Technical depth
Check fluency in OIDC, OAuth 2.1, SAML and SCIM flows, plus hands-on depth in Okta, Entra ID or PingFederate, FIDO2 passkeys, and NIST 800-63 assurance levels.
Evidence to listen for
- Command of the specific attack surface, tooling, and controls the role covers
- Understands how the underlying system works, not just how the tool reports on it
- Can explain an attack or control chain end to end
- Distinguishes what they found themselves from what a scanner flagged
Five-point scoring guide
Tool operator only; no understanding of the systems underneath.
Runs tooling but cannot explain findings or how the attack works.
Solid working knowledge; depth thins outside familiar tooling.
Strong command of the domain; explains attack and control chains clearly.
Explains token flows, claims mapping and PKCE trade-offs precisely, and names directory, federation and MFA products they configured themselves.