Key Takeaways
- Why isn't ATS data enough to hire cybersecurity talent?
An applicant tracking system captures a candidate at a single moment, the day they applied, based on what they said about themselves. It doesn't update as their skills grow, and AI-written resumes and automated applications have made that one snapshot less reliable. - What is learning data in hiring?
It's evidence generated through training: monitored assessments, hands-on labs, and role-based simulations scored against a standard. Course completions alone don't count, because they show attendance, not ability. - How does combining learning and hiring data improve hiring?
When both are mapped to the same skills and stored in one record, employers can compare candidates on verified evidence, track rejected candidates as they close skill gaps, and consider internal and external candidates side by side. - Is skills-based hiring actually working?
Not widely yet. Research from the Burning Glass Institute and Harvard Business School found fewer than 1 in 700 new hires benefited from employers dropping degree requirements. Changing the job posting isn't enough without skills evidence in the hiring system. - What framework can organizations use to describe cybersecurity skills?
The NIST NICE Framework provides a common language for cybersecurity work and the knowledge and skills it requires. It's a strong starting point for defining roles in terms of skills. - How does HiringIQ help?
HiringIQ, the employer experience powered by AdaptIQ, builds skills assessments into the application and interview process so hiring decisions rest on verified skills instead of resume claims.
An applicant tracking system captures one moment in time. AI has already doctored that moment. Learning data is how hiring catches up.
I've spent 17 years in staffing, which means I've spent more than my fair share of time inside applicant tracking systems. Greenhouse, BambooHR, and plenty of others whose logins I've happily forgotten.
So I know exactly what comes out of them. A stack of resumes and a pipeline.
That's the output. And the data inside it never evolves. Every record is frozen on the day someone applied: the resume they had that week, the title they held that year, the skills they decided to list. The candidate keeps learning, keeps building, keeps getting better. The ATS never finds out. Data that never changes doesn't hold its value. It just gets older.
And now even that one moment can't be trusted. AI writes the resume, tunes it to your job post, and in plenty of cases submits the application too. The single snapshot your ATS was built to hold has been retouched before it ever arrives.
Meanwhile, somewhere else in your company, a learning platform is collecting exactly what your ATS is missing. Evidence of what people can do, updated every time they learn something new. It just lives in a different system, owned by a different team, and nobody in hiring ever looks at it.
A Snapshot, Then a Retouched One
I'm not knocking the ATS. It tracks applicants, moves them through stages, keeps legal happy. But it was built around a single event, the application. Whatever was true that day is what you get, forever. The candidate you rejected in March for one missing skill is still missing that skill in your system in December, even if they closed the gap in May.
That was always a limitation. AI turned it into a liability. A candidate can generate a tailored resume for every posting, match every keyword, and send hundreds of applications without reading a single job description. Bots and fake candidates apply right alongside real ones. The snapshot got less trustworthy at the exact moment the pile got bigger.
Meanwhile the stakes went up too. The 2025 ISC2 Cybersecurity Workforce Study found 95% of respondents have at least one skills need, and 59% called those needs critical or significant, up from 44% the year before. Then the one that should keep a CISO up at night: 88% have experienced at least one significant cybersecurity consequence because of a skills deficiency.
So we're making higher-stakes hiring decisions on lower-quality data. That math doesn't work.
And before anyone says "we already moved to skills-based hiring," I'd gently point you to the Burning Glass Institute and Harvard Business School research from 2024. Plenty of companies announced it. In practice, fewer than 1 in 700 new hires benefited from employers dropping degree requirements. The researchers' conclusion was that skills-based hiring takes "more than simply stripping language from job postings."
I'd go one step further. You can't hire on skills when your system of record stopped updating the day someone applied, and the one thing it did capture may have been written by a machine.

Learning Data Is the Missing Half
Let me be careful here, because I've spent a whole post arguing that course completions aren't evidence. They still aren't. Somebody sat through a video. Great.
The learning data I mean is the other kind. A lab where someone had to actually contain the incident. An assessment taken in a monitored, timed session, scored against a passing bar. A role-based simulation where the work looks like the job. That's evidence, and most of it is already being generated inside your organization or inside the training your candidates paid for themselves.
It tells you things a resume never will:
- What someone can do right now, measured, not described.
- How fast they're moving. Two candidates with the same score today are not the same hire if one got there in three months and the other has been stuck for two years.
- Who's adjacent. The network engineer, the cloud admin, the fraud analyst who are one or two validated skills away from a cyber role you've had open since spring.

The catch is language. The ATS speaks job titles and keywords. The learning platform speaks courses and modules. Neither one speaks skills in a way the other can read.
That's why a shared skills language matters so much. The NIST NICE Framework exists to give us "a common language that describes cybersecurity work and the knowledge and skills needed to complete that work." It's a strong foundation. What most organizations are missing is the layer that ties that language to real evidence about real people, in the system where hiring decisions actually get made.
What Changes When They Share One Record
Put learning evidence and hiring decisions in the same record, mapped to the same skills, and a few things that used to be impossible get boring. That's a compliment.

The learn-to-hire loop · 4 steps around one record
The record sits in the middle and every step writes to it. The loop closes when what you learn from each hire sharpens how you define the next role.
The candidate record stops being a snapshot. Today, a resume is frozen the day someone applies. When the record is fed by validated learning, it keeps updating. The analyst who was two skills short in March can be ready in June, and you'll know it without anyone resubmitting anything.
"No" turns into "not yet." Every company has a pile of solid candidates it turned down for one missing skill. Today they disappear into the ATS. With a shared record, that pile becomes a pipeline you can actually watch.
Internal and external candidates show up in the same search. The person on your cloud team with three of the four skills you need sits next to the external applicant who has all four on paper. Now you can compare evidence to evidence, not employee to resume.
Your job requirements get honest. When hiring outcomes flow back into the record, you start to see which skills you actually needed and which ones were just habit on the job description.
What to Do About It This Quarter
You don't need a two-year transformation program for this. You need to stop letting your two best data sources ignore each other.
- Pick one hard-to-fill cyber role. Write down the five or six skills the work actually requires. Not the job description. The work.
- Get evidence on those skills, not claims. For external candidates, build a skills assessment into the application. For internal people, look at what your learning platform can already validate.
- Put both in the same place. If your ATS can't hold validated skills, that's your answer about whether it's a hiring system or a filing system.
- Keep the "not yets." Track the candidates you passed on for one missing skill. Give them a path. Check back.
- Close the loop. Six months after a hire, ask which validated skills actually mattered. Rewrite the next job requirement from that, not from last year's posting.
None of this is exotic. It's the same discipline you'd apply to any security program. Assess, harden, validate, repeat. We just keep forgetting to apply it to people.
I'm also finishing a cyber skills ontology for security leaders, the shared language that makes this loop work across roles. More on that soon.
Hire on evidence, not claims. HiringIQ, the employer experience powered by AdaptIQ, builds skills assessments into your application and interview process and keeps the results in the same platform as the learning that built those skills. See how it works on one of your open roles.
Sources
- 2025 ISC2 Cybersecurity Workforce Study, ISC2, December 2025
- Skills-Based Hiring: The Long Road from Pronouncements to Practice, Burning Glass Institute and Harvard Business School, February 2024
- Employers don't practice what they preach on skills-based hiring, report finds, Higher Ed Dive, February 2024