Presenting Cybersecurity Experience for ACS: Files and References
What the ACS assesses in a cybersecurity application
Cybersecurity is a fast-growing field, but the ACS assesses applications by the same principle as other ICT occupations: the actual content of the work must match the ANZSCO definition of the code you lodge under. The ACS does not assess job titles, does not assess certifications, and does not assess project scale — it assesses qualifications and work experience against ANZSCO only.
This means that no matter whether you hold a CISSP or a CEH, or work at a large company, if the application does not describe the work content correctly in ANZSCO terms, it still risks being assessed as not suitable.
For the full migration pathway and visa requirements for this occupation, see the cybersecurity specialist migration guide.
The types of cybersecurity work the ACS recognises
The ACS assesses cybersecurity work by the scope of the ANZSCO code lodged. The types of security work usually recognised include:
Defensive / Blue Team:
- Operating a SOC (Security Operations Centre): monitoring logs, analysing security events, incident response
- Deploying and configuring SIEM, IDS/IPS, endpoint protection
- Vulnerability assessment and patch management
- Building and maintaining firewall rulesets, network segmentation
Security testing (Offensive / Red Team):
- Penetration testing: authorised intrusion testing (web app, network, infrastructure)
- Threat modelling, threat hunting in a controlled environment
Security architecture and policy:
- Designing security architecture for systems, networks, cloud
- Building information security policy
- Risk assessment, compliance management: ISO 27001, ASD Essential Eight, NIST
Cloud security:
- Configuring security on AWS, Azure, GCP: IAM, security groups, encryption at rest/transit
- Performing cloud security assessments, CIS benchmarks
Which work does the ACS often assess as insufficient?
Some security-related work may not count fully towards ICT Security Specialist:
- IT helpdesk or sysadmin with minor security duties on the side: If most of the time is system administration and only a small part is security tasks, the ACS will assess the whole role rather than just the security part.
- Pure GRC analyst with no technical component: Work that is only checking compliance checklists and writing GRC reports, with no technical element of designing or operating security systems, is usually counted little towards the ICT Security Specialist code.
- Security trainer / educator: Delivering security training does not count as security work experience.
How to write an employment reference letter for cybersecurity
The employment reference letter is the most important document in an ACS application. A strong letter for cybersecurity needs to:
State clearly the type of security work you did: Do not just write “performed cybersecurity duties” — list specifics: SIEM monitoring, incident analysis, penetration testing, security architecture design, and so on.
State the proportion of time spent on security: If you worked as both sysadmin and security, the letter should state an estimate of how much of your time was spent on security work. The ACS assesses the whole role, not just one part.
Describe scope and independence: State clearly whether you worked independently or under supervision, the scale of the system/organisation you protected, and your responsibilities within the team.
Use specific technical language: Mention the technologies, frameworks and standards you used. ACS assessors understand technical terminology — avoid vague language.
The letter must include full employer details: Name, position, email, and phone number of the person signing the letter — and it must be someone who can verify your work.
Security certifications: do they help?
Professional certifications such as CISSP, CISM, CEH, CompTIA Security+, and OSCP are not counted by the ACS as work experience — but they can:
- Strengthen the credibility of the application (showing you have invested in your expertise)
- Provide support where the qualification or experience is “borderline”
A certification cannot replace genuine work experience. The ACS requires a sufficient number of years of formal work experience in an ICT role.
Common errors in cybersecurity applications
Descriptions that are too generic: “Responsible for company system security” is not enough. The ACS needs to know what specifically you did, with what technology, and in what kind of environment.
Not distinguishing a security role from a general IT role: Many applications describe a general IT role (setup, maintain, support) then add a single line “also responsible for security.” The ACS will assess the whole role — if most of it is sysadmin work, the ACS may assess it under the sysadmin code, not security.
Confusing ICT Security with information security at the management level: A CISO or Information Security Manager is usually not assessed as an ICT Security Specialist — that is a management role, not a technical one. Check the ANZSCO code that matches your level.
Not providing enough evidence for cloud security: Cloud security is a newer field and the ACS may need clearer evidence (cloud platform name, specific services) compared with traditional on-premise security.
Next steps
After building your cybersecurity application, read on for the realistic ACS application requirements and process, the common mistakes when lodging with the ACS, and how to choose the right ANZSCO code for an IT occupation.