Why pre-screen cloud engineers before the technical interview
The question that reveals most is whether the estate could be rebuilt from a repository. Manually configured infrastructure works until an account is lost, a region fails, or the person who built it leaves, at which point nobody can reproduce it. Engineers worth hiring know exactly which parts are not in code. A short screen asks what they could not rebuild, which nobody volunteers.
What actually matters when screening Cloud Engineer candidates
- 01
Technical proficiency
Check hands-on depth in a named cloud: VPC and IAM design, Terraform or CloudFormation modules, EKS or GKE clusters, plus CI/CD pipelines they built in GitLab or GitHub Actions.
- 02
Systems and trade-offs
Probe architecture decisions: managed service versus self-hosted, multi-AZ versus multi-region, container versus serverless, and what those choices cost per month in real bills.
- 03
Evidence and rigour
Test how they prove reliability: SLOs, error budgets, dashboards in CloudWatch or Grafana, load tests, and post-incident reviews with measured before and after figures.
- 04
Collaboration and communication
Assess how they work with developers and security: onboarding teams onto platform tooling, writing runbooks, handling on-call handovers, and pushing back on unsafe access requests.
Pre-screening questions to ask Cloud Engineer candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Infrastructure they run
3 questions01Can you discuss a project where you designed and maintained a cloud system?
Listen forAn estate they still operate, with scale described and an account of what they are paged for.
Infrastructure built and handed over, or no operational responsibility for anything they built.
02Do you have experience migrating applications and data to the cloud?
Listen forMigrations completed with cutover and rollback planned, and the data consistency question addressed.
Migrations described as lift and shift with no rollback plan, or data consistency assumed.
03What containerisation technologies do you have experience with?
Listen forContainer platforms operated rather than consumed, with resource limits and failure behaviour understood.
Containers used without resource limits, or orchestration treated as a managed black box.
Defined as code
3 questions04Can you describe your experience writing automation for cloud environments?
Listen forInfrastructure defined as code and version controlled, with an honest account of what remains manual.
Resources created through a console, or automation limited to a few scripts run by hand.
05What is your experience with deployment pipelines in a cloud environment?
Listen forPipelines they built and maintain, with rollback tested rather than assumed to work.
Deployments run manually, or rollback never exercised on a real release.
06Do you have experience with infrastructure and platform service models?
Listen forManaged services chosen deliberately with the operational trade-off understood, not by default.
Managed services assumed to remove operational responsibility, or their limits not known.
Cost and security managed
2 questions07How would you optimise cloud spending and manage cost?
Listen forSpend attributed to teams or services, with a specific reduction they found and implemented.
Cost discovered on a bill, or optimisation described as buying reserved capacity only.
08How familiar are you with cloud security and compliance requirements?
Listen forLeast privilege applied and reviewed, with public exposure of storage and services actively monitored.
Broad permissions granted for convenience, or no monitoring for accidentally exposed resources.
Worked an outage
4 questions09What is your process for identifying and resolving outages?
Listen forA real incident with the timeline described, including what was misdiagnosed on the way to the cause.
Outages described from a runbook, or no incident they personally worked through.
10How do you troubleshoot problems across a cloud platform?
Listen forLogs, metrics and traces used together to isolate a layer, with hypotheses tested rather than guessed.
Services restarted as a first response, or no method for isolating where a fault sits.
11What is your process for keeping cloud infrastructure running well?
Listen forPatching, capacity and certificate expiry all managed proactively rather than after a failure.
Maintenance done reactively, or expired certificates and quota limits discovered during an outage.
12How familiar are you with designing cloud network architecture?
Listen forNetwork segmentation and private connectivity designed deliberately, with routing understood in detail.
Flat networks with public endpoints, or network design copied without understanding the routing.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical proficiency
35%5Names specific services and versions, explains their Terraform module layout, state backend, and how IAM boundaries were scoped per environment.
Systems and trade-offs
25%5Weighs latency, blast radius, and cost with numbers, and cites a trade-off they later reversed after seeing production behaviour.
Evidence and rigour
25%5Quotes concrete metrics (p99 latency, deploy frequency, spend reduced) and describes the monitoring or test evidence behind each claim.
Collaboration and communication
15%5Describes runbooks or internal docs others adopted, and a case where they refused or reshaped a request while keeping the team unblocked.
Manually built infrastructure works until someone needs to rebuild it. A one-way video screen asks what is not in code.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for this role take?
Fifteen minutes across eight to ten questions, answered async. Enough to establish infrastructure they run, test their automation practice, and hear how they handled an outage.
How much should certifications count?
As a floor, not a signal. Cloud certifications show someone learned the service catalogue. Whether they can operate an estate under pressure and control its cost is what the screen must reach.
Evaluating answers
What is the strongest signal when screening this role?
Knowing what is not in code. Engineers who operate real estates can name the manual pieces. Anyone who claims everything is automated has either a very small estate or has not checked.
How do I judge their cost awareness?
Ask what they did about a bill that grew. Real answers describe finding the cause and changing it. Anyone who has never looked at spend will run an estate whose cost doubles without anyone noticing.
























