The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Lock it Down Podcast

Hiring Candidates Based on Practical Skills, Not Just Resumes

Lock it Down Podcast · 2026-07-29 · 10 min

0:00--:--

Key moments - from our scoring

Substance score

53 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber14 / 20
Specificity & Evidence8 / 20
Conversational Craft9 / 20

Security hiring often overweights credentials and certifications while overlooking the traits that predict actual job performance in regulated industries like healthcare and finance. Lucas Lisevsky draws from his experience building scalable tech teams for enterprises and PE-backed firms to argue that individuals demonstrating ownership, accountability, and the ability to navigate ambiguous situations under pressure outperform those with impressive paper qualifications. The key differentiator is how candidates handle situations where safety, security, and data access guidelines exist but real-world application remains unclear - and whether they can propose solutions while understanding business consequences. Lisevsky recommends a specific interview technique called "traveling the timeline," where interviewers present hypothetical decisions, simulate consequences 3, 6, and 12 months forward, and observe whether candidates ask clarifying questions, defend choices logically, or show initiative to reconsider. He also flags an often-overlooked hiring consideration: expanding into new geographies (especially Europe, with GDPR, EU AI Act, and emerging regulations) fundamentally reshapes both the compliance demands and the talent profile needed, which many companies underestimate.

Key takeaways

  • →Certifications and credentials are poor predictors of success in security roles; instead, evaluate candidates' ability to solve problems under pressure and take ownership in ambiguous situations.
  • →Use timeline role-play interviews where you present decisions, simulate forward consequences at 3, 6, and 12-month intervals, and observe whether candidates ask clarifying questions and understand business outcomes.
  • →The minimum acceptable initiative level for hiring is candidates who can actively propose solutions A and B with fully considered tradeoffs, allowing leaders to choose without needing to understand all underlying complexity.
  • →Regulatory complexity (GDPR, EU AI Act, emerging regional compliance) directly shapes both the talent pool available and the specific skills profile needed, yet most companies expanding geographically underestimate this impact.
  • →Supporting hired talent requires progressively increasing accountability and scope of ownership, encouraging candidates to demonstrate initiative by asking whether decisions can be revisited or modified based on new information.

Guests

Lucas Lisevsky

Topics in this episode

EU AI ActGDPRProblem-solving under pressureLL InformaticsBehavioral interview techniquesTimeline role-play methodAccountability and ownership in hiringCompliance complexity across jurisdictionsInitiative levels in team development

Questions this episode answers

What's a better predictor of security hiring success than certifications?

Demonstrating practical problem-solving ability, accountability, ownership mindset, and the capacity to work through ambiguous situations where guidelines exist but real-world application is unclear - combined with understanding business consequences of technical decisions.

How can security leaders identify if a candidate can solve problems and present solutions during interviews?

Use timeline role-play: present a hypothetical decision, then simulate consequences at 3, 6, and 12 months forward, observing whether the candidate asks clarifying questions, defends their choice logically, shows understanding of tradeoffs, and demonstrates initiative to revisit decisions with new information.

What hiring mistake do security leaders make in well-established corporations?

Over-focusing on credentials and certifications rather than evaluating whether candidates can execute under pressure, stay accountable when data or patient safety is at stake, and navigate situations where security guidelines exist but require practical judgment to implement.

Why does geographic expansion affect the security talent profile companies need?

Expanding into new regions like Europe introduces different regulatory regimes (GDPR, EU AI Act) that raise compliance complexity, which directly shapes both which talent is available in that market and what specific skills and compliance knowledge must be hired for.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains some substantive ideas - particularly the time-travel interview technique and the distinction between credentials vs. practical problem-solving under pressure - but these insights are undermined by repetitive circling, incomplete thoughts, and filler. Lucas frequently restarts sentences, loses his train of thought ("from the book, which it just escaped my brain now"), and restates the same core point multiple times without deepening it. A 10-minute format with a sponsor break leaves little room for density, and the conversation doesn't accumulate novel claims per minute.

people um, who can still get uh, locked and um, be unable to actually uh, execute properly under pressure
individuals with specific traits of ownership and accountability who tend to understand uh, that practical problem solving under pressure is uh, more important uh, than, than having those certificates

Originality

10 / 20

The core argument - hire for practical skills and ownership over credentials - is well-trodden in tech hiring discourse and not contrarian or particularly fresh. The time-travel interview technique is the most original element but is under-explained and presented as a personal innovation without deeper structure or evidence. The final point about compliance shaping talent pools is reasonable but brief and intuitive rather than counterintuitive.

we tend to focus too much on credentials and especially certification
I play a Bit of a role play during my interviews and I recommend to my other colleagues here at LLI to do this exactly the same. What we do is we travel the timeline

Guest Caliber

14 / 20

Lucas Lisevsky is a founder/CEO of a consultancy with stated experience building tech teams in regulated industries (healthcare, finance, PE), which is relevant to the topic. However, the transcript provides limited evidence of operating at significant scale or achieving measurable outcomes. He speaks from experience but remains somewhat vague about the scope and impact of his work, and his rambling delivery undermines confidence in his expertise.

CEO and founder of LL Informatics, a consultancy that builds and rescues complex systems for enterprises and PE backed firms
my background is in building uh, scalable tech teams for enterprises in highly regulated industries such as healthcare, finance, private equity

Specificity & Evidence

8 / 20

The episode lacks concrete examples, named companies, specific metrics, timelines, or quantified outcomes. References to GDPR, EU AI Act, and clinical trial data are regulatory name-drops rather than case examples. The interview technique is described but not illustrated with a real candidate interaction or outcome. The advice remains largely abstract and anecdotal ('in my practical experience') without hard evidence.

we see gdpr, we see EU act, right, AI act
in situations where um, there is um, an aspect of data leakage importance or prevention or sort of a situation where in clinical trials patient data is on the line

Conversational Craft

9 / 20

Jordan's questions are straightforward setup questions that allow Lucas space to answer, but there is minimal pushing, follow-up, or productive friction. When Lucas loses his train of thought or becomes vague (e.g., the forgotten book reference, the unclear explanation of 'lockage'), Jordan does not press for clarity or specific examples. The host accepts hand-wavy answers and moves to the next topic rather than drilling down, resulting in a soft interview rather than a substance-driven conversation.

Kind uh, of getting into the meat of the topic today. What common pitfalls do you think security leaders fall into when hiring?
And you touched on this a little bit in your answer. But what actually predicts success in technical and security adjacent roles?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B74%
  • Speaker A22%
  • Speaker C3%

Most-used words

security18magazine6today5understand5consequences5leader5thank4decision4practical4leaders4data4level4lock3lucas3experience3hiring3

Episode notes

Listen to Lukasz Lazewski, CEO and Founder of LLInformatics, share how security leaders can learn to make insightful hiring decisions.

Full transcript

10 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello and welcome to Lock it down with Security magazine where we talk about all aspects of security from leadership, security posture, risk management and much more. I'm Jordan Elger, Managing editor at Security Magazine Today. We're here with Lucas Lisevsky, CEO and founder of LL Informatics, a consultancy that builds and rescues complex systems for enterprises and PE backed firms. Welcome Lucas.

Speaker B: Hey Jordan. Pleasure to be here. Thank you.

Speaker A: Thank you so much for coming and getting things started. Could you talk about your background and experience within the security industry?

Speaker B: Right, so my background is in building uh, scalable tech teams for enterprises in highly regulated industries such as healthcare, finance, private equity. Um, within these industries it's uh, you know, security is baked in into every architectural and hiring decision. Uh, and that has given me a practical perspective of what secure auditable software actually requires from people uh, that are building it.

Speaker A: Kind uh, of getting into the meat of the topic today. What common pitfalls do you think security leaders fall into when hiring? Uh, are there qualities that sort of look good on paper that don't always correlate with practical success when someone's actually been hired?

Speaker B: That's a great question. I think especially in the well established companies in the corporate world in scale apps we tend to focus too much on credentials and especially certification. Um, in my practical experience we see people um, who can still get uh, locked and um, be unable to actually uh, execute properly under pressure. Uh, especially in situations where um, there is um, an aspect of data leakage importance or prevention or sort of a situation where in clinical trials patient data is on the line and you need to have a consent every few weeks uh, to check and understand that um, this is in line. Uh, on the other hand, individuals with specific traits of ownership and accountability who tend to understand uh, that practical problem solving under pressure is uh, more important uh, than, than having those certificates tend to ah, work out better in those organizations. That's my experience.

Speaker A: Yeah, absolutely. And you touched on this a little bit in your answer. But what actually predicts success in technical and security adjacent roles?

Speaker B: Mhm. So the strong signal is how someone will handle it, is uh, how they will um, how they will work in a situation when it's uh, ambiguous because um, in what we do, safety, uh, security, data access, those things are really clean and well defined. Obviously there are guidelines, there's gdpr, there's um, a bunch of other um, regulatory um, items that define this. But at the same time uh, I see people like out of fear or maybe you know, unable to make a decision on their own, uh, and, and unable to continue get stuck with a process and, and nothing really comes out of it till someone passed them at the back. And yeah, maybe it's a matter of. Let me reframe that. Maybe it's a matter of how people are actually approaching, um, situations where they need to document everything and they feel they are personally responsible for safety of that information which locks them in place instead of knowing, having some checklists and ideas how to modify their existing SOP and their operational work on day to day work to not get themselves in the kind of lockage that I described. Um, yeah, so the one who understands business consequences and business outcomes out of the working code, out of the working security, are the ones who will uh, perform the best, basically.

Speaker A: So once you sort of parse through as a security leader, you parse through these candidates and you figure out which ones are more likely to actually be successful in this role. And once you actually hire them, how can security leaders then support and develop this talent?

Speaker B: So my personal view is that giving more and more accountability. There's this, uh, pyramid of, uh, initiative, um, uh, from the book, which it just escaped my brain now. Uh, and I thought it's going to be so, well, so good to quote this and it's just literally skipped my brain. I'll just get back to you on this title. But ultimately, um, the book describes levels of initiatives that individuals should, uh, demonstrate in order to be successful in various different levels in the organization and at the different scopes of ownership that they have. And personally I don't hire below a certain level and I encourage other leaders not to hire below a certain level. That level is called um, the minimum level that I expect to see is I propose solutions actively. I allow my leader to choose between a solution A and solution B without fully understanding and comprehensive and complicated topics of what goes, you know, behind the scenes. Because all of these consequences, pros and cons, are baked into those choices that are presented to me.

Speaker C: This podcast is sponsored by Security magazine's Today's Cybersecurity Leader EE newsletter. Ransomware, AI phishing and more. Enterprise cybersecurity leaders need the latest threat intelligence to protect their organizations. Each month, Security Magazine highlights cyber trends for leadership in the Today's Cybersecurity Leader E newsletter. Subscribe now@securitymagazine.com subscribe

Speaker A: in the hiring process. How might a security leader be able to determine if a candidate has that ability or displays that ability to uh, solve problems and present those solutions? Like you said, how can they see that in a candidate?

Speaker B: Um, I play a Bit of a role play during my interviews and I recommend to my other colleagues here at LLI to do this exactly the same. What we do is we travel the timeline, I call it. So we present some idea, we see how the candidate reacts to it, and then we move forward time, 3, 6, 12 months, and we inform them of consequences of that decision and then we see how they go with it. Is it just more of a, uh, let's kick the ball forward and see what happens, or is there an actual, uh, thought process? Are they ready for the next step? Do they understand the consequences that come with it? Does it surprise them if I tell them, like, look, you were expecting this, but actually let's imagine that in scenario, in the scenario we're describing, actually this happens. Are they still defending their choice or are they asking any support questions to understand better, you know, to prepare for the next, you know, time travel forward? Are they, um, do they show initiative and questions such as, hey, can we actually travel back in time? Can I change my, ah, you know, decision? Can I try something else? I really, really want to see these kind of traits and questions because it shows me that they're trying to really understand the entirety of the problem. Think about the inputs and outputs, potential consequences, and not just how. Answer the question ad hoc.

Speaker A: As we start to wrap things up, do you have any last thoughts that you'd like to share?

Speaker B: Well, maybe. Important thing would be to mention how actual scene of security safety compliance is growing in complexity, uh, across jurisdictions. We're seeing various different changes, especially in Europe, where I'm currently based at, uh, we see gdpr, we see EU act, right, AI act, which are, um, not only raising the concerns because on the one hand, of course, this is slowing down development and growth, but on the other hand they represent, um, specific groups of interests and ideals, uh, that we need to as well defend, like privacy, Right to privacy, right to make sure that our data cannot be used to train models and so on and so forth. So companies that are expanding into new geographies often underestimate how much compliance shapes, uh, the talent pool that you will be able, uh, to get, but also the talent profile that you will actually need to fill in. So that's one of the things that might be worthwhile for someone listening to us to consider.

Speaker A: That's all the time we have for today. Thank you so much for joining us, Lucas.

Speaker B: My pleasure. Thank you for having me.

Speaker A: Thanks for listening to Lock it down with Security magazine. Follow us on Apple podcasts or Spotify, or listen to our podcast directly from our site, securitymagazine.com and don't forget to rate and review. Lock it down with Security magazine as well.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why Enterprise Software Deals Now Include a Vendor AI Model Explainability MandateB2B SaaS Talks with Fexingo · on EU AI Act94 / 100
  • How Fortune 500s Use Procurement to Manage Vendor AI Training Data RightsEnterprise Tech with Fexingo · on EU AI Act90 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUCSecurity & GRC Decoded · on EU AI Act76 / 100
  • How B2B Marketers Use First-Party Data After Cookie DeprecationB2B Marketing with Fexingo · on GDPR74 / 100
  • How Stripe Built a Payment Infrastructure for 100 CountriesThe CTO Podcast with Fexingo · on GDPR71 / 100
  • The Executive Guide to Ethical AI and GovernanceThe Bridgecast with Scott Kinka · on EU AI Act70 / 100

More from Lock it Down Podcast

All episodes →
  • Establishing and Measuring Trust55 / 100
  • 6 Data Breaches to Know About (June 2026)
  • 7 Data Security Stories to Know About (May 2026)
  • What Industry Leaders Can Do to Support Women in Security
  • Credential Management in High Turnover Environments
Explore the best B2B Ops podcasts →
All Lock it Down Podcast episodes →