Why pre-screen offensive security specialists before the technical interview
Two things separate specialists in this field and neither is technique. The first is authorisation discipline: scope, rules of engagement and written permission are absolute, and someone casual about them creates legal exposure for you. The second is remediation, because a report full of criticals that nobody fixed has bought a document rather than security. A short screen tests both, along with a real finding they can describe.
What actually matters when screening Offensive Security Specialist candidates
- 01
Technical depth
Probe hands-on command of adversary emulation: Cobalt Strike or Mythic C2 profiles, AD abuse paths (Kerberoasting, ADCS ESC1-8), EDR evasion, and custom loader development.
- 02
Real incidents and findings
Ask for real engagements: full-scope red team ops, purple team exercises, TIBER-EU or CBEST assessments, initial access achieved, and objectives such as domain admin or crown jewel access.
- 03
Risk judgement
Test how they scope risk on live production targets: rules of engagement, deconfliction with the SOC, avoiding data destruction, and prioritising findings by exploitability versus theoretical severity.
- 04
Getting things fixed
Check how findings become fixes: attack narrative reports, MITRE ATT&CK mapping, detection engineering handoff to blue team, and retesting closed gaps after remediation.
Pre-screening questions to ask Offensive Security Specialist candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Findings that were fixed
3 questions01Can you explain a situation where you identified and exploited a vulnerability during an authorised assessment?
Listen forA specific finding with the reasoning that led to it and what the client did afterwards to remediate.
Findings described with no remediation outcome, or work performed outside an authorised engagement.
02What experience do you have with red team operations, and how do they differ from penetration testing?
Listen forThe distinction understood clearly, with objectives and detection testing as the point rather than vulnerability counts.
The two conflated, or red team work described as a longer penetration test.
03What experience do you have with social engineering within authorised engagements?
Listen forConsent and staff welfare considered, with findings framed as a process failure rather than blaming individuals.
Individuals named in reporting, or social engineering conducted without explicit written authorisation.
Depth beyond tools
4 questions04Can you describe your experience with scripting in a security context?
Listen forTooling they wrote themselves to solve a specific problem, showing capability beyond running frameworks.
Scripting limited to modifying existing tools, or no code they have written for an engagement.
05What is your experience with penetration testing frameworks and tooling?
Listen forTools used with an understanding of what they do underneath, and manual verification of automated findings.
Scanner output reported as findings, or no manual validation of automated results.
06How familiar are you with network protocols and their role in security?
Listen forProtocol behaviour understood well enough to find issues that no automated scanner would report.
Protocol knowledge limited to what tools display, or findings that all came from automated scans.
07Can you describe your experience with wireless network assessments?
Listen forWireless testing with the physical and legal boundaries respected, including not testing neighbouring networks.
Testing that would capture traffic from networks outside the engagement scope.
Scope and authorisation
2 questions08How do you ensure ethical and legal considerations are met during assessments?
Listen forWritten authorisation and rules of engagement treated as absolute, with a stop-and-ask rule for anything outside scope.
Scope treated as flexible, or testing conducted on authorisation given verbally.
09How do you assess whether an organisation's detection capability would catch an intrusion?
Listen forDetection testing agreed with the client as an objective, with findings shared to improve monitoring afterwards.
Evasion pursued as a personal objective, or detection gaps found and not fed back to the defensive team.
Moving resistant teams
3 questions10How do you prioritise remediation after identifying multiple critical vulnerabilities?
Listen forPrioritisation by exploitability and exposure with practical fixes proposed, not just a severity list.
Findings handed over ranked by severity score, with no view on what to fix first.
11How do you conduct post-assessment reporting and stakeholder communication?
Listen forReports written so a developer can reproduce and fix, with a re-test to confirm remediation.
Reports that are tool output with severity ratings, or no re-test after fixes are claimed.
12How do you handle situations where recommended changes face resistance?
Listen forThe business constraint understood with a workable alternative offered, and the residual risk documented.
Resistance escalated as negligence, or risk accepted informally with nothing recorded.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical depth
35%5Names specific tooling and tradecraft, explains payload development and OPSEC-safe C2 configuration without reciting generic pentest checklists.
Real incidents and findings
30%5Walks through named engagements end to end, from phishing pretext to objective, including detections triggered and blue team response observed.
Risk judgement
20%5Sets clear rules of engagement, halts when scope is ambiguous, and ranks findings by realistic attack chains rather than raw CVSS.
Getting things fixed
15%5Produces reports engineers act on, maps techniques to ATT&CK, and can evidence detections or controls built as a direct result.
A report full of criticals that nobody fixed bought a document rather than security. A one-way video screen asks about a finding nobody remediated.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for this role take?
Fifteen minutes across eight to ten questions, answered async. Enough to establish engagements they ran, test their technical depth, and check their authorisation and reporting discipline.
What should I check alongside the screen?
Certifications and references for engagement conduct. Ask referees specifically about scope discipline and reporting quality, which matter more than technique for a role with this level of access.
Evaluating answers
What is the strongest signal when screening this role?
A finding nobody fixed and what they did about it. Specialists who care about outcomes escalate and re-test. Anyone who delivers a report and moves on has sold an exercise rather than an improvement.
How do I judge their authorisation discipline?
Ask what they do when they find a path outside the agreed scope. The answer you want stops and asks. Anyone who continues because it was interesting is a legal problem waiting to happen.
























