July 21, 2026
I asked 5 security leaders what they actually look for in hires
Not the version that goes on the job posting. The version that actually decides who gets the offer.

By h@shtalk
3 min read
Job postings in security are remarkably consistent and remarkably unhelpful as a guide to what actually gets someone hired. So I asked a handful of people who actually make hiring decisions, across SOC leadership, detection engineering, and a CISO, what they're genuinely evaluating for, separate from the certification checklist on the posting. Patterns showed up fast.
"I can teach tools. I can't teach curiosity."
This came up, in some phrasing, from nearly everyone, and it wasn't a platitude, it was specific.
The thing they consistently said they couldn't train into a candidate after hire was the instinct to keep pulling on something that looks slightly off, even after a first explanation seems to account for it.
Tool proficiency, specific SIEM syntax, familiarity with a particular EDR platform, all trainable on the job, often within weeks. The habit of noticing a small inconsistency and caring enough to chase it down, even when it's inconvenient and might lead nowhere, showed up as the thing every leader said they were actually screening for in interviews, usually by asking candidates to walk through a real investigation they'd done and watching closely for where their curiosity did or didn't continue past the first plausible answer.
"Can they explain a wrong guess as clearly as a right one"
A detection engineering lead specifically mentioned watching for how candidates talked about investigations that didn't pan out, like alerts they chased that turned out to be nothing, theories that were wrong.
Candidates who only had polished stories about catching real threats, with no comfortable, detailed account of the times they were wrong and what that taught them, read as either inexperienced or not self-aware enough to be trusted with ambiguous situations later, because real work is mostly composed of dead ends, and someone who can't talk about those naturally hasn't actually done much of it.
"How do they talk about the tools they didn't build"
With AI-assisted workflows now common, several leaders specifically asked candidates how they'd validate something a model or automated tool produced, rather than just asking whether they could use the tool.
The answer they were listening for wasn't technical sophistication, it was whether the candidate had an instinctive habit of checking automated output rather than trusting it by default. One leader specifically said a candidate who described blindly trusting an AI-generated detection rule without validating it against real data was a harder no than a candidate who'd never used AI tooling at all, because the second candidate at least had the right instinct to build on.
"Do they ask me anything real"
Multiple leaders flagged the questions candidates asked at the end of the interview as more informative than most of the interview itself.
Specific, situational questions, about how the team handles a particular kind of escalation, what the actual incident review process looks like, how automation failures get caughtm read as someone who'd actually thought about the job. Generic questions about culture or growth opportunities, while not disqualifying on their own, did less to differentiate a candidate in a leader's actual memory of the conversation afterward.
What this means if you're job hunting in this field right now
The certifications and tool list on your resume get you the interview.
What actually decides the outcome, according to the people making that call, is closer to demonstrated curiosity, intellectual honesty about your own mistakes, healthy skepticism toward automated output, and evidence you've actually thought about the specific job rather than the job title in general.
None of that shows up on a resume bullet point, which means it has to show up in how you talk about your actual experience, including, deliberately, the parts that didn't go perfectly.
The thing every leader implicitly agreed on, without being asked directly
Every conversation, in different words, came back to the same underlying belief: the tools are going to keep changing, fast, and betting on a specific tool stack as the core of a hire's value is a worse long-term bet than hiring for the underlying judgment that adapts as the tools change underneath it.
That's not a new insight in hiring generally.
It's just become a sharper, more explicit filter specifically because the tools are changing faster than they used to, and the gap between "knows this tool" and "would figure out the next one" matters more now than it did five years ago.