What Candidates Really Think About Your Careers Page
I've spent the last month reviewing dozens of corporate careers pages for a client who's struggling to hire penetration testers. And Christ almighty, the state of some of them.
This one tech firm, big name, you'd recognise them, had buried their security roles three clicks deep under a bizarre taxonomy that sorted jobs by office location rather than function. They were wondering why they'd had zero applications for a £140K role that should've been snapped up in days.
I've been placing cybersecurity professionals across the Atlantic for six years now. The market's never been hotter. Yet I'm watching companies self-sabotage their hiring efforts with careers pages that feel designed by committee in 2018 and never updated since.
Want to know what candidates are actually thinking when they hit your careers section? I asked the last 17 CISO and security architect candidates I placed. Their unfiltered feedback might make uncomfortable reading.
The Seven-Second Rule is Dead (It's Now Three)
The seven-second rule was already a stretch. In 2026, with senior security candidates receiving 20+ recruiter messages daily, you've got closer to three seconds before they move on. The cybersecurity candidates I place, particularly those with clearance levels, are receiving upwards of 20 outreach messages daily.
One security architect I placed last month at a London-based fintech showed me his LinkedIn inbox. 94 unread recruiter messages. Ninety-bloody-four.
These people aren't leisurely browsing your careers page with a cup of tea. They're scanning it at frightening speed on the Tube between Westminster and Bank. If they can't find what they need in three seconds, they're gone.
So what are they actually looking for?
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
The Real Hierarchy of Candidate Needs
Forget what HR thinks matters. Here's what my candidates consistently check first:
-
Salary range, Not seeing one is an instant close-tab for 70% of the security professionals I work with. The talent shortage in our space means they can afford to be choosy.
-
Remote/hybrid clarity, Post-COVID, this remains non-negotiable. Be crystal clear. "Hybrid" means different things to different companies. Is it two days a month in office or three days a week?
-
Security clearance requirements, For SC/DV roles, candidates want to know immediately if they qualify. Don't bury this on page three of the job spec.
-
Tech stack specifics, Vague platitudes about "cutting-edge technology" make security folk roll their eyes. Name the actual tools, frameworks and environments.
-
Cultural red flags, Yes, they're actively looking for these.
That last one deserves unpacking.
The Red Flags Security Candidates Are Scanning For
Candidate after candidate tells me they're specifically scanning careers pages for warning signs. Here's what sends them running:
1. Corporate Waffle-Speak
Any mention of "rock stars," "ninjas," "unicorns" or other Silicon Valley nonsense terms is poison to serious security professionals. This language signals to them that you don't understand the gravity of security work.
Equally toxic: careers pages dripping with corporate jargon about "synergistic culture" and "innovation DNA." Security people deal in precision and clarity. Fluff language suggests an organisation that might gloss over security concerns with marketing-speak.
2. The Rigid Application Process
I recently lost a top-tier candidate for a £190K CISO role because the company insisted on a 45-minute initial application form that couldn't be saved mid-completion. In what universe does someone earning that level of compensation have time for that?
Many security candidates tell me they judge a company's overall technical competence by how smoothly their application process works. Clunky, outdated forms that don't work on mobile? They assume your internal security tools are equally outdated.
3. Security Theatre in Job Descriptions
This kills me. Companies list every security certification under the sun as "required" when they're actually willing to compromise. One client insisted on CISSP + OSCP + cloud security certs in their listing, then hired someone with only CISSP and good cloud experience.
Security professionals can spot inflated requirements instantly. They assume you either don't understand what you actually need, or worse, that you're planning to load one person with the work of three.
4. The Missing Security Section
If you're hiring security staff but your careers page doesn't include a dedicated security section highlighting your security programme and commitment, you're dead in the water. These candidates want to see that security isn't just a compliance checkbox but a core value.
Your careers page is actually being treated as a proxy for your security maturity.
What Actually Works (Based on Real Placements)
The most effective careers pages I've seen for attracting top security talent share these characteristics:
Transparency as Default
The companies winning the security talent war are the ones putting salary ranges front and centre. Not ranges so wide they're meaningless ("£70K-£150K" tells nobody anything useful), but realistic 15-20% bands.
Transparency extends to the interview process too. My most successful placements happen when companies outline exactly what their interview process looks like, including who the candidate will meet and what type of technical assessment to expect.
Technical Credibility Signals
Security people want to work with other security people who know their stuff. The best careers pages include video snippets or quotes from the actual security team discussing real challenges they're solving.
I placed three security engineers at a payments company that included a simplified (sanitised) version of their security architecture diagram on their careers page. Bold move that paid off, it demonstrated technical sophistication without exposing vulnerabilities.
Day One Clarity
What will the first 30/60/90 days look like? Security professionals want to know if they'll be walking into a disaster recovery scenario or a mature programme needing refinement.
One defence contractor client explicitly states on their careers page: "Your first two weeks will be dedicated to accessing systems, understanding our threat model, and meeting key stakeholders. We don't expect immediate contributions, we value proper onboarding."
This kind of clarity has dramatically improved their offer acceptance rates.
The Mobile Experience Is Non-Negotiable
Your fancy careers page might look great on a desktop, but if it's rubbish on mobile, you're losing candidates.
Why? Because the initial browse almost always happens on a phone. The candidate might switch to desktop for the actual application, but that first crucial impression, when they're deciding whether your company is worth their time, that's happening on a 6-inch screen, probably while they're doing something else.
I've watched candidates dismiss companies during our placement calls because they couldn't easily view the job details on their phone. That's it. Decision made in seconds.
Let Candidates Self-Select Out
This might sound counterintuitive, but the most effective careers pages I've seen don't try to appeal to everyone. They're deliberately polarising.
A defence tech firm I work with regularly includes unvarnished statements about their expectations: "We value deep work. Expect to spend 4+ hours daily in focused, uninterrupted security analysis." Another states: "Our security team operates with limited resources against sophisticated threats. We need problem solvers who thrive under constraint."
These statements send some candidates running. Good. Better to have them self-select out before wasting everyone's time.
The Bottom Line (Literally)
In the current security talent market, your careers page is a critical hiring tool that's either working for you or costing you candidates.
I've lost count of how many times I've had to convince exceptional candidates to overlook terrible careers pages because I know the company is actually solid. That's a failure of employer branding, and it costs organisations their first-choice candidates.
If you're struggling to attract security talent, pull up your careers page right now on your phone. Set a timer for three seconds. What stands out? What questions remain unanswered? What impression are you actually making?
Because I guarantee that's what candidates are doing. And they're far less forgiving than I am.

