A cybersecurity candidate can have an impressive CV. Multiple certifications. A relevant degree. Several years of experience. A long list of technologies. But there is still an important question that a CV cannot fully answer:
What can the candidate actually do?
Cybersecurity is a practical discipline. SOC analysts investigate alerts. Incident responders investigate attacks. Penetration testers identify vulnerabilities. Security engineers design and implement controls.
These capabilities are difficult to evaluate through qualifications alone. That is why skills-based cybersecurity hiring is becoming increasingly important.
NIST’s NICE programme specifically promotes skills-based approaches to cybersecurity talent management and notes that employers often rely on proxies such as degrees, years of experience and certifications when evaluating capability. NIST recommends focusing more directly on the knowledge and skills required to perform the work.
Skills-based hiring evaluates candidates according to the capabilities required to perform a particular role rather than relying primarily on credentials or traditional indicators.
For cybersecurity recruitment, this can mean assessing whether a candidate can:
The objective is not to eliminate CVs, interviews or certifications. It is to add another layer: demonstrated capability.
Cybersecurity roles often require a combination of knowledge, technical ability and problem-solving. Consider a SOC analyst.
A candidate may understand SIEM terminology and hold relevant certifications. But when presented with a suspicious alert, can they:
Those are practical skills. A traditional interview can discuss them. A skills-based assessment can provide an opportunity for the candidate to demonstrate them.
Certifications can demonstrate commitment, structured learning and knowledge of particular domains. But a certification does not necessarily show how a candidate will perform in a specific organisational environment. Two candidates can hold similar credentials and have very different levels of practical capability.
This is why a stronger cybersecurity recruitment process can combine:
CV → Interview → Certification Review → Skills Assessment → Hiring Decision
rather than relying exclusively on:
CV → Interview → Hiring Decision
The assessment should be designed around the role. There is no reason to give every cybersecurity candidate the same test.
Security Operations
Candidates can be evaluated on alert analysis, investigation, triage and incident handling.
Threat Detection
Assess the ability to identify suspicious behaviour and determine an appropriate response.
Incident Response
Test how candidates approach an evolving security incident and prioritise actions.
Vulnerability Assessment
Evaluate vulnerability identification, risk understanding and security assessment capabilities.
Web Application Security
Assess understanding of common web application security issues and testing concepts.
Network Security
Evaluate network activity analysis and identification of potential threats.
Digital Forensics
Test analytical thinking around evidence, investigation and incident reconstruction.
General Cybersecurity
Evaluate foundational cybersecurity knowledge alongside practical problem-solving.
The exact assessment should depend on the job being filled.
A cybersecurity assessment should answer a simple question:
What does success look like in this role?
For example, an L1 SOC analyst may need strong fundamentals in:
An incident responder may require deeper capabilities in:
A penetration tester may need capabilities in:
The assessment should reflect the work.
NIST’s NICE Framework provides a common language for describing cybersecurity work through tasks, knowledge and skills, and NIST identifies candidate skill assessment as one of its practical employer uses.
One of the strongest arguments for practical assessment is that not every capable cybersecurity professional has the strongest conventional CV.
A candidate may have:
Yet they may demonstrate excellent technical ability. Conversely, a highly credentialed candidate may struggle with practical scenarios. Skills-based assessment gives both candidates an opportunity to demonstrate capability. This can help organisations broaden the talent pool while still maintaining objective assessment criteria. NIST notes that skills-based approaches can broaden the cybersecurity talent pipeline and reduce reliance on traditional proxies of capability.
Large cybersecurity recruitment campaigns can create a significant screening challenge. Imagine receiving hundreds of applications for several SOC positions.
Recruiters may need to review:
A structured assessment can introduce another data point.
The process can look like:
01 — Invite
Candidates receive an assessment aligned with the role.
02 — Assess
Candidates complete the defined cybersecurity skills assessment.
03 — Evaluate
Performance is measured against the assessment criteria.
04 — Rank
Candidates can be compared according to their assessment performance.
05 — Shortlist
Recruiters and hiring managers identify candidates for the next stage.
06 — Interview and Hire
Assessment results become one input into the broader hiring decision.
The assessment does not replace human judgement. It makes that judgement better informed.
When organisations are evaluating a large applicant pool, manually comparing candidates can become difficult.
A performance-based ranking can help hiring teams quickly identify stronger performers and determine who should progress. A platform such as the TISS Candidate Assessment Platform can create a leaderboard based on assessment performance.
This allows hiring teams to ask:
The result is a more structured approach to initial candidate screening.
A strong assessment should be:
Relevant
It should test capabilities that matter for the specific role.
Structured
Candidates should be assessed against defined criteria.
Objective
The evaluation methodology should be consistent across candidates.
Practical
Where appropriate, candidates should have opportunities to demonstrate applied skills.
Scalable
The assessment should work whether an organisation is evaluating ten candidates or hundreds.
Defensible
Hiring teams should be able to explain why candidates progressed or did not progress based on defined criteria.
Organisations can start by defining the capabilities required for each cybersecurity role.
For every position, identify:
The assessment can then be designed around those requirements.
This approach makes recruitment more closely aligned with the actual job.
The cybersecurity workforce is evolving quickly. Organisations need people who can adapt, investigate, analyse and solve problems, not simply people who can list technologies or certifications on a CV.
A skills-based approach provides a more direct way to evaluate that capability. The best candidate may still be the person with the strongest experience and qualifications. But organisations should have a way to determine whether that candidate can demonstrate the skills the role actually requires. Because ultimately: A CV tells you where someone has been. An assessment can show you what they can do.