nosocial.media A statement on hiring practice

Application form · field 7 of 12 · required

Left blank. On purpose. Here is the reasoning.

The Unfindable Professional

Why hiring teams should stop demanding a LinkedIn profile from security people.

The ask

You want the org chart from the people paid to hide it

Most of us spend our working lives telling other people to shrink their footprint. Scrub the org chart off the public site. Get the executive's home address out of the property records. Stop confirming your employer, your team, your manager and your tech stack to anyone who asks nicely.

Then we apply for a job and get asked for a public profile containing exactly that: our face, our employer, our reporting line, our tooling, and a list of everyone we've worked with for the last fifteen years.

A growing number of employers now treat this as a baseline requirement. Some applicant tracking systems won't accept a submission without a profile URL. Some recruiters read a blank field as a red flag, or assume the candidate is hiding something.

It's an odd request to make of the people you're hiring to keep you out of the news.

What it hands over

A completed profile is a free intelligence product

It confirms who works where, what they do, who they report to, which products they run, and when they moved. Attackers know this. Building a target list for a phishing campaign against a specific company is a fifteen minute job, and the profiles do most of the work.

We know this because we write the reports that say so. Half the incident write-ups in this industry contain some version of "the attacker identified the finance team via publicly available professional networking data." We then go back to our desks and update our own profiles.

Compartmentalization

It works in both directions

Keeping identities and contexts separate is one of the first things this field teaches. Different accounts, different machines, different personas, no bleed between them.

A public professional profile collapses that on purpose. It ties a real name to an employer to a face to a personal network, and it does so on a platform whose business model depends on that link being permanent and searchable. For a lot of roles, particularly offensive security, threat intel, fraud, and anyone whose work involves engaging with people who would rather they didn't, that link is a real problem rather than a philosophical one.

The contradiction

You already pay to undo this

Companies buy executive protection services. They buy data broker removal subscriptions for their staff. They run training that tells employees to be careful what they post. Some of them do all of this and still won't look at a security candidate who doesn't have a public profile with a headshot.

The stated reason is usually professional visibility or networking. That reason makes sense for sales. It makes considerably less sense for the person you want running your detection engineering.

What to ask for instead

The fields that actually tell you something

None of this means candidates should be unverifiable. It means the verification shouldn't require a social media account.

In fairness

An empty search result isn't proof of skill

There are excellent engineers with detailed public profiles and active conference schedules, and there are terrible ones with none. Absence of a footprint doesn't tell you much on its own.

The argument here is narrower than that. Requiring a profile filters on something unrelated to the job, and it filters hardest on exactly the people whose reasons for staying quiet are the most professionally sound. That's a bad screen, and it's costing employers candidates they'd want.

The ask, returned

Take the field off the form

Stop treating a blank profile field as a warning sign. If someone can do the work and comes recommended by people you trust, that's enough, and it always has been.