CISO, SOC, DPO, pentest: the HR guide to cyber roles

décembre 2, 2025
Recrutement cybersécurité RH

How do you recruit a cyber expert when you are not technical? This HR guide gives you the keys to assess, distinguish and hire the right profiles.

Why cyber recruitment is so difficult for HR

The global cybersecurity market is short of 3.4 million professionals. In France, hiring an experienced CISO often takes more than six months. For an HR professional without specialist knowledge, assessing a cyber CV is a hazardous exercise: job titles are vague, certifications are numerous and technical skills are hard to evaluate in a standard interview.

The six main cyber roles explained to HR

Role What they actually do Typical profile Salary, Paris 2024
CISO Leads the security strategy, reports to the board, manages teams and budgets Managerial, 10 years or more of experience, broad view €80,000 to €130,000
SOC analyst Monitors systems in real time, detects and analyses incidents Technical, junior to experienced, works in a 24/7 team €35,000 to €60,000
Pentester Tests systems by simulating attacks to find weaknesses Highly technical, creative, OSCP or CEH certified €45,000 to €80,000
DPO Ensures GDPR compliance, handles data subject rights, liaises with the regulator Legal and technical, CIPP/E certified €50,000 to €85,000
GRC Risk management, compliance with ISO 27001 and NIS2, audits Auditor or consultant, CISA or CRISC certified €50,000 to €90,000
Security architect Designs secure architectures and selects technical solutions Senior technical expert, systems-level view €70,000 to €110,000

How to assess a CISO candidate without being technical

The CISO is the most strategic cyber hire. They report to the board and their profile must be as managerial as it is technical. Questions worth asking in an HR interview:

  • How have you presented your security budget to the board? Assesses their ability to communicate with non-technical people.
  • Describe a security crisis you have handled. Assesses composure and method.
  • How do you keep up with new regulations? Assesses their monitoring and regulatory awareness.
  • What is your view of our organisation’s cyber maturity? Assesses their ability to analyse quickly.

A good CISO speaks the language of the board before speaking the language of engineers. If your candidate cannot explain their role in business terms, that is a warning sign.

Cyber certifications: which ones actually matter

Certification Level For which profile
CISSP Expert CISO, architect, the international reference
CISA Experienced GRC, auditor, governance oriented
OSCP Technical Pentester, the most recognised offensive credential
ISO 27001 Lead Auditor Experienced GRC, CISO, compliance oriented
CIPP/E Experienced DPO, the European data protection reference
CompTIA Security+ Junior Entry level, tier 1 SOC

The profiles to avoid

  • The expert in everything with no speciality
  • The pure technician with no business perspective
  • The certified candidate with no practical experience
  • The CISO who cannot talk to the board

Hire better with the CyberMasterClass Talent

90 minutes to understand cyber roles, assess candidates and hire with judgement. Designed for non-technical HR professionals.

Publications

Get the next publications.

One analysis per publication on cyber governance, resilience and compliance.

Take action in 90 minutes

Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.

See the masterclasses