ICT Security Specialist or one of the five cyber codes? The choice decides which visas exist for you at all
Migratio Editorial · Last updated
TL;DR: Two cyber security applicants with near-identical jobs can face completely different visa options depending on which ANZSCO code fits. 262112 ICT Security Specialist is MLTSSL-only — it reaches the points-tested 189 plus state and regional routes, but has no employer-sponsored 482 or 186 access at all. The five newer codes, 262114 through 262118, are CSOL-only — they reach only 186 and 482, with no 189, no state nomination and no temporary graduate route. Getting this wrong is not a duty mismatch you fix later; it can close off a whole category of visa before the application is lodged. This page also covers the five-way operational cluster (network, systems and database administration) and the DAMA trap that catches four of this family's codes.
Most guidance to picking an ANZSCO code focuses on matching your duties to a description. In network and security ICT roles that only gets you halfway, because the codes that read as duty-siblings often sit on completely different visa lists. This page works through ACS's published material for the seventeen occupations it assesses across ICT security, network engineering, systems and database administration, and business and systems analysis. It reports what ACS's own pages say. It cannot tell you which code your history fits, or whether an assessment would succeed.
The split that matters most: two pages, two different visa worlds
ACS splits its cyber and security occupation descriptions across two separate pages, and the split is not cosmetic. 262112 ICT Security Specialist sits on ACS's general "IT occupations" page, carries the MLTSSL, and is the only security-titled code in the family reaching the points-tested 189 visa — alongside 190, 491, 494, 407 and 485. It does not reach 482 or 186 at all.
The five newer codes — 262114 Cyber Governance Risk and Compliance Specialist, 262115 Cyber Security Advice and Assessment Specialist, 262116 Cyber Security Analyst, 262117 Cyber Security Architect and 262118 Cyber Security Operations Coordinator — sit on a separate, dedicated "Cyber Security Occupations" page. Each carries only the CSOL, and each reaches only two visas: 186 and 482. No 189. No 190. No 491. No 494. No 407. No 485.
So an applicant with a genuine employer willing to sponsor them, and duties that fit any of the five newer codes, has exactly one route in: that employer nomination. An applicant with the same employer but duties fitting ICT Security Specialist instead has no sponsored route open to them at all — their case rests entirely on the points-tested and state pathways. Two people doing recognisably similar cyber security work can be looking at two entirely disjoint sets of available visas, and nothing about that is visible from the job title on a business card.
Why the split exists — and what it signals
This is not an arbitrary ACS quirk. Each of the five newer codes carries a footnote tying its description to a distinct Australian Bureau of Statistics occupation number in the 271xxx range — for example, "Occupation description derived from Occupation 271131 Cyber Governance Risk and Compliance Specialist | Australian Bureau of Statistics." That is a different numbering block entirely from the older, native 262xxx description still used for ICT Security Specialist.
Structurally, ACS is treating the cyber-governance and cyber-security codes as a newer, separately-defined occupation set layered on top of the original unit group, distinct in its own published material from the broader, older security code sitting beside it on a different page. The practical result is that these are not simply narrower specialisations of ICT Security Specialist with the same visa reach — they are a separate CSOL-only tier, added to the skilled list architecture after ICT Security Specialist's MLTSSL placement was already fixed.
What each of the five newer codes actually describes
ACS's lead definitions for the five newer codes point at genuinely different duties, even though "cyber security" describes all of them loosely:
262114 Cyber Governance Risk and Compliance Specialist leads governance, risk and compliance for cyber security — a policy and audit role.
262115 Cyber Security Advice and Assessment Specialist conducts risk and security control assessments, interprets security policies, reviews information system designs and advises on strategies to manage identified risks — an advisory and assurance role.
262116 Cyber Security Analyst analyses and assesses vulnerability in infrastructure, investigates tools and countermeasures, and recommends fixes — the hands-on technical analysis role, closest to what a "SOC analyst" title usually means.
262117 Cyber Security Architect designs a security system or major components of one, and may head a design team — design-and-build, with seniority implied by the team-leading language.
262118 Cyber Security Operations Coordinator leads the coordination and response to complex cyber security incidents and threat hunting investigations across teams — incident-response leadership.
A generalist "Cyber Security Specialist" or "Information Security Manager" job title, extremely common in the real labour market, could plausibly be described by any of these five, or by ICT Security Specialist, depending on which duty a reference letter emphasises. Only one of the six carries MLTSSL access.
Do not pick by seniority — pick by duty
"Architect" and "Governance Risk and Compliance" both sound senior, and it is tempting to nominate whichever code sounds closest to a promotion. ACS's lead definitions do not work that way. They tie each code to a specific duty shape — design-and-build from scratch for Architect, policy-and-audit for Governance Risk and Compliance, incident-response coordination for Operations Coordinator, vulnerability analysis for Analyst, advisory assessment for Advice and Assessment Specialist.
A senior security analyst whose actual duties are vulnerability analysis and incident triage, but whose job title reads "Architect" because that is what the employer called the role, risks a mismatch between the code nominated and the evidence a reference letter can actually support. The description that fits your day-to-day duties, not the one that sounds most senior, is the one worth checking first.
The operational cluster: network, systems and database roles blur into each other
Away from the security codes, this family also covers a five-way operational cluster that describes the same shape of role applied to different layers of a technology stack: 263111 Computer Network and Systems Engineer, 263112 Network Administrator, 263113 Network Analyst, 262113 Systems Administrator and 262111 Database Administrator.
Computer Network and Systems Engineer is the broadest and most senior — end-to-end responsibility for configuration management and operational readiness, and the only one of the three network codes on the MLTSSL. Network Administrator is operational and day-to-day: installing hardware and software, managing passwords, ensuring server and PC performance, with ACS noting it may also cover help desk support. Network Analyst is the planning and architecture end: researching network architecture and recommending design strategy, not hands-on operations.
Systems Administrator does the same shape of work as Network Administrator — plan, install, troubleshoot, maintain — but applied to an operating system and server estate rather than the network layer specifically. Database Administrator does the identical shape again, applied to a database management system instead. A job that genuinely covers servers, storage and the database running on top of them, a very common small-team reality, has no single code that cleanly covers all of it.
A real case: one career, three plausible codes, two unit groups
This is not a theoretical problem. One applicant on Whirlpool, already in Australia on a 457 visa, laid out the dilemma in his own words: "I'm on the fence as to whether I should go for Analyst Programmer or Computer Network and Systems Engineer." His most recent employment — the experience he would actually submit for assessment — was "for the last 2 years working on a 457 visa as a Systems Administrator."
That is one career history plausibly mapping to at least three different ANZSCO codes across two different unit groups, with no single obviously correct answer visible from the thread. It illustrates exactly why job title alone cannot settle a nomination in this cluster — a generalist "IT Administrator" or "Network Engineer" background can genuinely straddle three or four of these codes depending on which duty gets emphasised on the reference letter.
Systems Analyst versus ICT Business Analyst
A separate confusable pair sits earlier in the family: 261111 ICT Business Analyst and 261112 Systems Analyst. ACS's ICT Business Analyst definition centres on talking to users and formulating a requirements specification — the human, requirements-gathering side. Systems Analyst is defined as evaluating processes and methods used in EXISTING ICT systems and proposing modifications or new components to meet needs already expressed in a specification.
Structurally, 261112 reads as the step after 261111's output: one produces the requirements document, the other works from one. A career that straddles both — writing the requirements and then redesigning the system to meet them — has no single obviously correct code from the duty description alone. Both are on the MLTSSL and CSOL, so unlike the security cluster, the visa stakes of choosing between these two are lower; the risk here is a mismatched assessment, not a closed visa category.
The DAMA trap: four codes in this family are missing from South Australia's list
South Australia's combined DAMA occupation list gives a genuine concession for many ICT codes — for 261111 ICT Business Analyst, for instance, the list states "only one (1) year of relevant work experience is required for the TSS visa program," against the standard General Skills matrix's two-to-six-year range.
Thirteen of this family's seventeen codes appear on that list under an "ICT Professionals" heading: both analyst codes, Database Administrator, Systems Administrator, all five newer cyber codes, and all four support-and-test engineer codes.
Four codes do NOT appear anywhere on the list, verified by exhaustive search rather than a sampling check: 263111 Computer Network and Systems Engineer, 263112 Network Administrator, 263113 Network Analyst, and 262112 ICT Security Specialist — the one MLTSSL security code in the family. An applicant reasoning "other ICT codes get a DAMA concession, so mine probably does too" would be wrong for exactly these four, and the gap is not obvious from the list's general ICT Professionals heading, which only appears next to the codes it actually lists.
Where sponsorship actually comes from
The industry labour agreement lanes — dairy, horticulture, aged care, hospitality, fishing, on-hire, meat, pork — do not cover ICT occupations at all. Sponsorship for this family runs through standard direct-employer nomination under whichever visa list a given code actually reaches, not through a regional or industry labour-agreement channel.
That makes the visa-list split in this page's opening section the practical question for anyone counting on employer sponsorship specifically. A code that does not reach 482 or 186 cannot be sponsored under this family's structure at all, regardless of how willing an employer is.
Evidence beyond a degree: vendor certifications
ACS accepts named vendor certifications as supporting evidence specifically for the cyber security and DevOps codes — CompTIA (Security+, CySA+, PenTest+, SecurityX), ISACA (CRISC, CISM, CISA, CGEIT) and ISC2, including the CISSP and CSSLP. This sits within a standard application as supporting evidence, not as a separate faster pathway or a substitute for the qualification or work-experience requirement.
ACS's instructions ask each certification to clearly display the issuing authority, a validation or certificate number, the applicant's full name and the date of issuance, with proof of renewal where the certificate carries a validity period. Treating a certification as a shortcut around the standard evidence base, rather than an addition to it, is a way this family's evidence requirements get misread.
Frequently asked questions
Can ICT Security Specialist be sponsored on a 482 visa?
No. 262112 ICT Security Specialist carries the MLTSSL and reaches the points-tested 189 visa plus 190, 491, 494, 407 and 485 — but it does not appear on the CSOL, and the 482 and 186 employer-sponsored visas both require CSOL or MLTSSL-with-482-eligibility. This code has no employer-sponsored route at all under ACS's current occupation lists.
Which cyber security ANZSCO codes reach the 189 visa?
None of the five newer codes — 262114 Cyber Governance Risk and Compliance Specialist, 262115 Cyber Security Advice and Assessment Specialist, 262116 Cyber Security Analyst, 262117 Cyber Security Architect, 262118 Cyber Security Operations Coordinator — reach 189. They are CSOL-only and reach only 186 and 482. The one code in the security cluster that reaches 189 is 262112 ICT Security Specialist, which in turn does not reach 186 or 482.
What is the difference between Network Administrator, Network Analyst and Computer Network and Systems Engineer?
ACS defines Network Administrator as day-to-day operational work — installing, maintaining, managing passwords and inventory, and may include help desk support. Network Analyst is planning and architecture — researching network design and recommending strategy, not hands-on operations. Computer Network and Systems Engineer is the broadest, with end-to-end responsibility for configuration management and operational readiness, and is the only one of the three carrying MLTSSL access.
What separates Systems Administrator from Database Administrator?
Structurally, nothing about the shape of the role — both are defined as planning, developing, installing, maintaining and supporting an IT asset for integrity, security, backup and performance. The difference is the layer: Systems Administrator covers the operating system and server estate, Database Administrator covers the database management system running on it. A job covering both has no single ACS code that cleanly describes it.
Are Computer Network and Systems Engineer, Network Administrator and Network Analyst on South Australia's DAMA list?
No. Checked directly against South Australia's combined DAMA occupation list, none of the three network codes appear anywhere on it, despite the list covering thirteen of the seventeen codes in this wider family under an ICT Professionals heading. ICT Security Specialist is also absent. These are the four exceptions in an otherwise well-covered family.
Can I nominate more than one ANZSCO code in one ACS application?
Yes. ACS's portal lets applicants choose up to three occupations and ANZSCO codes to be assessed against in one application, and issues a separate outcome letter for each code successfully assessed. This dossier could not confirm from ACS's published fee pages whether a second or third nomination carries an extra fee, so check that directly with ACS.
Does a CISSP or CompTIA certification replace the ACS work-experience requirement for cyber security codes?
No. ACS accepts named vendor certifications — including CISSP, CSSLP, and certifications from CompTIA and ISACA — as supporting evidence specifically for cyber security and DevOps codes, but this sits within the standard General Skills or RPL evidence base. It supplements the qualification and employment evidence; it does not replace it.
Is Cyber Security Architect a more senior code than Cyber Security Analyst?
ACS's definitions tie each cyber code to a duty shape, not a seniority tier as such. Architect is design-and-build focused and may involve heading a design team; Analyst is hands-on vulnerability analysis and countermeasure recommendation. A senior analyst whose real duties are still vulnerability analysis and incident triage should be evidenced against the Analyst definition, not nominated as Architect purely because the job title sounds more senior.
Compare MARA-registered migration agents — free
Related: Software Engineer, Developer Programmer or Analyst Programmer? What ACS actually uses to tell them apart · Your occupation isn't on any skilled occupation list. What actually remains? · ACS Skills Assessment for IT Migration: 2026 Guide · Skills Assessment for Australian Migration: Complete 2026 Guide