Why pre-screen security awareness trainers before the interview
The usual programme is an annual module people click through and a phishing test that embarrasses whoever falls for it. Neither improves security, and the second makes staff hide their mistakes. Trainers worth hiring measure reporting rates rather than failures, and treat a click as a system problem. A short screen asks how staff who fail a simulation are treated.
What actually matters when screening Cybersecurity Awareness Trainer candidates
- 01
Subject and technical command
Check they can explain phishing, BEC, MFA fatigue and social engineering accurately, and name frameworks they map training to: NIST 800-50, ISO 27001 Annex A, SANS Security Awareness Maturity Model.
- 02
How they actually teach
Probe how they run sessions: onboarding inductions, lunch-and-learn formats, tabletop exercises, gamified modules in KnowBe4 or Proofpoint, and how they adapt content for developers versus finance staff.
- 03
Group management and safeguarding
Assess control of mixed rooms including sceptical engineers and senior executives, plus handling of staff who disclose real incidents or personal data mid-session.
- 04
Progress and communication
Look for metrics they owned: phish-prone percentage, click and report rates, completion rates, time to report, and how they briefed leadership or auditors on trends.
Pre-screening questions to ask Cybersecurity Awareness Trainer candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Behaviour changed
3 questions01Can you describe a time when training measurably changed user behaviour?
Listen forA measured change such as improved reporting or fewer risky actions, with before and after data.
Behaviour change assumed from completion rates, or no measurement beyond attendance.
02What experience do you have creating and delivering awareness programmes?
Listen forProgrammes they built and ran, with audience size and the formats used described concretely.
Delivery of purchased content only, or no involvement in designing the programme.
03Can you discuss your experience with phishing simulations?
Listen forSimulations run with a fair difficulty level, and results used to improve controls not to punish.
Deliberately cruel lures used, or results circulated to managers as a discipline matter.
Built for the audience
3 questions04How do you tailor training for different audiences within an organisation?
Listen forContent differentiated by the risks each group faces, with technical staff given real depth.
One module for everyone, or executives given the same content as general staff.
05What methods do you use to keep sessions engaging?
Listen forRealistic scenarios and discussion rather than slides, with relevance to people's actual work.
Engagement pursued through entertainment alone, or sessions built around policy recitation.
06How do you incorporate real incidents into your training?
Listen forRecent and relevant cases used, including internal near misses shared without blaming anyone.
Examples years out of date, or internal incidents used in ways that identify individuals.
Simulations used fairly
3 questions07How do you measure the effectiveness of security training?
Listen forReporting rate and time to report tracked, alongside click rate, with trends followed over time.
Effectiveness measured by completion, or click rate treated as the only outcome.
08What metrics do you report to stakeholders on training programmes?
Listen forMetrics tied to risk reduction, presented honestly including where results did not improve.
Only favourable metrics reported, or measures chosen because they look good.
09How do you keep your training materials current?
Listen forMaterial updated as attack techniques change, with threat intelligence feeding into content.
Content unchanged for years, or examples describing attacks that are no longer common.
Reporting improved
3 questions10How do you handle resistance to security policies or training?
Listen forFriction taken seriously, with unworkable controls fed back to security rather than defended.
Resistance treated as non-compliance, or workarounds never reported back as a control problem.
11What strategies do you use to build a security-aware culture?
Listen forReporting made easy and rewarded, so people raise mistakes early rather than concealing them.
Culture pursued through campaigns, or mistakes handled in ways that discourage reporting.
12What role should management play in security awareness?
Listen forLeaders expected to complete training and model the behaviour, with exemptions challenged.
Executives exempted routinely, or management engagement limited to endorsing a campaign.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Subject and technical command
30%5Explains current attacker tradecraft correctly and ties each module to a named control, standard or audit requirement without prompting.
How they actually teach
30%5Describes specific session designs and role-tailored content, with concrete examples of reworking material after learners disengaged.
Group management and safeguarding
25%5Handles resistance without shaming, escalates disclosed incidents to the security team properly, and keeps large virtual cohorts participating.
Progress and communication
15%5Quotes before and after numbers from campaigns they ran and links behaviour change to specific training or nudge interventions.
Annual modules everyone clicks through change nothing. A one-way video screen asks what behaviour moved.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for this role take?
Ten to fifteen minutes across eight to ten questions, answered async. Enough to establish behaviour they changed, test their training design, and hear how they use simulations.
How technical does this trainer need to be?
Enough to explain current attacks accurately and answer questions from technical staff. Training built on outdated examples loses credibility with exactly the audience that matters.
Evaluating answers
What is the strongest signal when screening this role?
How staff who fail a simulation are treated. Effective trainers use it as a teaching moment and measure reporting. Anyone who names and shames will make people conceal real incidents.
How do I judge their measurement?
Ask what improved. Real answers include the reporting rate for suspicious messages, which matters more than the click rate. Completion percentages measure attendance, not security.
























