CyberHire

SOC hiring

Hire SOC analysts who can actually triage.

Send us the role and the applicants you already have. We build the assessment around what the job actually involves, run the candidates through it, and hand back a ranked shortlist with the evidence attached.

Why this hurts

SOC hiring is broken in three specific ways.

  1. 01

    CVs are calibrated against certs, not the job.

    Stacks of certifications look impressive on paper. They predict almost nothing about whether someone can read a log line and reason about what happened. And now that any applicant can generate a well-tailored CV in seconds, the little signal that document carried has largely gone.

  2. 02

    Interview questions are trivia.

    "What port does DNS use?" tells you someone can search. It does not tell you they can look at a failed Kerberos authentication chain and decide whether it is a misconfigured service account or the start of lateral movement.

  3. 03

    Volume drowns the hiring team.

    200 applications for a Tier 1 role is normal. Most get filtered on keyword scans that reject strong candidates and approve weak ones, and your SOC leads end up with a shortlist nobody trusts and an afternoon of interviews to prove it.

How we fix it

Measure the work. Not the paperwork.

  1. Real environments, real telemetry.

    Candidates work in a live shell, a Sentinel-grade KQL editor, an Event Viewer or a mail client, against realistic data. You find out whether they can locate the signal in actual log output, not whether they memorised a cheat sheet.

  2. Cases built with decoys, not signposts.

    A challenge with one anomaly on an otherwise clean page tests reading. Our cases put legitimate activity alongside the malicious kind, because separating the two is the actual job.

  3. Ranked evidence, not a pass mark.

    Every campaign produces a ranked cohort with per-skill breakdown, the underlying answers, and integrity signals reviewed before reporting. You get the full picture before anyone books an interview slot.

What you can actually test for

SOC-specific content, calibrated to the tier.

  • KQL hunting across sign-in, device and audit telemetry
  • Phishing triage with full headers and raw source
  • Windows Event Log investigation (Kerberoasting, suspicious logon chains)
  • Raw log analysis in a live Linux shell
  • Alert prioritisation under time pressure
  • Detection rule authoring and tuning
  • PCAP analysis for command-and-control traffic
  • Endpoint detection review
  • Incident write-up for a non-technical stakeholder

Honest comparison

SOC hiring with CyberHire vs the old way.

CyberHire CV screen + interview
Measures triage skill Hands-on against realistic telemetry Indirect - trivia, keyword scan and vibes
Assesses blue team fundamentals First-class discipline Proxied through certifications
Who builds the assessment CyberHire, from your job spec Your SOC leads, in evenings they do not have
Who runs the candidate process CyberHire, end to end Your hiring team, alongside the day job
Integrity controls Built for external candidates, reviewed before reporting Generic or none
Fairness across candidates Same environment, same scoring, every time Interview variance and reviewer fatigue

What a SOC candidate actually sits

Not a quiz about security. The work, in the tools, with the noise left in. Here are two cases from a real SOC assessment.

Email analysis · cloud-share impersonation Full size An email analysis challenge showing a phishing message in a mail client with Email, Headers and Raw Source tabs. The message impersonates Microsoft SharePoint, passes SPF, DKIM and DMARC, and its link points to a genuine login.microsoftonline.com OAuth authorize URL redirecting to an external domain.
SPF, DKIM and DMARC all pass. The link genuinely goes to login.microsoftonline.com. Every check a junior analyst is taught to run comes back clean, and it is still an attack. One of the offered answers is the exact conclusion a checklist-trained analyst reaches.
Log analysis · Apache web attack detection Full size A log analysis challenge with a live terminal showing Apache access log entries from a dozen internal IP addresses across various endpoints, and a free-text answer box asking which address performed a brute force attack on the login endpoint.
Raw access logs in a real shell, mostly legitimate browsing. One address is brute forcing the login endpoint and nothing is labelled. The answer box is free text, so there is nothing to guess between.

How a SOC campaign runs

  1. 01

    Send us the role

    Share the job specification and tell us the tier you are hiring at. We identify the skills the role actually depends on rather than the tools listed above them.

  2. 02

    We build the assessment

    A SOC-specific assessment calibrated to Tier 1, 2 or 3, drawn from the library or written for the role, and reviewed before it goes anywhere near a candidate.

  3. 03

    Connect your applicants

    Secure bulk upload, email invitation, or your ATS. Direct applicants, referrals, internal movers and agency submissions all go through the same door and are held to the same bar.

  4. 04

    We run it

    Candidates complete the work in real environments while we manage the process. You can watch progress, results and integrity signals live in your workspace if you want to.

  5. 05

    You get the evidence

    A ranked shortlist and a hiring intelligence report: who performed strongest, per-skill breakdown, integrity findings, and what to probe with each candidate at interview.

SOC hiring questions we get asked

How do you assess a SOC analyst before interviewing them?

Put a small piece of the actual job in front of them. For a SOC role that means triage under ambiguity, reading raw logs, correlating across sources, and explaining what happened to a non-technical stakeholder. All four are testable in under an hour, and none can be answered from memory or a search engine.

Can you calibrate the assessment to Tier 1 rather than Tier 3?

Yes, and it matters more than most teams expect. The most common reason a SOC assessment fails is that it was written by the strongest analyst on the team, who naturally wrote something they found interesting. Screening Tier 1 candidates against a Tier 3 bar makes everyone fail and makes the market look empty. We calibrate to what the person will own on day thirty.

How long does a candidate spend on it?

For a first screen across a large applicant pool, deliberately short. The goal at that stage is establishing who is worth an hour of a senior analyst's time, not fully evaluating anyone. Asking 200 people for three hours gets you a self-selected sample of the least busy, and you lose strong candidates first.

What stops candidates using AI during the assessment?

Mostly the task design. An LLM will define Kerberoasting instantly but cannot tell you which of six accounts in your specific log set is doing it, because that answer only exists in the artefact in front of the candidate. Investigation tasks degrade gracefully under AI assistance in a way recall questions do not. Behavioural integrity signals are captured alongside, reviewed before reporting, and treated as a reason to probe at interview rather than as an automatic rejection.

Do we still interview candidates?

Yes, and the interview gets better. Instead of spending the hour working out whether someone can read a log, you spend it on judgement, escalation behaviour, how they handle being wrong, and whether they will still be here in two years. The assessment tells you who to interview and gives you sharper questions to ask them.

Can you assess candidates our agency sent us?

Yes. Direct applicants, referrals, internal candidates and agency submissions all go through the same assessment and are ranked on the same evidence. Some recruitment agencies also run this themselves and present the evidence to their clients, which is what CyberHire Partners is for.

Stop guessing.

Hire SOC analysts who can actually defend the SOC.