Skip to content
Cyber Recrut

Assessing cybersecurity skills beyond the CV

How to assess a candidate's cybersecurity skills: hands-on labs, a fair exercise, a scoring rubric, reviewing results and the legal basics in France.

Published on 7 min read

In cybersecurity, a CV tells you what someone has studied, rarely what they can do on your systems today. Certifications, job titles and keywords give a first impression, but they are no substitute for evidence. This article shows you how to build an assessment based on real capability, fair to candidates and useful for your decisions.

Why the CV misleads

The CV is not useless: it lets you check a career path and its context. But in security, it misleads in both directions.

  • Keywords inflate profiles. A candidate can list a SIEM, an EDR and a dozen frameworks after a single course. Conversely, an excellent practitioner may describe their work in three plain lines.
  • Certifications measure an exam, not a job. They prove effort and a knowledge base, which has value. They do not tell you whether the person can investigate a compromise under pressure. Our article on certifications in hiring looks at what they are really worth.
  • Job titles are not standardised. "Security analyst" can mean compliance management just as much as incident response.
  • The best atypical profiles get filtered out. Career changers and self-taught people, often very strong in practice, vanish at the first keyword screen. See our guide to hiring career changers.

Assess capability, not knowledge

The shift is simple: instead of asking "what do you know?", ask "what can you do?". To get there, start from the role.

  1. List the real situations the person will face in their first months: qualifying an alert, auditing a web application, reviewing a cloud access policy, writing a report for the executive committee.
  2. Pick two or three key capabilities among them. Not ten. These are the ones that separate a good hire from an average one.
  3. Define what a good result looks like for each, before you see a single candidate.

This step often forces you to clarify the role itself. If you cannot describe what a good result means, the job description needs rework before the assessment.

Hands-on labs, quizzes or take-home exercises

Assessment formats are not equal. Each has its place, as long as you know what it measures.

FormatWhat it measuresLimitsRecommended use
Quiz or multiple choiceBasic knowledge, vocabularyCan be memorised, shows no reasoningLight first filter, never on its own
Supervised hands-on labAbility to act in a realistic environmentRequires a prepared environmentCore of the technical assessment
Take-home exerciseAutonomy, quality of deliverableRisk of excessive length, hard to compareShort, scoped, with an indicative time
Spoken scenarioReasoning, prioritisation, communicationFavours confident speakersAs a complement, during the interview

In most technical hires, a short, realistic lab yields more information than all the other formats combined. That is the choice Cyber Recrut makes: our shortlisted candidates solve hands-on labs built around the role, on their own machine.

Designing a fair exercise

A good exercise resembles the job, fits in a reasonable time and gives the candidate a real chance to show what they can do.

  • Realistic but fictional: use synthetic or anonymised data, a test environment, a deliberately vulnerable application. Never your production systems or your real alerts.
  • Stated and respected duration: say clearly how long it should take. An exercise that eats a whole weekend penalises candidates with family commitments or a current job.
  • Clear instructions: objective, expected deliverable, allowed resources (documentation, search engine). In security, looking things up is part of the job.
  • Several possible paths: reward reasoning, not a single correct answer.
  • The same exercise for everyone: otherwise comparison is meaningless.
  • Tested internally: have a team member take it before sending it out. If it takes twice the planned time, cut it down.

For a SOC role, for example, a log investigation around a compromised host works well. Our guide to hiring a SOC analyst describes a full example.

Building a scoring rubric

Without a rubric, two assessors judge two different things. A rubric makes the decision explainable and reduces bias. Here is a template to adapt.

Criterion1: insufficient2: adequate3: solid4: outstanding
ApproachRandom actions, no methodPartial methodStructured, coherent approachStructured, with hypotheses stated and ruled out
Technical resultObjective not metObjective partly metObjective metObjective met with relevant extra findings
PrioritisationLost in detailsPrioritises hesitantlyHandles what matters firstJustifies priorities by risk
Written deliverableConfused or missingUnderstandable but incompleteClear and actionableClear, concise, suited to its reader
Limits and honestyAsserts without evidenceAcknowledges some limitsSeparates facts from hypothesesIdentifies what should be checked next

Weight the criteria by role: prioritisation counts more for a SOC analyst, the written deliverable more for an auditor or pentester. Decide on the expected threshold before marking the first exercise.

Reviewing the results

The assessment does not end with the score.

  • Mark in pairs where possible, ideally with a security practitioner. Compare scores before discussing them.
  • Mark blind if you can: hide the name and background while scoring the deliverable.
  • Debrief with the candidate in the interview. Asking them to comment on their work shows how they reason and how they take feedback. Our article on preparing for a technical interview covers this moment from the candidate's side.
  • Document the decision against the rubric. You can then explain it to the candidate and your team.

Caring for the candidate experience

Good security profiles are in high demand. A poorly handled assessment loses candidates, and word travels fast in the community.

  • Announce the exercise in the first conversation, with its duration and purpose.
  • Let the candidate choose the slot, within a reasonable window.
  • Reply quickly after submission, even when the answer is no.
  • Give concrete feedback: two or three points drawn from the rubric are enough.
  • Do not stack tests. One well-designed exercise beats three successive ones.

In France, the Labour Code governs recruitment methods: they must be relevant to the role, and candidates must be informed of them beforehand. The CNIL also reminds employers that data collected during recruitment must be limited to what is necessary and kept for a defined period. The texts are available on legifrance.gouv.fr and the guidance on cnil.fr.

In practice:

  • No unpaid real work. An exercise must never produce a deliverable you will use (an audit of your application, writing your procedures, handling your alerts). Beyond the legal question, it sends a very negative signal to the candidate.
  • A direct link to the role. Only assess what the role truly requires.
  • The same conditions for everyone, with adjustments available for candidates with disabilities.
  • Clear information on the method, how results are used and how long they are kept.

In short

Assessing beyond the CV means starting from the real situations of the role, choosing a format that shows action rather than memory, designing a short and fair exercise, and scoring with a rubric defined in advance. That rigour protects your decisions as much as the candidate experience.

Want to hire on evidence rather than keywords? Tell us about your hiring need. A recruiter and a security practitioner run every search, and every shortlisted candidate proves their skills on hands-on labs matched to the role. See our process.

Related articles