THOMAS MORANSkills
Based on NICE Framework Components v2.2.0

Cybersecurity work-role mapping

Connecting my projects to recognized cybersecurity work.

This page maps specific project evidence to selected NICE work roles, tasks, and skills. The labels show what I can demonstrate today, what I have practiced, and what I am still building.

Demonstrated
1 role
Practiced
4 roles
Building
2 roles
Framework
NICE v2.2.0

Demonstrated

Several public artifacts directly show selected tasks and skills.

Practiced

A project shows part of the role, but not the full responsibility described by NICE.

Building

I am learning and practicing the area without claiming full work-role experience.

Mapped work roles

Project evidence, mapped without overclaiming.

DD-WRL-003Design and Development

Secure Software Development

Developing, creating, modifying, and maintaining applications, software, or specialized utility programs.

Demonstrated

Why it maps

My portfolio includes several working applications written in TypeScript and Python, automated tests, release packaging, documentation, and production deployments.

Evidence

Selected NICE tasks and skills

T0077

Develop secure code and error handling

T1074

Prepare secure code documentation

T1258

Perform integrated quality assurance testing

S0597

Skill in writing code in a currently supported programming language

DD-WRL-004Design and Development

Secure Systems Development

Securely designing, developing, and testing systems while evaluating security throughout the system life cycle.

Practiced

Why it maps

AccessGraph and the detection lab use rule-based findings, validated imports, documented security choices, and automated tests for core behavior and security boundaries.

Evidence

Selected NICE tasks and skills

T0122

Implement security designs for new or existing systems

T1079

Develop cybersecurity risk profiles

T1138

Create system testing and validation procedures and documentation

T1365

Document cybersecurity design and development activities

OG-WRL-012Oversight and Governance

Security Control Assessment

Assessing management, operational, and technical security controls to determine whether they work as intended.

Practiced

Why it maps

I completed a scoped self-assessment of this portfolio, documented findings, implemented response headers and AI endpoint safeguards, and recorded limits that still require independent review.

Evidence

Selected NICE tasks and skills

T0309

Assess the effectiveness of security controls

T1263

Perform security reviews

T1328

Verify implementation of software, network, and system cybersecurity postures

T1330

Recommend required actions to correct deviations from implemented security postures

IO-WRL-001Implementation and Operation

Data Analysis

Analyzing data from multiple sources to provide cybersecurity and privacy insight and building algorithms used for analysis.

Practiced

Why it maps

The detection lab normalizes endpoint events, applies single-event and threshold rules, and turns matching evidence into an investigation queue. The phishing detector and AccessGraph provide additional security-data analysis examples.

Evidence

Selected NICE tasks and skills

T1440

Assess the validity of source data

T1458

Develop data gathering processes

S0631

Skill in performing data preprocessing

S0854

Skill in performing data analysis

IO-WRL-006Implementation and Operation

Systems Security Analysis

Analyzing the integration, testing, operation, and maintenance of system security.

Practiced

Why it maps

The detection lab analyzes Windows security events and validates detection behavior. AccessGraph evaluates access controls, while the portfolio audit verifies deployed controls and records remediation.

Evidence

Selected NICE tasks and skills

T1255

Perform cybersecurity testing of developed applications and systems

T1287

Document systems security activities

T1548

Determine adequacy of access controls

S0667

Skill in assessing security controls

PD-WRL-003Protection and Defense

Incident Response

Investigating, analyzing, and responding to network cybersecurity incidents.

Building

Why it maps

The detection lab provides practice with alert review, log analysis, evidence collection, incident triage, ATT&CK mapping, remediation guidance, and findings reports. It does not claim production incident-response experience.

Evidence

Selected NICE tasks and skills

T1299

Determine causes of network alerts

T1250

Perform cyber defense incident triage

T1332

Produce incident findings reports

S0866

Skill in performing log file analysis

PD-WRL-007Protection and Defense

Vulnerability Analysis

Assessing systems and networks for unsafe configurations or policy gaps and evaluating protection against known vulnerabilities.

Building

Why it maps

I have practiced vulnerability assessment, Wireshark, network traffic analysis, and virtual-machine labs. My public portfolio audit shows a limited authorized review, but I am not presenting it as a full penetration test.

Evidence

Portfolio security auditCoursework and local labs not published

Selected NICE tasks and skills

T1118

Identify vulnerabilities

T1119

Recommend vulnerability remediation strategies

T1279

Prepare audit reports

T1619

Perform risk and vulnerability assessments

Source

Role IDs and statement text come from the official NICE Framework Components v2.2.0 JSON published by NIST on April 28, 2026.

Scope

This is a personal evidence map, not a certification, employer assessment, or claim that I perform every task associated with each work role.