CyberHire

AI has broken the CV signal in cyber security hiring

Applications are up and every CV now reads well. What AI actually changed about cyber hiring, what a CV still tells you, and what to use instead of reading harder.

Every CV you receive now reads well.

That is the problem.

AI did not make candidates better. It made CVs better. Those are different things, and the gap between them is where your hiring risk now lives. Whatever weak signal a CV used to carry has largely gone, because the things it measured are now free.

What actually changed

Two things, and they compound.

Volume went up. LinkedIn’s own figures, reported last year, put applications at around 11,000 per minute across the platform, a 45% rise year on year. Workday’s Global Workforce Report recorded a 31% increase in applications in the first half of 2024 against the same period in 2023. Applying to fifty roles used to take an evening. Now it takes a prompt.

And the floor rose. This is the part people miss. AI did not just add more applications, it lifted the quality of the worst ones. The badly formatted CV with three spelling mistakes and no tailoring has mostly disappeared. Everything arrives competent.

So the distribution compressed. The floor came up, the ceiling did not move, and everything is now bunched in the middle where you cannot tell anything apart.

312 applicants
Live · 4h since posting

Same phrases, hundreds of times

  • "results-driven" × 0
  • "passionate about cyber" × 0
  • "strategic thinker" × 0
  • "proven track record" × 0
  • "cyber enthusiast" × 0

What the inbox looks like on Monday morning. All formatted alike. All claiming everything. All impossible to rank.

Evidence, not claims Overall
MA

Maya Andersen

Verified in live technical assessment

94%
KQL investigation
94%
SIEM triage
89%
Incident response
82%
Cloud security
76%

Actually did the work

  • Correctly triaged 4/5 alert scenarios
  • Escalated the fifth appropriately
  • Clean integrity across the session
Recommended for interview

Illustrative, not a real cohort. The applicant count and the buzzword frequencies here are made up for the purpose of the picture. What is real is the pattern: the same structure, the same rhythm, the same three phrases, over and over.

The signal that died

Be honest about what a CV ever actually told you, because it was never capability.

A CV was weak evidence of two things. First, effort: had they bothered to tailor it to your role, which suggested they wanted this job specifically rather than any job. Second, communication: could they describe their own work clearly, which is a real skill and does transfer.

Both of those now cost nothing. Tailoring is a paste. Clear description is a default output. The two proxies that made CV screening feel like it was working have been commoditised, and what remains is a document where every applicant makes the same claims in the same order.

The uncomfortable follow-on: if the CV was mostly measuring effort and articulacy, and you have been hiring on it for years, you have been selecting for effort and articulacy. Which explains a certain kind of hire that everyone in security has met.

What AI did not change

Worth saying plainly, because this topic attracts a lot of doom.

AI did not make people worse at their jobs. The person who can pull a Kerberoasting attack out of a noisy Security log is still out there and still just as good. They are still in your applicant pile. Nothing about their ability changed.

Nor is using AI to write a CV cheating. It is a rational response to a process that rewards it. Any candidate who refuses on principle is competing against people who did not, in a system that reads the output rather than the person. I would use it too.

The problem is not the candidates. The problem is that your filter now measures something that costs nothing to produce.

Why cyber gets this worse than most fields

Three reasons this bites harder in security than in, say, hiring a plumber.

Cyber already ran on proxies. The industry leans on certifications more heavily than most technical disciplines. That was always a weak proxy for ability. Now you have a weak proxy sitting on top of a document that has lost its remaining signal, and both point the same way: someone who looks qualified.

The salaries attract volume. Cyber pays well and is widely described as having a shortage, so applicant pools for entry and mid-level roles are large. More volume, more compression, less signal per hour of reading.

The vocabulary is easy to borrow. “Monitored SIEM alerts and escalated in line with playbooks” is a sentence anyone can generate. Actually doing it requires reading a log and making a judgement call that the sentence does not capture. The distance between describing security work and doing it is unusually wide, and language is the thing AI is best at.

The tells do not work, and chasing them is a trap

The instinct is to get better at spotting AI writing. Em dashes, “delve”, suspiciously balanced sentences, that particular corporate rhythm.

Do not build a process on this.

Detection is unreliable, gets less reliable every model release, and the cost of a false positive is severe. Rejecting a strong candidate because their writing looked synthetic is a worse outcome than reading one more AI-written CV. Non-native English speakers are disproportionately flagged by every heuristic anyone has tried, which turns a detection habit into a fairness problem.

And the deeper issue: even where you can tell, it does not help. Knowing a CV was AI-assisted tells you nothing about whether the person can do the job. You have identified the tool, not the candidate.

The uniformity is the tell. But uniformity is a property of the pile, not of any individual in it, so it cannot help you decide who to interview.

What still carries signal

Three things, in this order.

1. Demonstrated work. What did they actually do, in conditions you controlled, that you watched. This is the only category that is genuinely resistant, because the artefact is in front of them and the answer only exists inside it.

CyberHire · PowerShell forensics · malicious script investigation A PowerShell forensics assessment showing a live terminal with Get-WinEvent output, including a logon event, special privileges assigned, a PowerShell process launched with an execution-policy bypass and hidden window, a new account created and added to Administrators, a scheduled task, and file access on an HR spreadsheet and a backup archive.
An entire intrusion in ten log lines. An LLM will define every one of these event IDs for you. It cannot tell you what happened here, because the answer only exists in this specific terminal.

2. Specific, checkable claims. Not “experienced with SIEM” but which platform, at what scale, what did they own versus contribute to, what was the alert volume, who did they escalate to. Specifics are harder to generate convincingly and much easier to probe. A candidate who owned something can go three questions deep. A candidate who borrowed the sentence cannot go one.

3. References. Unfashionable, still useful, still the only source of information about how someone behaves over months rather than minutes.

Notice that CV reading is not on the list.

So what do you actually do

Move the evidence step earlier.

If the CV can no longer separate your applicants, the answer is not to read CVs more carefully. It is to stop using them as the first filter and put something in front of candidates that produces evidence instead. The practical version of that, including what to do when there are two hundred of them, is in how to screen 200 cyber applicants without reading 200 CVs. The method itself is in how to assess cybersecurity candidates.

And keep reading CVs. Just read them second, for the fifteen people you already know can do the work, when you are deciding what to ask rather than who to ask.

One honest sentence

The CV was always a weak signal that we treated as a strong one, and AI has simply made that impossible to keep ignoring.

Stop reading CVs. Start reading evidence.

See what the evidence looks like.

The hiring intelligence report is the deliverable: ranked candidates, skill-level performance, integrity findings, and where to press each one at interview.

Discuss a live role Request a sample report