Pedigree Is Not Proof. Cyber Hiring Needs Evidence.

The résumé can introduce the candidate. It cannot make the hiring decision. 

Nobody gets fired for hiring the candidate with the CISSP, the big-name employer, and ten years of adjacent experience. That's the actual purpose of a résumé in cyber hiring. It isn't a prediction of performance. It's insurance for the person making the decision. 

Stack enough pedigree together and the decision starts to feel responsible. It looks good in the applicant tracking system. It survives the approval meeting. If the hire fails, at least nobody can accuse you of taking a wild chance. 

Key takeaways 

  • Do cybersecurity degrees and certifications matter? Yes. They provide useful context and can verify important knowledge. They do not prove current performance against every task in a specific role. 
  • What counts as evidence in cyber hiring? Role-relevant assessment, hands-on performance, completed work, structured scenarios, and validated outcomes. 
  • Why is pedigree alone risky? Titles vary, experience gets stale, and impressive credentials can still leave the actual capability untested. 
  • What should employers do instead? Define the work, set the evidence standard, and combine credentials with a fair, current demonstration of capability. 

 And it works. Just not for the team that inherits the hire. 

A degree is context. A certification is context. A title and ten years in the field are context. Useful context, sometimes essential context, but still context. When we treat those signals as proof of current, role-relevant capability, we are not removing hiring risk. We are moving it downstream, where it becomes onboarding pain, missed delivery, another reopened requisition, and a very expensive calendar invite. 

Pedigree tells you where somebody has been. Evidence tells you what they can do next. 

 

We Ask for Evidence and Still Screen on Pedigree 

The data makes this slightly awkward. 

ISC2 found that 84% of organizations use skills-based assessments or tests for entry- and junior-level cybersecurity applicants. Good. That suggests employers understand candidates should demonstrate knowledge in action, not just describe it on paper. 

The same research found that 34% of hiring managers expect entry-level candidates to hold the CISSP, and 33% expect it at junior level. The CISSP requires five years of cumulative paid cybersecurity experience. 

So apparently we want evidence. We would just like candidates to accumulate five years of it before we consider them for the role that is supposed to give them year one. 

That is not a certification problem. CISSP is a serious, valuable credential for the right work and level of responsibility. This is a requirements problem. We are taking a useful signal and asking it to do a job it was never meant to do. 

A certification can validate a defined body of knowledge. It cannot tell you, by itself, how somebody will investigate a noisy alert, challenge a weak control, explain risk to a business leader, or make a defensible decision when the evidence is incomplete. Those are different questions. They need different signals. 

Why Pedigree Feels Safer Than It Is 

Because pedigree is legible. 

The degree has a name. The certification has an issuing body. The title fits neatly into a hierarchy. The years add up without anybody having to debate them. Evidence is harder because somebody has to define the work, agree on what good looks like, and build a fair way to observe it. 

Pedigree lets the hiring team outsource that thinking to the candidate's history. 

But titles are wildly inconsistent. A security analyst in one company triages alerts. In another, that person threat hunts, tunes detections, handles cloud investigations, and gets pulled into governance because nobody else owns it. Ten years of experience can mean ten years of increasing scope. It can also mean the same year repeated ten times. A degree may show foundational learning. It does not come with a live feed confirming what is still current. 

None of this is an argument for throwing those signals away. It is an argument for putting them in their proper place. 

The NIST NICE Framework is useful here because it describes cybersecurity work through work roles, tasks, knowledge, and skills. Not prestige. Not whether the previous employer had a famous logo. The work itself. NIST's skills-based hiring guidance is unusually direct: advanced degrees, years of experience, and certifications are often proxies for capability, and overreliance on them can narrow the pool and make hiring slower and less effective. 

That is a lot of operational damage to do in the name of being cautious. 

Define the Work Before You Evaluate the Person 

Here is the part where I stop complaining about the job description and propose a replacement. 

Start with the work. What will this person actually be expected to do in the first six months? Which tasks are critical on day one? Which can be learned? What decisions will they own, and what is the consequence of getting them wrong? 

Then build the evidence around those answers. 

For a SOC analyst, that may mean triaging a realistic alert, explaining the severity, deciding what to escalate, and writing a clean case note. For a cloud security engineer, it may mean reviewing an identity and access configuration, spotting the material risk, and proposing a practical remediation. For a GRC role, it may mean turning a messy control gap into a risk statement somebody outside security can understand and act on. 

That gives you a signal stack instead of a single gate: 

  • Context: Degrees, titles, tenure, industry exposure, and career history. 
  • Verified knowledge: Relevant certifications and learning tied to the role's knowledge requirements. 
  • Applied capability: A work sample, lab, assessment, or completed project that resembles the real task. 
  • Judgment: A structured scenario that shows how the candidate handles ambiguity, tradeoffs, escalation, and communication. 
  • Validated outcomes: Evidence from prior projects, managers, or operational results, with enough context to understand the candidate's actual contribution. 

Recency runs through the whole stack. A skill demonstrated three years ago in a different environment may still be valuable, but it is not the same signal as capability verified against the tools and problems in front of you now. 

And please keep the assessment proportional. Candidates should not have to donate a weekend of unpaid consulting to prove they can attend a meeting on Monday. Use the same role-related task and scoring rubric for comparable candidates. Offer reasonable alternatives where the format creates an irrelevant barrier. A bad assessment is just another proxy wearing a lab coat. 

Certifications Matter. They Just Cannot Carry the Whole Decision. 

I want to be clear because the easy version of the argument is also the wrong one. 

Certifications matter. They create a shared knowledge baseline, demonstrate professional commitment, and may be required for particular roles or contracts. If a credential maps to the work, seniority, and compliance context, it belongs in the stack. 

What it cannot do is answer every question about readiness. A candidate can know the framework and struggle to apply it under pressure. Another can perform the task well but lack the credential your filter treats as mandatory. One may need practice. The other may need a path to certification. Those are development decisions. Neither is helped by pretending the résumé settled the matter. 

Credentials and evidence are not competing signals. One validates learning or experience within a defined scope. The other shows how capability appears in the work. Better hiring uses both and knows the difference. 

 

In Regulated Industries, This Is a Risk Decision 

This matters everywhere. It matters more when the work sits close to patient safety, protected health information, customer funds, operational resilience, or a regulator's clock. 

HHS cybersecurity performance goals for healthcare prioritize concrete practices such as phishing-resistant multifactor authentication, credential revocation, training, and strong encryption. The OCC treats cybersecurity and operational resilience as supervisory priorities for banks, including incident notification requirements that can create a 36-hour reporting clock after a qualifying incident is determined. 

Those are not résumé words. They are operating conditions. 

If you are hiring someone to own identity and access in a hospital, you need evidence they can remove inappropriate access without casually disrupting clinical work. If you are hiring into incident response at a financial institution, you need to see how the person separates noise from a material event, documents the decision, and escalates under time pressure. 

The most decorated candidate may be excellent. Great. Let the evidence confirm it. The less conventional candidate may be closer to the work than the résumé suggests. Great. Let the evidence reveal it. 

A regulated employer does not need a hiring process that looks selective. It needs one that can explain why the evidence matched the job. 

 The Résumé Gets an Introduction, Not a Vote 

Most organizations already collect some evidence. They just collect it after the keyword screen, pedigree filter, and three rounds of interviews. By then, the same weak signals have decided who gets to demonstrate capability. 

That is the failure underneath AI résumé screening that filters out capable cyber candidates. It is also the problem behind The Numbers Game in Resume Submission Is Broken: a thousand polished applications become a signal-to-noise problem instead of a better hiring decision. 

If evidence only appears after pedigree has narrowed the pool, it is not replacing the proxy. It is decorating it. 

Move a short, fair, role-relevant signal earlier. Use it to decide who deserves a deeper conversation. Then let the structured interview explore how the candidate thinks, communicates, learns, and operates in your environment. 

 The résumé can introduce the candidate. It cannot make the hiring decision. 

Pedigree Is Context. Evidence Makes the Decision Defensible. 

This is not complicated. It is just more honest than the system most of us inherited. 

Define the work. Decide what evidence would genuinely reduce uncertainty. Collect that evidence consistently. Then use degrees, certifications, titles, and experience for what they are good at: adding context, not impersonating proof. 

HiringIQ is the employer experience powered by AdaptIQ. It brings verified skills and role-relevant evidence into the decision earlier, so hiring teams can see who is ready, who is close, and where development belongs. 

It does not replace recruiters, and no score removes uncertainty. The point is to give the people making the decision something better than résumé familiarity and crossed fingers. 

The best candidate may have the degree, the certification, the title, and the evidence. Wonderful. Hire them with confidence. 

But if the proof is missing, the pedigree does not magically become proof because everybody in the approval meeting recognizes the logo. 

Pedigree tells you where somebody has been. Evidence tells you whether they can do the work in front of you. 

Hire with both. Just stop pretending they are the same thing. 


Explore evidence-based hiring with HiringIQ. 

Evidence-Based Cyber Hiring: Quick Answers 

Are cybersecurity certifications still valuable? 

Yes. Certifications can verify a defined body of knowledge, support compliance or contract requirements, and show professional commitment. They are strongest when combined with evidence of current, role-relevant performance. 

What counts as verified evidence in cyber hiring? 

Verified evidence can include role-based assessments, hands-on labs, work samples, completed projects, structured scenarios, manager validation, and documented operational outcomes. The evidence should resemble the work and be recent enough to inform the decision. 

How should employers start using evidence-based hiring? 

Define the role through the tasks and decisions that matter, separate required credentials from preferred context, introduce a short and fair evidence step early, and score comparable candidates against the same role-related rubric. 

Sources 

 

About the Author 

Launa Rich, Cyber Skills & Talent Intelligence Leader 

10+ years building cybersecurity workforce pipelines, hiring intelligence programs, and go-to-market strategy for enterprise security teams. Focused on closing the gap between credentials and capability.