Vetting Writer Credentials at a Cybersecurity Content Agency
Real vetting means testing whether writers understand security, not just write about it polished.

Hiring a cybersecurity writer is genuinely hard, and most agencies are doing it wrong. The standard process (post a job, collect portfolios, pick the most polished one) produces writers who sound credible until a security practitioner actually reads their work. This piece lays out what a real vetting process looks like and why each step earns its place.
What the buyer environment demands from security content today
Security buyers are not a forgiving audience. They are, in fact, some of the most skeptical readers any piece of content will ever face. And there are more of them than there used to be.
Buying committees in cybersecurity deals have grown meaningfully over the past few years, with more than nine stakeholders expected in the average deal by 2026. That number includes security architects and SOC leads who will catch a technically soft claim immediately, alongside CFOs and procurement leads who need the same content to make sense without a decoder ring.
B2B buyers now consume an average of 13 pieces of content before making a purchase decision, and most of that content comes directly from vendor websites. Vendors are carrying almost all of the credibility burden. A generic white paper or a blog post full of vague threat language does not just fail to convert. It actively signals to a technical reader that the company behind it doesn't really understand the space.
The practical implication is this: the writer who can produce technically precise content for a security architect and genuinely accessible framing for a CFO, in the same piece, is exceptionally rare. Vetting has to match that difficulty level.
Why a portfolio review alone tells you very little
A polished portfolio is unreliable evidence of capability. A 2025 Content Marketing Institute survey found that 72% of hired writers use AI tools, often without disclosing it. Cybersecurity content is a specific risk area here. Research using transformer models found that AI-generated false security reports fooled cybersecurity experts in controlled studies. Meaning: output can look authoritative while being technically wrong.
Even setting AI aside, a portfolio review has always had a structural problem.
- It shows the finished piece, not the first draft.
- Published clips may reflect a skilled editor's corrections, not the writer's original accuracy.
- Voice and structure come through clearly. Whether the writer understands why a particular threat model matters does not.
A portfolio review catches what a writer sounds like, nothing more. Whether the writer understands how a defensive control actually works, or where a common vendor claim falls apart the moment a practitioner looks at it closely, stays hidden. Think of it like judging a chef by their Instagram photos — the plating is flawless, but you still don't know whether they can actually cook.
Agencies that conflate "writes clearly about security" with "understands how security actually works" find out about the gap when a client's technical reviewer flags errors in delivered work. By then, the damage is already done.
Which certifications carry real signal and how to verify them
Credentials are a starting point. Some carry substantially more signal than others.
CISSP requires at least five years of cumulative paid experience across two or more of eight security domains. With over 165,000 holders worldwide, it signals sustained domain engagement. ISC2 maintains a public verification tool where any certification can be confirmed by name or member number. Make submission of a verifiable credential ID a mandatory application step, not an optional one.
OSCP is the stronger signal for writers covering offensive security or penetration testing. Candidates actually compromise live systems during the exam. CEH, by comparison, is more concept-based. Both can be verified through their respective issuer portals (EC-Council for CEH). CompTIA has its own verification portal for Security+.
CompTIA Security+ has no experience prerequisite. It is a reasonable entry-level marker, insufficient on its own for technical depth assignments.
A few principles worth holding:
- Active certifications matter more than lapsed ones. CISSP and CEH each require continuing education credits every three years. A current certification signals the writer is still engaging with the field as it changes.
- One certification plus three years of applied practice outweighs five certifications with no operational background.
- Credentials narrow the field and leave the rest unsettled.
Also worth noting: writers with genuine practitioner backgrounds are rare because the global cybersecurity talent shortage runs to more than 4.7 million professionals, per the 2024 ISC2 Cybersecurity Workforce Study. Agencies and employers are fishing in the same small pond. Rarity makes credentials worth misrepresenting. Verification is not optional.
Testing technical judgement, not just technical knowledge
Knowing what zero trust architecture is differs from understanding when a vendor's zero trust claim is overstated. A practitioner reader will catch the second problem instantly, where a writer who only knows the definition will reproduce the vendor's framing without questioning it.
Consider the writer who once submitted a piece confidently describing a "next-generation firewall" as something that "uses AI to predict attacks before they happen." It was polished. It was coherent. It was the kind of sentence that a non-technical editor might wave through without a second look. A SOC lead would have stopped reading right there. The sentence wasn't just wrong — it was wrong in a way that announced the writer had never spent an afternoon in an actual security operations environment. The test task caught it. The portfolio review never would have.
Test tasks require genuine editorial challenge, not a simple blog post prompt.
What a useful test task looks like:
- Give the writer a technically dense brief and ask them to make editorial calls. What do they include? What do they flag as contested? What do they leave out because it adds noise rather than clarity?
- Embed a plausible but incorrect technical claim in the source material. See whether the writer catches it, queries it, or reproduces it. This single check tells you more than a full portfolio review.
- Run the output through AI detection and look at structure carefully. Undisclosed AI use on a vetting task predicts undisclosed AI use on client work.
Strong candidates ask questions about the target reader before they write. They want to know who is reading, what that person already knows, and what they are trying to decide. Weak candidates produce technically correct but audience-blind content that a security leader would stop reading after two paragraphs.
The test task also reveals how a writer handles uncertainty, which is the most important signal of all. Do they hedge appropriately where the evidence is thin? Do they fabricate confidence? Do they flag what they would need a subject-matter expert to confirm? That last behaviour, flagging gaps honestly, is a practitioner habit and a rare one.
Reading the writer's track record for audience fit, not just subject coverage
Publication history reveals the kind of reader a writer has been writing for. Trade publications read by practitioners carry a different credibility signal than general technology outlets or content marketing blogs. The publications themselves are a clue.
Cybersecurity content performs well on LinkedIn, generating meaningfully more engagement than on most other platforms. The dominant distribution channel rewards writing that speaks to security practitioners in a register they recognize as peer-level. A writer who has spent their career producing practitioner-facing content has been trained by reader feedback to get that register right. A writer whose background is demand-generation copy has been trained to optimize for something else entirely.
A few checks worth running:
- Ask the candidate to describe a recent piece they are proud of and why. The answer reveals whether they think in terms of technical precision and audience insight, or surface metrics like pageviews and shares.
- Reference checks with editors or clients who commissioned the work are more informative than the writer's own description of it. The reference conversation should specifically probe whether the first draft required significant technical correction.
- A writer accustomed to practitioner audiences handles expert skepticism differently from one who has never faced a reader who will push back. Both are technically literate, or they are not. Only one has been tested by an audience that actually knows the material.
The two writer types that show up in practice are former practitioners who pivoted to writing, and subject-matter-curious journalists who have read deeply but never operated in a security role. Both types can succeed. The vetting challenge is different for each, and conflating them leads to mismatched placements.
What a defensible vetting process looks like end to end
Most agencies run a lighter version of this process, which is why technically credible cybersecurity writers remain rare even among candidates who have cleared standard vetting.
Here is what a complete process covers:
Stage one: baseline screen. Request verifiable credential IDs and employment history showing security-adjacent roles. Remove candidates who cannot provide either before investing further evaluation time. This step alone filters out a significant portion of misrepresented applications.
Stage two: portfolio review with a specific lens. Ask whether the writer makes editorial choices that reflect how a security practitioner thinks about the problem. Look for evidence of judgment, not just competence.
Stage three: paid test task. Include a technical accuracy trap. Require the writer to declare any AI tool use. Assess whether the output would survive a read by the intended audience. Pay for the task. Serious candidates expect it; unpaid tasks attract desperate applicants over qualified ones.
Stage four: structured conversation about the work. Not a conventional interview. A discussion of the specific choices the writer made in the test task and why they made them. This is where genuine practitioner background shows itself most clearly. A writer who operated in the field will talk about tradeoffs, context, and reader expectations, while one who only read about it will talk about the content itself.
Stage five: reference contact. Reach out to a previous commissioning editor or client specifically asking about first-draft accuracy and how the writer handled technical challenges. The word "first draft" matters in how you ask the question. Editors know the difference between a piece that arrived clean and one that required significant repair.
Building practitioner triage into this process at the research and draft stage, not just at final QA, is what separates a defensible workflow from a superficial one. Security practitioners review content for technical credibility before it goes out the door. The vetting of the writer is followed by an ongoing check on the work itself, and that combination produces content a security architect will read and a CFO will understand, in the same document.
The process is demanding. It should be. The readers it is designed to reach are demanding too.


