CISO, SOC, DPO, pentest: the HR guide to cyber roles
How do you recruit a cyber expert when you are not technical? This HR guide gives you the keys to assess, distinguish and hire the right profiles.
Why cyber recruitment is so difficult for HR
The global cybersecurity market is short of 3.4 million professionals. In France, hiring an experienced CISO often takes more than six months. For an HR professional without specialist knowledge, assessing a cyber CV is a hazardous exercise: job titles are vague, certifications are numerous and technical skills are hard to evaluate in a standard interview.
The six main cyber roles explained to HR
| Role | What they actually do | Typical profile | Salary, Paris 2024 |
|---|---|---|---|
| CISO | Leads the security strategy, reports to the board, manages teams and budgets | Managerial, 10 years or more of experience, broad view | €80,000 to €130,000 |
| SOC analyst | Monitors systems in real time, detects and analyses incidents | Technical, junior to experienced, works in a 24/7 team | €35,000 to €60,000 |
| Pentester | Tests systems by simulating attacks to find weaknesses | Highly technical, creative, OSCP or CEH certified | €45,000 to €80,000 |
| DPO | Ensures GDPR compliance, handles data subject rights, liaises with the regulator | Legal and technical, CIPP/E certified | €50,000 to €85,000 |
| GRC | Risk management, compliance with ISO 27001 and NIS2, audits | Auditor or consultant, CISA or CRISC certified | €50,000 to €90,000 |
| Security architect | Designs secure architectures and selects technical solutions | Senior technical expert, systems-level view | €70,000 to €110,000 |
How to assess a CISO candidate without being technical
The CISO is the most strategic cyber hire. They report to the board and their profile must be as managerial as it is technical. Questions worth asking in an HR interview:
- How have you presented your security budget to the board? Assesses their ability to communicate with non-technical people.
- Describe a security crisis you have handled. Assesses composure and method.
- How do you keep up with new regulations? Assesses their monitoring and regulatory awareness.
- What is your view of our organisation’s cyber maturity? Assesses their ability to analyse quickly.
A good CISO speaks the language of the board before speaking the language of engineers. If your candidate cannot explain their role in business terms, that is a warning sign.
Cyber certifications: which ones actually matter
| Certification | Level | For which profile |
|---|---|---|
| CISSP | Expert | CISO, architect, the international reference |
| CISA | Experienced | GRC, auditor, governance oriented |
| OSCP | Technical | Pentester, the most recognised offensive credential |
| ISO 27001 Lead Auditor | Experienced | GRC, CISO, compliance oriented |
| CIPP/E | Experienced | DPO, the European data protection reference |
| CompTIA Security+ | Junior | Entry level, tier 1 SOC |
The profiles to avoid
- The expert in everything with no speciality
- The pure technician with no business perspective
- The certified candidate with no practical experience
- The CISO who cannot talk to the board
Hire better with the CyberMasterClass Talent
90 minutes to understand cyber roles, assess candidates and hire with judgement. Designed for non-technical HR professionals.
Get the next publications.
One analysis per publication on cyber governance, resilience and compliance.
Take action in 90 minutes
Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.
See the masterclasses