What should you ask a Cybersecurity Recruitment Agency before you sign?

Posted by Iwan Robertson - 19/08/2026

How many agencies got in touch the week your last role went live?

Three? Six? More, if the role was posted publicly and the job title had the word "security" anywhere near it.

They will all have said roughly the same thing. Specialists in cyber. Strong network. Some placements you have never heard of at companies you have. And you will have had about twenty minutes to work out which of them is actually going to help.

The problem is not that agencies lie. Most of them do not. The problem is that "cybersecurity recruitment" describes at least three completely separate markets, and almost nobody is genuinely good at all of them. Sorting that out is on you, and it happens in a conversation before anything is signed.

So here are the questions worth asking. They are not clever, and that is deliberate. The useful ones rarely are.

Let's Dive In!

 

"Which part of the Security market do you actually work in?"

Ask this first and listen to the shape of the answer, not the content.

Security splits into practitioners (Security Engineers, SOC Analysts, Pen Testers, Cloud Security), Leadership (CISOs, Heads of Security, GRC), and Commercial (the people who sell, market and retain the software). Different networks, different candidate motivations, different interview processes. An Agency that has genuinely built a network in one of those has usually done it at the expense of the others.

An honest answer names one, maybe two. "All of it" is a marketing answer.

This one question does most of the work, because it tells you whether you are talking to someone who understands their own business.

 

"What have you placed in the last six months?"

Not what they can place. What they did place.

You are listening for specificity. Role, Stage of Company, roughly how long it took, what made it hard. Someone who has done the work tells you about the awkward bit - the candidate who nearly took the counter-offer, the brief that had to change halfway through. Someone who has not will talk in categories.

You do not need a reference list at this stage. You need to hear that they have actually been in the room.

 

"Explain what makes selling security different."

This is the one that separates people fastest, and you can ask it without sounding like you are setting a test.

Anyone who has genuinely worked commercial roles at Security Vendors will go somewhere concrete quickly. The proof of concept that sits in the middle of the sales cycle. The security questionnaire that arrives at exactly the wrong moment. The fact that your buyer has been trained, professionally, to be suspicious of the thing you are saying. The way a CISO and a CTO care about different risks and need different conversations.

If the answer stays at "security buyers are more technical", the network probably is not there.

 

"Who is actually going to work on this?"

The person pitching is often not the person sourcing. That is not sinister, it is just how Agencies are structured, but you should know it before you sign rather than three weeks in when the emails start coming from a name you have not met.

Ask who runs the search day to day, how much of their week it gets, and how many other roles they are carrying. The last one is the question people forget.

 

"What does your process look like, in writing?"

How they screen.

What a first shortlist looks like and roughly when it lands.

How often you will hear from them when nothing is happening, which is when communication usually goes quiet.

What they do if the first slate misses.

That last point matters more than it sounds. Every search has a version where the first shortlist is wrong. The difference between a good Agency and a bad one is entirely in what happens next.

 

"What are your Terms if this goes wrong?"

Fee model, Rebate or Replacement terms, Exclusivity, and what happens if you end up hiring someone they only lightly touched.

None of this is awkward before you start. All of it is awkward later, when there is a candidate on the table and a start date being discussed. Get it done early and it stops being a conversation you have to have.

 

"What would you tell me that I do not want to hear?"

The best answer we ever get to this from the other side of the table is a client saying it back to us.

An Agency that has never talked a client out of a role, or out of a sequence, or out of a salary band, is not advising you. They are taking the brief. Those are different jobs and only one of them is worth a fee.

 

One more, quietly

Ask whether they would refer you elsewhere if this is not their market.

We say no to technical security roles fairly often. Security Engineers, SOC, Offensive Security, GRC, Cloud Security, CISO Search - all of that belongs with a Technical Security Specialist, and there are good ones. We recruit the Commercial team that sells the software, which is a different network built for a different reason.

An Agency that can tell you where they stop is usually telling you the truth about where they start.

None of this takes long. Twenty minutes on a call, most of it. The alternative is finding out in month two, having spent a quarter and a fair bit of your own credibility internally.

 


 

If you want the longer version, we have written up the whole selection process - the three markets, what a bad choice costs, and how to run the comparison properly - here: how to choose a cybersecurity recruitment agency.

And if you are weighing up a commercial hire at a security vendor right now, book a call. We will tell you fairly quickly whether it is one for us.

 

Iwan Robertson

Iwan Robertson

Global Business Development Manager

Get in touch

Select who you are from the dropdown menu

Fill out the form and we'll be right back with you.

Ready for go-to-market growth without limits? Or looking to accelerate your career in a role that empowers you to unleash your potential? Unlock game-changing opportunities – connect with Strive today.

Let’s Talk