Hiring Engineers, Not Scammers: Lessons from the Field
See what happens when a security professional finds himself in the role of an engineering manager hiring full stack software engineers. How do you weed through 3,000+ applications — discarding AI spam, spotting organized call center fraud during interviews, and identifying candidates who are actual qualified humans? I'll walk you through our learnings with numerous real-life examples.
Let's fill some open engineering positions! Applications started rolling in and I settled in to do what hiring managers do. Three thousand applications later, I was running spreadsheet queries to look for phony patterns, listening for call-center audio in Zoom interviews, and explaining to our applicant tracking system vendor that the same person had applied eleven times under different names.
This talk is the story of what I found, told through real examples:
The interview tell-tales: virtual backgrounds glitching at suspicious moments, audio that sounds like a call center floor, candidates reading answers off-screen, and the eerie pattern of "perfect" responses from people who never ask a clarifying question.
Patterns across the piles of applications: clusters of duplicate applications, identifier reuse across different names, almost convincing LinkedIn profiles, and a small handful of other signals when analyzing applications in aggregate.
Interpretation and judgment calls: how to interpret those signals, how to recognize and prevent bias, and how to not throw out genuine candidates who happen to use AI tools responsibly.
You'll leave entertained, possibly mildly horrified, and with a practical sense of what's actually happening in hiring pipelines right now. Useful whether you're a hiring manager, a recruiter, a security practitioner whose People team is about to ask for help, or a job seeker who'd like to not get filtered by accident.
David Ochel is the Director of Product Security at Hypori, where he helps product and engineering teams strengthen their security posture — and occasionally gets pulled into adjacent problems, like figuring out how to hire engineers in an era of AI-generated applications and organized interview fraud. Over 25+ years in security and privacy, he has directed corporate security, privacy, and risk management programs; worked as a product manager in privacy software; and served as a consultant, technical assessor, and auditor across various compliance domains. David lives in Austin, Texas. In his spare time, you can find him on international caving expeditions, exploring digital modes on his HAM radio, or riding his bicycle from one coffee shop to the next.