ResumeWorld
Screening guide
Security is several professions sharing one word. A SOC analyst triaging alerts, a penetration tester, an application security engineer and a governance, risk and compliance lead have little day-to-day work in common, yet their resumes use the same keywords and often the same certifications. Screening cybersecurity candidates starts with deciding which of those jobs you are hiring for, then reading for evidence of work in it — with the added complication that the best security work is frequently the least disclosable.
Signal
Security operations, offensive testing, application security, cloud security and GRC are distinct careers. Strength in one is weak evidence for another, however similar the job titles look.
Security+ is a broad foundation. OSCP is a hands-on practical exam, so it evidences offensive skill directly. CISSP carries an experience requirement and tests breadth and management judgement rather than hands-on depth. None substitutes for the others.
Strong candidates describe impact without exposing the target: the class of issue found, the control built, the detection coverage added. Specific about the work, restrained about the weakness.
For defensive roles, look for what the candidate built or tuned — detection rules, playbooks, response procedures. Alert counts describe the workload, not the analyst.
Security judgement rests on knowing how systems actually work. Prior networking, systems administration or development experience is often the most useful signal on the page, and career changers from those fields are easy to under-rank.
Noise
None of these is disqualifying on its own. Each is a reason to ask a question rather than assume an answer.
Scanners, SIEMs and exploitation frameworks listed with no environment, scope or outcome attached
Identifiable detail about an employer's or client's weaknesses — a judgement problem, however skilled the work
Offensive work described with no mention of scope, authorisation or engagement type
A stack of entry-level certifications presented as if it were senior experience
"Responsible for security" in a role where it was plainly a side duty, with no control or incident described
Rubric
Write the criteria down before you look at anyone. An undocumented standard drifts, and it cannot be audited afterwards.
Hands-on experience in the security discipline the role actually sits in.
Depth in the networks, systems, cloud platforms or code the role defends or tests.
Controls implemented, detections shipped, findings remediated — described without over-disclosure.
Required ones checked as a gate; the rest weighted by what their exam actually tests.
Familiarity with the standards you are assessed against, such as ISO 27001, SOC 2 or PCI DSS — weighted heavily for GRC roles and lightly elsewhere.
Next step
Ask the same ones of every candidate. Comparability is the whole point.
FAQ
Put it into practice
Score every application against the role you are actually hiring for, then get a ranked shortlist with the reasoning attached.
ExploreTurn PDFs, DOCX files and multi-column designs into structured candidate data without scrambling the reading order.
ExploreGet a competency signal with the application instead of discovering the gap in the second interview.
ExploreOther roles
Certification lists are long and cheap. Incident ownership is short and expensive.
Read the guideSeparating engineers who shipped something from engineers who were nearby when something shipped.
Read the guideEveryone lists SQL and Python. Almost nobody describes a decision their analysis changed.
Read the guideGo deeper
Most screening criteria are unfalsifiable. How to turn a job description into five to eight requirements you could actually verify from a document.
Read the guideKeyword matching is largely gone from modern screening. What to do instead of stuffing, and the four places exact wording still counts.
Read the guideStructured interviews predict job performance far better than unstructured ones. What structure actually means, and how to implement it well.
Read the guideDefine the criteria once, screen every application against them, and get a ranked shortlist with the reasoning attached.