Technical depth
Check command of the EU AI Act risk tiers, GDPR Article 22, NIST AI RMF and ISO 42001, plus how they read model cards, DPIAs and vendor training data clauses.
Evidence to listen for
- Command of the specific attack surface, tooling, and controls the role covers
- Understands how the underlying system works, not just how the tool reports on it
- Can explain an attack or control chain end to end
- Distinguishes what they found themselves from what a scanner flagged
Five-point scoring guide
Tool operator only; no understanding of the systems underneath.
Runs tooling but cannot explain findings or how the attack works.
Solid working knowledge; depth thins outside familiar tooling.
Strong command of the domain; explains attack and control chains clearly.
Cites specific articles and control frameworks from memory, and distinguishes high risk from limited risk classification with concrete system examples.