CyberHire is a technical screening platform built end to end for
cyber security hiring. Real environments, real tools, real
signal. Six product surfaces, one calibrated hiring decision.
14 days free · No credit card · No sales call required
Six surfaces
What you actually get when you log in.
Every part of the product earns its space. No filler, no
features built for the brochure.
Test builder
Paste the job spec. Ship the test.
Drop a job description into the builder and a calibrated assessment lands on the other side. Review it, edit it, send it. Beats spending an afternoon writing scenarios you have already written four times this year.
Custom challenges
When the library does not have it, write a sentence.
Describe the scenario you want to test. The environment, questions, and grading criteria are generated. You review and publish. Useful for the role-specific edge cases the templates do not cover.
Candidate experience
Real tools. Not toy sandboxes.
Candidates triage phishing in an email client. Investigate Security Events in a Windows Event Log style viewer. Write KQL in an editor matched to Sentinel keystroke for keystroke. Pop a shell in a real Linux box. Whatever the discipline, the surface looks like the job.
Anti-cheat
Three tiers. Tracking, enforcement, proctoring.
Standard tracks tab switching, copy/paste, and keystroke patterns - no enforcement. Secure adds enforced fullscreen and blocked copy/paste. Proctor adds periodic webcam monitoring with explicit candidate consent. Pick the tier per assessment.
Infrastructure
Fresh box per candidate. Zero shared state.
Isolated Docker environments on Fly.io in London. Every candidate gets their own clean environment. No leaked flags, no answer reuse across cohorts, no candidate clobbering the next one's session.
Insights
Open the dashboard. Pick your hires.
Score distributions, skill breakdowns across the cohort, time analytics, integrity flags, ranked candidates. The data sorts itself. The dashboard surfaces the people you should be talking to. You make the offer.
From job spec to test
Upload your job spec. Get a custom hiring test.
Instantly.
This is not 1999 so why do we still hire like it? Drop a JD into
CyberHire and get a complete assessment back, calibrated to what
the role actually needs. Edit it, customise it, send it.
Job spec
emptypasted · 287 words
Paste or drop a job spec here
Tier 2 SOC Analyst
Banking · UK · hybrid
We are hiring a Tier 2 SOC Analyst to join our 24/7 security
operations team. The role focuses on alert triage, threat
hunting, and incident response handover.
Required:
· 3+ years SOC experience
· Strong KQL and Microsoft Sentinel
· Linux command-line proficiency
· Packet analysis with Wireshark or tshark
· Incident response exposure
· MITRE ATT&CK familiarity
Generated assessment
READY
Waiting for a job spec
SOC Analyst Tier 2 Screen
6 challenges · ~50 min · hands-on
01
KQL Threat Hunt
Sentinel-style log investigation
10 min
02
Privilege Escalation
Linux terminal · sudo misconfig
10 min
03
PCAP Triage
Lateral movement detection
8 min
04
Auth Log Investigation
Brute force + persistence
8 min
05
Incident Response
Multi-stage scenario triage
9 min
06
ATT&CK Mapping
TTP knowledge check
5 min
Copy⌘C
Paste⌘V
Select All⌘A
Custom challenges
Describe the scenario.
Get the challenge.
When the library does not have what you need, write a sentence.
The environment, the questions, and the grading criteria are
generated. You review, tweak, publish.
Your description
waiting47 words
Describe the scenario you want to test...
A SOC analyst challenge where the candidate investigates a brute-force SSH attack on a Linux server. They should identify the attacker IP, check if any logins succeeded, find the persistence mechanism, and recommend a remediation.
1 AI credit
Generated challenge
READY
Waiting for a description
SSH Brute-Force Investigation
Linux terminal · ~12 min · hands-on
Environment
Ubuntu 22.04 sandbox box
Pre-loaded /var/log/auth.log with attack traces
Persistence planted in /etc/cron.d/
Questions (5)
01What is the attacker's source IP address?
02Did any login attempts succeed? If so, which user?
03Where did the attacker plant their persistence?
04Which command would you run to remove it?
05What hardening would prevent the attack vector?
The candidate experience
Real tools.
No toy sandboxes.
Candidates triage phishing in an email client. Investigate
Security Events in a Windows Event Log style viewer. Write KQL
in an editor built to match Sentinel. Pop a shell in a real
Linux box. Let candidates show their actual skills.
⚠
Stored XSS via dangerouslySetInnerHTML on untrusted user.bio
A real Linux box. SSH in, work like you're on the job.
Built to match the Microsoft Sentinel Logs UI keystroke for keystroke.
Phishing triage in a familiar inbox layout. Headers and raw source on tap.
Native Windows Security Event triage. Same columns, same icons, same workflow.
Syntax-highlighted code review with the languages your AppSec team actually reviews.
Anti-cheat
Cheaters are creative.
We are paranoid.
Cheating in 2026 looks like a second monitor with ChatGPT open,
a friend on Discord, a phone camera on the question, or hiring
someone to take the test. Capture every signal that matters and
score candidate integrity end to end.
TO
Tom Okafor
SOC Analyst Tier 2 Screen · Completed in 28m 14s
Risk score
41/100
REVIEW
IP81.143.62.118
Geo
Manchester, United Kingdom
BrowserChrome 122 / Windows 11
Integrity events
4 triggered · ranked by severity
Excessive paste3 events · 247 chars
Concentrated in Q3. Largest paste was 184 chars into the free-text answer.
high
Multi-monitor detected1 event
Second display connected at 14:32, 11 minutes into the session.
high
Tab visibility lost12 events
8 of 12 in the final 5 minutes of the session.
med
Keystroke cadence outlierQ4 only
Inter-keystroke intervals were uniform within 4ms variance.
med
Passed checks
Standard signal sweep
No fullscreen exits No copy events Browser supported Consent recorded Webcam snapshots captured KQL introspection clean
Suggested action: manual review of Q3 and Q4
Open session log
Three integrity tiers. Standard, Secure, Proctor. And no, ChatGPT does not type like a human.
Insights and analytics
Open the dashboard.
Pick your hires.
Score distributions, skill breakdowns across the cohort, time
analytics, integrity flags, ranked candidates. The data sorts
itself, the dashboard surfaces the people you should be talking
to. You make the offer.
The old way
312
CVs to read
23h
screening
6w
to fill
James Wilson
5 yrs SOC, CISSP, GCIH
unread
Sarah Chen
3 yrs IR, SC-200
unread
David Kumar
7 yrs cloud security, CCSP
unread
Emma Brooks
4 yrs AppSec, OSCP
unread
Marcus Lee
6 yrs threat intelligence
unread
Lena Park
5 yrs forensics, GCFA
unread
Tom Reed
8 yrs pentest, OSEP
unread
Priya Patel
2 yrs SOC analyst
unread
Olivia Stone
4 yrs detection engineering
unread
Daniel Cole
6 yrs malware analysis
unread
Aisha Khan
3 yrs GRC, CISA
unread
Carlos Vega
7 yrs IR, GCIA
unread
Maya Andersen
5 yrs SOC + KQL specialism
unread
Noah Tremblay
Self-described "cyber ninja"
unread
Robert Singh
10 yrs CIO, transitioning
unread
Hannah Walker
Recent grad, CompTIA Security+
unread
Jordan Li
5 yrs SOC, GCIH, KQL strong
unread
Priya Raman
4 yrs SOC, Sentinel exp
unread
James Wilson
5 yrs SOC, CISSP, GCIH
unread
Sarah Chen
3 yrs IR, SC-200
unread
David Kumar
7 yrs cloud security, CCSP
unread
Emma Brooks
4 yrs AppSec, OSCP
unread
Marcus Lee
6 yrs threat intelligence
unread
Lena Park
5 yrs forensics, GCFA
unread
Tom Reed
8 yrs pentest, OSEP
unread
Priya Patel
2 yrs SOC analyst
unread
Olivia Stone
4 yrs detection engineering
unread
Daniel Cole
6 yrs malware analysis
unread
Aisha Khan
3 yrs GRC, CISA
unread
Carlos Vega
7 yrs IR, GCIA
unread
Maya Andersen
5 yrs SOC + KQL specialism
unread
Noah Tremblay
Self-described "cyber ninja"
unread
Robert Singh
10 yrs CIO, transitioning
unread
Hannah Walker
Recent grad, CompTIA Security+
unread
Jordan Li
5 yrs SOC, GCIH, KQL strong
unread
Priya Raman
4 yrs SOC, Sentinel exp
unread
Then you interview 25 of them.
→
The new way
19
tests sat
2m
to review
8
ready to hire
Ranked by performance
MA
Maya Andersen
94
HIRE
02
JL
Jordan Li
91
HIRE
03
PR
Priya Raman
87
HIRE
04
OS
Olivia Stone
82
HIRE
05
DK
David Kumar
79
HIRE
06
CV
Carlos Vega
76
HIRE
07
AK
Aisha Khan
73
HIRE
08
LP
Lena Park
71
HIRE
Character interview + culture fit.
6 weeks
spent reading CVs and scheduling interviews
2 minutes
picking the people who really know their stuff
Challenge library
Every cyber discipline.
Hand built.
Hand-written by working cyber practitioners. Calibrated to role
level. Refreshed when techniques drift. The library you would
have built if you had three years and nothing else to do.
Linux terminal exploitation and privilege escalation
Sentinel-grade KQL hunting against realistic telemetry
Phishing triage with header analysis and IOC pivoting
PCAP analysis for C2, lateral movement, exfiltration
Web exploitation CTFs (auth bypass, IDOR, SSRF, deserialisation)
Reverse engineering and basic malware triage
Cloud security audits across AWS misconfiguration
Detection authoring (Sigma rules, KQL detections)
Incident response write-ups and stakeholder comms
Knowledge gates calibrated to role level
Role templates
Day one templates for the roles cyber teams
actually hire.
Skip the blank page. Pick a template, customise in seconds, ship
the test. Each one calibrated by people who have hired into the
role.
SOC analyst (Tier 1, Tier 2, Tier 3)
Penetration tester
Cloud security engineer
Application security engineer
Incident responder
Digital forensics analyst
Malware analyst
Threat intelligence analyst
GRC analyst
Why teams pick us
Seven reasons you are already in
a different weight class.
01Validated, practical skill
Better capability. More credibility.
Hire people who can actually triage, query, reverse, and respond.
Your median-time-to-detect moves in the right direction the week
they start, and the board notices.
02From GBP 299 / mo
One hire and it pays for itself. Several times over.
A mis-hire costs about 30% of first-year salary. Our Starter plan
costs about 30% of one day's billable consultancy.
03Async screening at scale
Screen hundreds of candidates. Without interviewing them.
Bulk invite your entire applicant stack. Scores ranked, integrity
flagged, shortlist surfaced. You only book interviews with the
people actually worth meeting.
04Test flight, not paperwork
You wouldn't hire a pilot without a test flight.
Your security team is flying your entire operation. When it crashes
and burns, the cost is measured in regulatory fines, breach
disclosures, and a very awkward board meeting. Put them in the
simulator first.
05Audit-ready workforce competence
Regulators want proof.
Every serious framework wants documented evidence your security
team can actually do the job.
ISO 27001:2022 Clause 7.2
Requires documented evidence that security personnel are
competent, based on education, training, or experience.
SOC 2 CC1.4
Explicit requirement to "attract, develop, and retain
competent individuals."
NIS2 Article 20/21
EU. Management bodies must ensure staff have "sufficient
knowledge and skills."
DORA Article 13
EU financial services. Training "commensurate with role."
NIST CSF 2.0 PR.AT-01
Personnel must possess knowledge and skills to perform tasks.
06Blind, skills-first, standardised
People deserve a fair shake.
We believe in fairness. Your filters are quietly rejecting hidden
gems. The self-taught analyst. The career-switcher. The one without
the university logo. Skill-first testing drags them back in.
07AI grading - ranked dashboards
A hiring decision you can defend.
Every candidate scored on the same assessment, against the same
baseline, with the same evidence trail attached. Top of the dashboard
is your shortlist. The "why this hire?" question is answered before
anyone asks it.
Ready when you are
Try it. We'll put the kettle on.
14 days free. Invitation only. Request a code, get up and
running in minutes. No demo required. No sales call required.