Assessing cybersecurity skills beyond the CV
How to assess a candidate's cybersecurity skills: hands-on labs, a fair exercise, a scoring rubric, reviewing results and the legal basics in France.
In cybersecurity, a CV tells you what someone has studied, rarely what they can do on your systems today. Certifications, job titles and keywords give a first impression, but they are no substitute for evidence. This article shows you how to build an assessment based on real capability, fair to candidates and useful for your decisions.
Why the CV misleads
The CV is not useless: it lets you check a career path and its context. But in security, it misleads in both directions.
- Keywords inflate profiles. A candidate can list a SIEM, an EDR and a dozen frameworks after a single course. Conversely, an excellent practitioner may describe their work in three plain lines.
- Certifications measure an exam, not a job. They prove effort and a knowledge base, which has value. They do not tell you whether the person can investigate a compromise under pressure. Our article on certifications in hiring looks at what they are really worth.
- Job titles are not standardised. "Security analyst" can mean compliance management just as much as incident response.
- The best atypical profiles get filtered out. Career changers and self-taught people, often very strong in practice, vanish at the first keyword screen. See our guide to hiring career changers.
Assess capability, not knowledge
The shift is simple: instead of asking "what do you know?", ask "what can you do?". To get there, start from the role.
- List the real situations the person will face in their first months: qualifying an alert, auditing a web application, reviewing a cloud access policy, writing a report for the executive committee.
- Pick two or three key capabilities among them. Not ten. These are the ones that separate a good hire from an average one.
- Define what a good result looks like for each, before you see a single candidate.
This step often forces you to clarify the role itself. If you cannot describe what a good result means, the job description needs rework before the assessment.
Hands-on labs, quizzes or take-home exercises
Assessment formats are not equal. Each has its place, as long as you know what it measures.
| Format | What it measures | Limits | Recommended use |
|---|---|---|---|
| Quiz or multiple choice | Basic knowledge, vocabulary | Can be memorised, shows no reasoning | Light first filter, never on its own |
| Supervised hands-on lab | Ability to act in a realistic environment | Requires a prepared environment | Core of the technical assessment |
| Take-home exercise | Autonomy, quality of deliverable | Risk of excessive length, hard to compare | Short, scoped, with an indicative time |
| Spoken scenario | Reasoning, prioritisation, communication | Favours confident speakers | As a complement, during the interview |
In most technical hires, a short, realistic lab yields more information than all the other formats combined. That is the choice Cyber Recrut makes: our shortlisted candidates solve hands-on labs built around the role, on their own machine.
Designing a fair exercise
A good exercise resembles the job, fits in a reasonable time and gives the candidate a real chance to show what they can do.
- Realistic but fictional: use synthetic or anonymised data, a test environment, a deliberately vulnerable application. Never your production systems or your real alerts.
- Stated and respected duration: say clearly how long it should take. An exercise that eats a whole weekend penalises candidates with family commitments or a current job.
- Clear instructions: objective, expected deliverable, allowed resources (documentation, search engine). In security, looking things up is part of the job.
- Several possible paths: reward reasoning, not a single correct answer.
- The same exercise for everyone: otherwise comparison is meaningless.
- Tested internally: have a team member take it before sending it out. If it takes twice the planned time, cut it down.
For a SOC role, for example, a log investigation around a compromised host works well. Our guide to hiring a SOC analyst describes a full example.
Building a scoring rubric
Without a rubric, two assessors judge two different things. A rubric makes the decision explainable and reduces bias. Here is a template to adapt.
| Criterion | 1: insufficient | 2: adequate | 3: solid | 4: outstanding |
|---|---|---|---|---|
| Approach | Random actions, no method | Partial method | Structured, coherent approach | Structured, with hypotheses stated and ruled out |
| Technical result | Objective not met | Objective partly met | Objective met | Objective met with relevant extra findings |
| Prioritisation | Lost in details | Prioritises hesitantly | Handles what matters first | Justifies priorities by risk |
| Written deliverable | Confused or missing | Understandable but incomplete | Clear and actionable | Clear, concise, suited to its reader |
| Limits and honesty | Asserts without evidence | Acknowledges some limits | Separates facts from hypotheses | Identifies what should be checked next |
Weight the criteria by role: prioritisation counts more for a SOC analyst, the written deliverable more for an auditor or pentester. Decide on the expected threshold before marking the first exercise.
Reviewing the results
The assessment does not end with the score.
- Mark in pairs where possible, ideally with a security practitioner. Compare scores before discussing them.
- Mark blind if you can: hide the name and background while scoring the deliverable.
- Debrief with the candidate in the interview. Asking them to comment on their work shows how they reason and how they take feedback. Our article on preparing for a technical interview covers this moment from the candidate's side.
- Document the decision against the rubric. You can then explain it to the candidate and your team.
Caring for the candidate experience
Good security profiles are in high demand. A poorly handled assessment loses candidates, and word travels fast in the community.
- Announce the exercise in the first conversation, with its duration and purpose.
- Let the candidate choose the slot, within a reasonable window.
- Reply quickly after submission, even when the answer is no.
- Give concrete feedback: two or three points drawn from the rubric are enough.
- Do not stack tests. One well-designed exercise beats three successive ones.
Legal and fairness basics
In France, the Labour Code governs recruitment methods: they must be relevant to the role, and candidates must be informed of them beforehand. The CNIL also reminds employers that data collected during recruitment must be limited to what is necessary and kept for a defined period. The texts are available on legifrance.gouv.fr and the guidance on cnil.fr.
In practice:
- No unpaid real work. An exercise must never produce a deliverable you will use (an audit of your application, writing your procedures, handling your alerts). Beyond the legal question, it sends a very negative signal to the candidate.
- A direct link to the role. Only assess what the role truly requires.
- The same conditions for everyone, with adjustments available for candidates with disabilities.
- Clear information on the method, how results are used and how long they are kept.
In short
Assessing beyond the CV means starting from the real situations of the role, choosing a format that shows action rather than memory, designing a short and fair exercise, and scoring with a rubric defined in advance. That rigour protects your decisions as much as the candidate experience.
Want to hire on evidence rather than keywords? Tell us about your hiring need. A recruiter and a security practitioner run every search, and every shortlisted candidate proves their skills on hands-on labs matched to the role. See our process.