Skip to content

Job Description — Template (ECSF-structured)

Fill from the ENISA ECSF Role Profiles document: pick the primary profile, copy/adapt its mission and tasks, add your specifics. Delete guidance quotes before publishing. Mapping guidance: docs/12-roles-and-competences.md.

[Job title] — [team/CDC name]

Field Value
Primary ECSF profile e.g., Cyber Incident Responder
Secondary ECSF elements e.g., Cyber Threat Intelligence Specialist
Level EQF [4–7] / e-CF competence level [e-2..e-4] · Junior / Medior / Senior
Reports to
Working pattern e.g., 8×5 + on-call rotation, or 24/7 shift plan [describe rotation honestly]
Location / language

Mission

Adapt the ECSF profile mission to your scope. Example (Incident Responder): monitors the organisation's cybersecurity state, analyses and mitigates the impact of incidents, identifies root causes, and restores systems per the Incident Response Plan.

[2–3 sentences]

Main tasks

Base on the ECSF profile's task list; keep 6–9, concrete to your CDC.

  • [Task 1 — e.g., triage and investigate alerts per the severity matrix (DE-3)]
  • [Task 2 — e.g., execute containment per playbooks and charter authority (RS-4)]
  • [Task 3 — e.g., contribute detections and tuning feedback to engineering (DE-2)]
  • [Task 4 — e.g., produce incident timelines and reports supporting statutory notification (RS-5)]
  • [ …]

Key deliverables

  • [e.g., incident records, investigation reports, tuned detections, post-incident inputs]

Skills & knowledge (from the ECSF profile)

Must have: [4–6 ECSF key skills — competence-based, not tool brands] Nice to have: [2–4, incl. platform-specific] Knowledge areas: [ECSF key knowledge items, e.g., incident handling standards/methodologies, operating systems and network security, legal framework for security and data protection]

Development path

This role develops toward [Tier 2 / Detection Engineer / Threat Hunter / …] along the paths in docs/12-roles-and-competences.md; training budget and a personal skills matrix review twice yearly.

What we offer / practicalities

[Salary range where required or wise · shift compensation · training days · retainer of external DFIR meaning no lone-wolf pressure · etc.]


Template from the Open CDC Framework (CC BY 4.0). Built on the ENISA European Cybersecurity Skills Framework (ECSF) — © ENISA, referenced with attribution.