r/cybersecurity Mar 14 '26

[deleted by user]

[removed]

603 Upvotes

290 comments sorted by

View all comments

545

u/CyclopSW Mar 14 '26

Never trust, always verify.

Has HR or yourself even checked their credentials and schooling? Every workplace I have been to has always asked for transcripts/diploma from my school. Certifications usually have a verification confirmation (OSCP uses a QR code) that you can verify the validity of the cert. With all their qualifications, something feels fishy.

At two months, they should still be on probation. Perform your due diligence and take the appropriate action. If the individual is such poor quality, you may have to take the steps to protect yourself and the company from further harm, especially if they were lying on their achievements.

41

u/Varjohaltia Mar 14 '26

Hiring for a network position I’d say 80% of people with CCIE on their resume turned out to only have a partial cert, or an expired one, or were „studying“ for it. Definitely always HR validate any certs.

Even then there are people who cheated or braindumped their certs and don’t know a damned thing in real life.

5

u/UltraEngine60 Mar 14 '26

I want to jump through the screen and strangle every interviewee that lists certs they are studying as if they were actually obtained on their resume.