
Job postings often list specific technology proficiency requirements that applicants must meet or exceed to qualify for an interview. According to HR lore, this “best practice” is meant to pre-emptively filter out those applicants who simply won’t be qualified based on the unique needs of the open position. When job seekers learn that a specific role requires “X years using tool Y to perform function Z,” they can remove themselves from consideration, thereby not wasting everyone’s time … their own, the HR screener’s, and the hiring manager’s.
For example, here’s an entry that showed up on LinkedIn for a “Security Engineering Principal” position for a company located a few towns north of me. Under the post’s “What we’re looking for …” section, the company requires:
• Knowledge of MySQL/Postgres (or other relational database technologies).
• Ability to code using current security principles and best practices.
• Ability to in the following and use frameworks: React, Next.js, Python, Node.js (or other web development technologies). [sic]
I’m assuming that last bulleted entry meant the ability to code in the listed frameworks, but I could be wrong. I’m neither a developer nor an engineer, so maybe they meant the ability to dance in Node.js. Honestly, that wouldn’t surprise me given some of the weirder developers I’ve known.
I don’t necessarily object to job posters listing specific technology proficiencies for a given role. If written accurately, these can be a useful way to warn folks – like me! – that we likely wouldn’t be immediately productive in the role, assuming we made it through the interview at all. Doesn’t mean that an applicant couldn’t do the work after some training or wouldn’t be an excellent “cultural fit.” Just means that they probably can’t breakdance to Python on day one (or whatever the expectation is).
That said, I believe this “best practice” is too narrowly focused. By focusing solely on specific technologies used in the worker’s primary function, job posters are missing important indicators that suggest that an applicant might be an unintentional security risk. From a Security Awareness perspective, this is dangerous. Applicant Bob might be the best Next.js square dancer that ever do-si-do’d, but if Bob can’t understand or follow urgent cybersecurity instructions, Bob is highly likely to unintentionally cause a security incident because he’s incapable of correctly executing required actions.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543