Security Certifications (CISSP, OSCP, CEH)
Also written as CISSP, OSCP, CEH, Certified Ethical Hacker, CompTIA Security, CISM, CISA, GIAC
The security credentials that appear most on resumes and JDs, and they test very different things. CISSP and CISM are management and governance certifications that require several years of work experience; CISA is for IT auditors; OSCP is a hands-on exam where the candidate must break into real machines against the clock; CEH and CompTIA Security+ are entry-level; GIAC certifications (from SANS) are respected technical specialisms.
Think of it like
A driving licence, a lorry licence and a racing licence are all 'licences', but they prove very different things.
Junior or senior?
Don't treat them as interchangeable. OSCP is strong evidence of hands-on attack skills; CISSP signals seniority and breadth, not technical depth; CEH or Security+ alone is entry-level. Many excellent engineers hold none, so a missing certificate shouldn't block a strong candidate.
Ask them
“Which certification taught you the most, and what did you do differently at work afterwards?”
Sounds like real experience
Connects the certification to real work — for OSCP, describes the exam or labs concretely; for CISSP or CISM, talks about policies, risk decisions or audits they owned.
Probe further if
Can recite the exam topics but can't connect any of them to a task they've actually done at work.