Work Roles are not job titles. A Work Role is a grouping of cybersecurity work. One real job can span several Work Roles, and several job titles can sit under one Work Role. Where a profile could reasonably map to more than one element, the primary mapping is shown and the alternative is recorded in the notes.
Where nothing fits, nothing is claimed. Some cybersecurity work has no current NICE Work Role. Two Work Role Categories, Cyberspace Effects and Cyberspace Intelligence, were removed at v2.0.0; NIST notes that work is now covered by the DoD Cyber Workforce Framework. Profiles affected by this say so rather than being given a code that does not fit.
This is an independent mapping. It has not been reviewed, validated or endorsed by NIST or the NICE Program Office. The NICE Framework is a public resource; alignment to it is a claim about this site's content, not a claim of any relationship with NIST.
| Career profile | NICE ID | NICE element name | Type | Why this mapping |
|---|---|---|---|---|
| PD · PROTECTION AND DEFENSE | ||||
| Cybersecurity Analyst | PD-WRL-001 | Defensive Cybersecurity | Work Role | Page covers monitoring networks, investigating threats and reducing risk using defensive tooling. Shares this Work Role with SOC Analyst. Job title, not a NICE role name. |
| Detection Engineer | PD-WRL-001 | Defensive Cybersecurity | Work Role | Page covers designing, testing and improving the detection logic that turns telemetry into defensive alerts. Shares PD-WRL-001 with Cybersecurity Analyst, SOC Analyst and Threat Hunter. Disclosed on the page. |
| SOC Analyst | PD-WRL-001 | Defensive Cybersecurity | Work Role | Page covers alert triage, investigating suspicious activity and analysing data from defensive tools to reduce risk. Shares this Work Role with Cybersecurity Analyst. |
| Threat Hunter | PD-WRL-001 | Defensive Cybersecurity | Work Role | Page covers proactively searching defensive telemetry for attacker presence where no high-confidence alert has fired. Shares PD-WRL-001 with Cybersecurity Analyst, SOC Analyst and Detection Engineer. Disclosed on the page. |
| Incident Forensics Analyst | PD-WRL-002 | Digital Forensics | Work Role | Page covers examining digital evidence from security incidents to establish what happened and support mitigation. Shares PD-WRL-002 with Malware Analyst. Note the separate Digital Forensics profile maps to IN-WRL-002 for its investigative/law-enforcement emphasis. |
| Malware Analyst | PD-WRL-002 | Digital Forensics | Work Role | Page covers examining malicious files and related evidence to establish behaviour, impact and defensive indicators. Primary mapping. Some malware-analysis posts also perform work aligned to PD-WRL-006 Threat Analysis; disclosed on the page. Shares PD-WRL-002 with Incident Forensics Analyst. |
| Incident Responder | PD-WRL-003 | Incident Response | Work Role | Page covers containment, analysis and recovery following a cybersecurity incident. |
| Cybersecurity Infrastructure Specialist | PD-WRL-004 | Infrastructure Support | Work Role | Page covers deploying, maintaining and administering the hardware and software used to protect systems and networks. |
| Insider Threat Analyst | PD-WRL-005 | Insider Threat Analysis | Work Role | Page covers identifying and assessing misuse of trusted access and producing findings that can support investigation. |
| Threat/Warning Analyst | PD-WRL-006 | Threat Analysis | Work Role | Page covers tracking adversary activity and producing actionable warning for defenders. |
| Penetration Tester | PD-WRL-007 | Vulnerability Analysis | Work Role | Page covers identifying and validating exploitable weaknesses and reporting impact. Job title spanning multiple Work Roles. DD-WRL-007 Systems Testing and Evaluation is also relevant. Shares PD-WRL-007 with Vulnerability Assessment Analyst. |
| Vulnerability Assessment Analyst | PD-WRL-007 | Vulnerability Analysis | Work Role | Page covers finding, validating and prioritising security weaknesses for remediation. Shares this Work Role with Penetration Tester. |
| IN · INVESTIGATION | ||||
| Cybercrime Investigator | IN-WRL-001 | Cybercrime Investigation | Work Role | Page covers investigating intrusions and technology-enabled crime using documented investigative process alongside legal considerations. Work Role comprehensively revised at v2.1.0 (December 2025). |
| Digital Forensics | IN-WRL-002 | Digital Evidence Analysis | Work Role | Page emphasises evidence collection and preservation, chain of custody, and support to law-enforcement investigation. Mapped to IN-WRL-002 for its investigative and law-enforcement emphasis. PD-WRL-002 is separately named 'Digital Forensics' and is covered by the Incident Forensics Analyst and Malware Analyst profiles. Naming overlap is disclosed on all three pages. |
| DD · DESIGN AND DEVELOPMENT | ||||
| Security Architect | DD-WRL-001 | Cybersecurity Architecture | Work Role | Page covers designing secure systems and standards ahead of build. |
| Enterprise Security Architect | DD-WRL-002 | Enterprise Architecture | Work Role | Page covers technology rules, target architectures and cross-organisation patterns supporting business and mission needs. Distinct from Security Architect (DD-WRL-001 Cybersecurity Architecture). |
| Secure Software Developer | DD-WRL-003 | Secure Software Development | Work Role | Page covers creating and modifying applications and utilities with security applied throughout development. Distinct from Secure Software Assessor (DD-WRL-005). |
| Security Engineer | DD-WRL-004 | Secure Systems Development | Work Role | Page covers designing and building security systems and controls. DD-WRL-001 Cybersecurity Architecture also applies to architecture-heavy jobs. |
| Application Security Engineer | DD-WRL-005 | Software Security Assessment | Work Role | Page covers reducing application security weaknesses through design review, code review, testing and developer guidance. Shares DD-WRL-005 with Secure Software Assessor. Disclosed on the page. |
| Secure Software Assessor | DD-WRL-005 | Software Security Assessment | Work Role | Page covers reviewing code and applications for security flaws. |
| Security Requirements Analyst | DD-WRL-006 | Systems Requirements Planning | Work Role | Page covers translating customer needs, risks and policy into clear technical security requirements. |
| Security Test Engineer | DD-WRL-007 | Systems Testing and Evaluation | Work Role | Page covers planning and running tests to verify systems against defined security specifications. |
| Security Researcher | DD-WRL-008 | Technology Research and Development | Work Role | Page covers investigating technologies and software to discover weaknesses and develop new capability. |
| OT Cybersecurity Engineer | DD-WRL-009 | Operational Technology (OT) Cybersecurity Engineering | Work Role | Page covers engineering industrial systems against intentional and accidental cyber events alongside safety and reliability. Work Role introduced in v2.0.0 (March 2025). |
| IO · IMPLEMENTATION AND OPERATION | ||||
| Cybersecurity Data Analyst | IO-WRL-001 | Data Analysis | Work Role | Page covers analysing data from multiple sources and building workflows or models for complex security datasets. |
| Database Security Administrator | IO-WRL-002 | Database Administration | Work Role | Page covers administering database systems for secure storage, querying, protection, recovery and use of data. |
| Cybersecurity Knowledge Manager | IO-WRL-003 | Knowledge Management | Work Role | Page covers the processes and tools used to identify, document and access an organisation's intellectual capital. |
| Network Operations Specialist | IO-WRL-004 | Network Operations | Work Role | Page covers planning, implementing and operating networks across on-premises and cloud environments. |
| Systems Administrator | IO-WRL-005 | Systems Administration | Work Role | Page covers installation, configuration, updates, account management, backup and recovery, and implementing security controls. |
| Systems Security Analyst | IO-WRL-006 | Systems Security Analysis | Work Role | Page covers the security of systems as they are integrated, tested, operated and maintained. |
| Technical Support Specialist | IO-WRL-007 | Technical Support | Work Role | Page covers supporting users with client hardware and software under approved organisational process. Presented as an entry point into the wider cybersecurity workforce. |
| OG · OVERSIGHT AND GOVERNANCE | ||||
| COMSEC Manager | OG-WRL-001 | Communications Security (COMSEC) Management | Work Role | Page covers managing an organisation's Communications Security resources. |
| GRC Analyst | OG-WRL-002 | Cybersecurity Policy and Planning | Work Role | Page covers translating cybersecurity requirements into policy, plans, risk decisions and evidence. Job title; NICE role name differs. |
| Cybersecurity Workforce Manager | OG-WRL-003 | Cybersecurity Workforce Management | Work Role | Page covers planning how an organisation recruits, develops, assesses and retains the cybersecurity workforce. |
| Cybersecurity Curriculum Developer | OG-WRL-004 | Cybersecurity Curriculum Development | Work Role | Page covers designing and evaluating cybersecurity learning content, methods and activities against instructional needs. |
| Cybersecurity Instructor | OG-WRL-005 | Cybersecurity Instruction | Work Role | Page covers developing and delivering cybersecurity awareness, training or education. Shares OG-WRL-005 with Security Awareness Specialist. Disclosed on the page. |
| Security Awareness Specialist | OG-WRL-005 | Cybersecurity Instruction | Work Role | Page covers creating and delivering practical cybersecurity awareness and training that helps people make safer decisions. Shares OG-WRL-005 with Cybersecurity Instructor. Awareness work and formal instruction overlap but are not identical; OG-WRL-005 is the closest current element. |
| Cybersecurity Legal Advisor | OG-WRL-006 | Cybersecurity Legal Advice | Work Role | Page covers advising on cybersecurity legal matters and monitoring relevant legislation and regulation. |
| Chief Information Security Officer (CISO) | OG-WRL-007 | Executive Cybersecurity Leadership | Work Role | Page covers setting cybersecurity direction, priorities and risk decisions at organisational level. |
| Privacy Analyst | OG-WRL-008 | Privacy Compliance | Work Role | Page covers operating a privacy programme across governance, policy and compliance. |
| Product Support Security Manager | OG-WRL-009 | Product Support Management | Work Role | Page covers planning and managing support strategies that keep systems and components operational through their lifecycle. |
| Cybersecurity Program Manager | OG-WRL-010 | Program Management | Work Role | Page covers coordinating a defined group of related cybersecurity work and accountability for its overall success. Distinct from Cybersecurity Project Manager (OG-WRL-011 Secure Project Management). |
| Cybersecurity Project Manager | OG-WRL-011 | Secure Project Management | Work Role | Page covers running technology projects with cybersecurity built into delivery. |
| Security Control Assessor | OG-WRL-012 | Security Control Assessment | Work Role | Page covers independent evaluation of management, operational and technical controls. |
| Security Authorization Specialist | OG-WRL-013 | Systems Authorization | Work Role | Page covers supporting decisions about whether systems operate at an acceptable level of risk. Distinct from Security Control Assessor (OG-WRL-012 Security Control Assessment). |
| Cybersecurity Manager | OG-WRL-014 | Systems Security Management | Work Role | Page covers coordinating people, priorities, resources and risk so a system or enclave is managed securely. Distinct from Cybersecurity Project Manager (OG-WRL-011). |
| Cybersecurity Portfolio Manager | OG-WRL-015 | Technology Portfolio Management | Work Role | Page covers managing a portfolio of technology and security investments against mission and enterprise priorities. |
| Security Auditor | OG-WRL-016 | Technology Program Auditing | Work Role | Page covers evaluating technology programmes against defined standards and requirements. |
| Cybersecurity Supply Chain Risk Analyst | OG-WRL-017 | Cybersecurity Supply Chain Risk Management | Work Role | Page covers identifying and managing cybersecurity risk from suppliers, products, services and dependencies. Work Role introduced in v2.2.0 (28 April 2026). |
| NF · (COMPETENCY AREA - NOT A WORK ROLE CATEGORY) | ||||
| Identity & Access Management Engineer | NF-COM-001 | Access Controls | Competency Area | Page covers designing and operating the controls that decide who can access systems, applications and data. Competency Area, not a Work Role. |
| AI Security Specialist | NF-COM-002 | Artificial Intelligence (AI) Security | Competency Area | Page covers securing the use and build of AI systems including data, models and integrations. Competency Area, not a Work Role. Updated at v2.1.0; Knowledge and Skill statements added at v2.2.0. |
| Cyber Asset Management Analyst | NF-COM-003 | Asset Management | Competency Area | Page covers maintaining an accurate picture of digital assets across identification, operation, upgrade and disposal. Competency Area, not a Work Role. |
| Cloud Security | NF-COM-004 | Cloud Security | Competency Area | Page covers securing cloud platforms and services. Competency Area, not a Work Role. Cloud security jobs span multiple Work Roles. |
| Communications Security Specialist | NF-COM-005 | Communications Security | Competency Area | Page covers securing transmissions, communications infrastructure, switching, control and related network systems. Competency Area, not a Work Role. Distinct from COMSEC Manager (OG-WRL-001). |
| Cryptography Engineer | NF-COM-006 | Cryptography | Competency Area | Page covers cryptographic methods and systems that keep data readable only to authorised people. Competency Area, not a Work Role. Updated at v2.2.0. |
| Cyber Resilience Engineer | NF-COM-007 | Cyber Resiliency | Competency Area | Page covers designing systems that anticipate, withstand, recover from and adapt to adverse cyber conditions. Competency Area, not a Work Role. Updated at v2.0.0. |
| DevSecOps Engineer | NF-COM-008 | DevSecOps | Competency Area | Page covers integrating security into how software and infrastructure are built, tested, deployed and operated. Competency Area, not a Work Role. Updated at v2.2.0. |
| Operating System Security Engineer | NF-COM-009 | Operating Systems (OS) Security | Competency Area | Page covers securing and maintaining operating systems alongside administration, backup, troubleshooting and recovery. Competency Area, not a Work Role. |
| — · NOT CURRENTLY MAPPED | ||||
| Cyber Operator | NO CURRENT NICE ELEMENT | — | No current NICE element | No current NICE Framework Work Role covers this work. Legacy cyber operations roles were removed at v2.0.0 when the Cyberspace Effects and Cyberspace Intelligence categories were retired; NIST notes these are now in the DoD Cyber Workforce Framework (DCWF). Page states no current NICE role rather than asserting one. |
NIST updates the NICE Framework Components periodically. When a new version is released this crosswalk is reviewed against it and the version history in the downloadable spreadsheet is updated. If you spot a mapping you think is wrong, please get in touch — corrections are welcome and will be credited.
NICE Framework: Current Versions (NIST)
NICE releases NICE Framework Components v2.2.0 (NIST, 28 April 2026)
NIST SP 800-181 Rev. 1 — Workforce Framework for Cybersecurity