For hiring managers

Interview guide for cybersecurity roles: a loop with alert triage, a tabletop and a detection exercise

On this page
  1. The loop at a glance
  2. Stage 1: the screen (30 minutes)
  3. Stage 2: the alert triage work sample (60 minutes)
  4. Stage 3: the incident tabletop (45 minutes)
  5. Stage 4: the detection or hardening exercise (45 minutes)
  6. Stage 5: manager and stakeholder conversation (45 minutes)
  7. Scorecard competencies and weights
  8. Legal points for security hiring
  9. The decision rule
  10. Adjusting the loop
  11. Common mistakes in security loops
  12. Questions people ask

Security hires are trusted with the keys to everything: admin consoles, logs full of personal data, and the decision about whether an odd login at 2 a.m. is a breach or a salesperson in an airport. A loop that asks candidates to define the CIA triad or list the OWASP Top 10 tests memory, not judgment. What you need to know is whether the candidate can separate signal from noise in real alerts, run an incident calmly, write a detection that does not page the team all night, and handle sensitive access ethically. This guide gives security managers a loop for a mid-level SOC analyst or security engineer: five stages, owners, an alert triage work sample, an incident tabletop, a detection exercise, weights and a decision rule. Adjustments for penetration testers, GRC analysts and cleared roles are at the end.

The first call, including how to place a candidate by SOC tier and word clearance questions, is in cybersecurity analyst screening questions. For sourcing, see Boolean search strings for cybersecurity roles. This page is the loop after the screen.

The loop at a glance

StageInterviewerOwnsLengthPass rule
1. ScreenRecruiter or SOC leadTier, tools actually used, shift and on-call fit, clearance if required30 minClear match on tier; any required clearance confirmed as a status, not a guess
2. Alert triage work sampleSenior analystTriage judgment; investigation method; ticket writing60 minAt least 3 on triage judgment
3. Incident tabletopIncident response leadIncident handling; communication under pressure45 minAt least 3 on incident handling
4. Detection or hardening exerciseSecurity engineerDetection engineering or control design45 minAt least 2; a 3 for engineering roles
5. Manager and stakeholder conversationSecurity manager plus an IT or engineering partnerEthics; collaboration; learning45 minEthics gate passed; nothing below 2

Stages 2 to 5 fit in one day or two half-days. The structure mirrors the interview guide for DevOps roles, which uses a similar live incident; if you hire both, share the scenario bank but score different competencies.

Stage 1: the screen (30 minutes)

  • "Walk me through your last shift: how many alerts, from which tools, and what did you close versus escalate?" Listen for: numbers and their own decisions, not the team's.
  • "Tell me about a detection rule or alert you tuned. What was wrong with it and what changed?" Listen for: false positive rates and a specific change. This separates people who ran a SIEM from people who watched one.
  • "This role covers [shift pattern] with on-call one week in [n]. How does that fit?" State it plainly to every candidate.
  • Clearance, only if the contract requires it: "This role requires an active [level] clearance. Do you currently hold one, and at what level?" Ask the same way for everyone.

Stage 2: the alert triage work sample (60 minutes)

Give the candidate a packet of eight invented alerts with the log lines behind each, in a plain document or a sandboxed tool. Write it once and use it for every candidate. Never use real logs; they contain personal data and internal details a candidate should not see.

Example packet

  • Three benign alerts: an impossible-travel login that matches a VPN exit node, a scheduled admin script, and a vulnerability scanner hitting a web server.
  • Two ambiguous alerts that need one more data point, such as a new mail forwarding rule on a finance mailbox.
  • Two true positives that connect: a phishing click followed, 40 minutes later, by a PowerShell download on the same host.
  • One low-severity alert that is actually the most important, such as a new local admin account on a domain controller.

What to score

  • Triage judgment: closes the benign ones with a reason, escalates the linked pair, and notices the quiet domain controller alert.
  • Method: asks for, or looks for, the one extra fact that would settle each ambiguous alert, rather than escalating everything.
  • Ticket writing: one escalation note a Tier 3 analyst could act on without calling them: what happened, the evidence, the scope so far and the recommended next step.

Stage 3: the incident tabletop (45 minutes)

The interviewer plays the rest of the company. Scenario: at 09:10 on a Monday, the help desk reports that several users in accounting cannot open files, which now have a new extension. Feed in facts as the candidate asks: a file server share is affected, backups ran last night, and the CFO wants to know whether to pay anything.

  • Containment first: isolating affected hosts and the share, and protecting backups before they are reached, without wiping evidence.
  • Roles and communication: naming an incident lead, setting an update interval, and knowing when legal, leadership and insurers need to be told under the company's plan.
  • Judgment on the ransom question: not answering it alone; routing it to leadership and counsel with the facts they need.
  • Afterward: "What goes in the post-incident review?" Listen for: root cause, detection gaps and owners for follow-ups, not blame.

Stage 4: the detection or hardening exercise (45 minutes)

For SOC and detection roles, give a short description of an attacker technique, such as creating a mail forwarding rule to an external address, and a sample of log fields. The candidate writes a detection in pseudo-query or your query language, then explains how it would fail: false positives, blind spots and how an attacker would evade it. For security engineering roles, swap in a hardening review: a short, invented cloud configuration with a public storage bucket, an over-permissive role and logging turned off.

Score whether the candidate thinks about the people who will be paged by the rule. A detection that fires on every legitimate forwarding rule in the company is a 2, however clever the query.

Stage 5: manager and stakeholder conversation (45 minutes)

  1. "Tell me about a time you had access to something you were not supposed to look at, or found data you did not expect. What did you do?" Listen for: stopping, reporting and not browsing. This is the ethics gate.
  2. "Tell me about a security control you pushed for that the business resisted." Listen for: understanding the business cost and finding a version that shipped.
  3. From the IT or engineering partner: "What do you need from my team when you raise a finding?" Listen for: clear asks, priorities and willingness to help fix, not just file tickets.
  4. "What have you learned in the last six months, and how?" Listen for: something specific, applied at work.

Scorecard competencies and weights

Example weights for a mid-level SOC analyst. Lock yours before the first candidate.

CompetencyOwned byExample weight
Triage judgmentAlert triage work sample25%
Investigation methodWork sample; tabletop20%
Incident handling and communicationTabletop20%
Detection engineeringDetection exercise15%
Written communicationTicket note10%
Collaboration and learningManager and stakeholder conversation10%
Ethics with sensitive accessManager conversationPass/fail gate

The scorecard builder checks that weights add up to 100 and prints one sheet per interviewer, so each person scores only the competencies their stage owns.

Checked against the linked primary sources as of October 2026. This is not legal advice; confirm requirements for cleared work with the client's or your own facility security officer and counsel.

  • Clearances are requested by the company. Under 32 CFR 117.10, contractors must limit eligibility requests to the minimum number of employees needed, and requests may not be used "to establish a cache of cleared employees." A contractor may start the process before hire with a written commitment for employment, which must say employment will begin within 45 days of eligibility being granted. Non-US citizens can receive only a limited access authorization, in rare circumstances.
  • Citizenship requirements need a legal basis. The Justice Department says an employer may restrict hiring to US citizens only if a law, regulation, executive order or government contract requires it. Do not add a citizenship requirement to a commercial security role because the work feels sensitive.
  • Contract qualification rules. Defense work can carry workforce qualification requirements under DoD Manual 8140.03. Get the exact requirement for the role from the contract or the client's program office rather than inferring it.
  • Background checks. If a background check company provides the report, 15 U.S.C. 1681b(b) requires a stand-alone written disclosure and written authorization before the report, and a copy of the report and a summary of rights before adverse action. The steps are in the FCRA background check process.

The decision rule

  1. Scorecards first, including the ticket note and detection, before anyone talks.
  2. Gate: the ethics answer passes. A candidate who describes browsing data out of curiosity does not proceed, however strong the rest.
  3. Floor: triage judgment at 3 or above.
  4. Weighted total: in this example, 2.8 or higher on a 1–4 scale is an offer.
  5. Split panel: if the triage and tabletop scores differ by two points, compare the candidate's actual words from each before anything else.

Adjusting the loop

RoleWhat changes
Tier 1 analyst or career changerShorter packet with more benign alerts; drop the detection exercise; weight learning and ticket writing. The IT support interview guide covers the adjacent loop.
Penetration testerReplace triage with a scoped test on a lab you own and have authorized; score the written finding and its remediation advice as heavily as the exploit.
GRC or compliance analystReplace the detection exercise with a control mapping task: map a short invented policy to a framework and find the gaps; weight writing and stakeholder work.
Cleared roleConfirm the clearance requirement with the facility security officer before posting; let the security officer verify status in the government system, not the recruiter.

Common mistakes in security loops

  • Trivia rounds. Port numbers and acronyms are a search away; triage judgment is not.
  • Real logs in exercises. They leak data and make scoring inconsistent.
  • No ethics question. Privileged access is the job; ask about it directly.
  • "Clearable" as a requirement. It is a belief, not a status you can verify.

Questions people ask

What is the best work sample for a SOC analyst interview?

An alert triage packet: a handful of invented alerts with the log lines behind them, some real and some benign. The candidate decides which to escalate, explains why, and writes a short ticket note. It tests the daily job directly and is easy to score the same way for every candidate.

Can I ask a cybersecurity candidate whether they hold a security clearance?

Yes, when the role genuinely requires one. Ask every candidate the same way about current clearance level and status, and leave investigation details to the formal process. A sponsoring contractor, not the individual, requests eligibility, and under 32 CFR 117.10 it may not request clearances to build a cache of cleared employees. As of October 2026; not legal advice.

Should a security interview include a hacking challenge?

Only for offensive roles such as penetration testers, and only in an environment you own and have authorized for the test. For defensive roles, triage, investigation and detection exercises predict the job better than capture-the-flag puzzles.

How much weight should certifications carry for security roles?

Use them as a screen when a contract or policy requires them, and verify them with the issuer. In the loop, score what the candidate does with alerts, logs and incidents. A certification shows study; the work sample shows judgment.