In defence hiring, the word “security” can turn into performance: long questionnaires that never drive a decision, checks bolted on at the end, and vague wording that leaves candidates unsure of the rules. Security theatre creates a feeling of control while burning team time, scaring off strong engineers, and failing to reduce real risk.
At Fidesa, screening is part of hiring quality — not a separate ritual. Below is how to tell substance from theatre, where agency responsibility ends and client compliance begins, and how to handle personal data without collecting surplus.
What security theatre looks like in practice
Theatre is activity that looks strict but correlates weakly with a hire / no-hire decision or with the client’s actual threat model.
Common signs:
- Checks start after the technical team has already spent multiple rounds.
- Questions are written so answers cannot be verified or applied.
- Extra personal data is collected “just in case,” without a legal basis or retention policy.
- There is no written split: what the agency does, what the client does, what an authorised function does.
- Candidates are not told why a request exists — only told to “fill the form.”
- The process changes from vacancy to vacancy with no standard.
Theatre is expensive: it increases drop-off among strong candidates and creates a false sense that “we checked everything” when checks were late or aimed at the wrong thing.
Principles of screening without theatre
1. Early, but proportionate. Basic disqualifiers and fit frames appear at the start of the funnel. Deeper checks only for people who already show substance fit and where the client has justified interest.
2. Clear criteria before the first technical round. Hiring manager and agency agree what is a hard stop versus a signal for follow-up. Without that, every interviewer improvises.
3. Minimum data, maximum decision. Collect only what the stage requires. Do not archive “interesting biography details” without purpose.
4. Explainability for the candidate. People should understand the rules: what is checked, who controls the data, how long it is kept, and how to withdraw consent where applicable.
5. Separation of roles. The agency does not impersonate the client’s security function and does not sell “pseudo-clearance.” The client does not push legal responsibility onto an agency that cannot carry it.
Boundaries: agency vs client compliance
A clear boundary protects every side.
Typically in the agency’s zone (by agreement):
- structured primary screening against an agreed checklist;
- capturing answers and signals for the hiring manager;
- checking résumé consistency against publicly shareable career facts;
- filtering profiles that clearly fail geographic / legal frames of the role;
- organising interviews and passing only relevant context down the funnel;
- processing personal data within the recruiting mandate and policy.
Typically in the client’s zone:
- internal policy for access to information and facilities;
- official background / security procedures where law or contract requires them;
- final risk and hiring decisions;
- long-term HR files and registries;
- engagement with state or sector regimes where applicable.
When the boundary blurs, two failure modes appear: the agency promises what it does not control; the client assumes “the recruiter already covered it.” Both are dangerous. A healthy process states the boundary in the role brief — before sourcing.
Personal data: discipline instead of volume
In Defence Tech the temptation to “collect more” is strong. The right answer is the opposite: less, under control.
Practical rules:
- Legal basis and purpose are named before collection.
- Sourcing-stage data is not mixed with offer-stage data without need.
- Access inside the agency follows need-to-know.
- Retention is limited; surplus is deleted.
- Transfer to the client is only the package required for the current decision.
- Candidates can ask what is processed and why.
Screening that ignores data protection is not “more secure.” It creates a new legal and reputational risk and contradicts the idea of discipline itself.
What substantive early screening can look like
Without disclosing client-internal protocols or pretending there is a universal secret questionnaire, a useful frame is:
- Role context — location, format, and information-access expectations at a level that can be stated to the candidate.
- Legal and geographic fit — hard criteria agreed with the client.
- Career consistency — whether experience and motivation match the operating regime, not only the stack.
- Process readiness — whether the candidate understands that some checks sit with the employer and take time.
- Escalation — a clear path when an answer needs a client decision, not recruiter improvisation.
The goal is not an interrogation. The goal is not to spend a week of technical interviews on a profile that could not pass a day-one filter.
Talking to candidates without intimidation
Strong engineers leave processes that feel arbitrary. Theatre often sounds like distrust without rules. Substantive screening sounds like a professional industry norm.
Useful communication:
- what is needed at this stage and why;
- what comes next on the employer side;
- that the candidate may decline or stop;
- that confidentiality of their data is part of the standard, not a favour.
Respect here is not softness. It is the condition under which strong people stay in process.
Takeaway for hiring managers
If your security process starts late, collects surplus, and has no owner, you are paying for theatre. If the protocol is early, proportionate, role-split, and data-disciplined, you protect the programme and accelerate a quality shortlist at the same time.
Fidesa builds screening as part of Defence Tech recruiting quality: without imitating the client’s security function and without collecting data “for the archive.” To align the frame for a specific role, book a call via Calendly in the contact section.