Does Placing in CTFs Still Matter as a Career Credential?
Watching AI advance lately, I’ve started to understand why people call this the era of “one-click everything.” When I see what AI can do in vulnerability research and CTF challenges, it makes me rethink how we should evaluate someone’s skills.
I’ve also found myself questioning whether CTF placements—something I once considered a strong indicator of technical ability—should still be viewed in the same way. Today, I’d like to share some personal thoughts based on my experience in security work and hiring.
CTF Placements Still Matter—But How We Evaluate Them Needs to Change
I’ll start with my conclusion: CTF placements still matter. However, I believe it has become harder to judge an individual’s skills based on their placement history alone.
I haven’t been in this field for decades, but I have reviewed applications and interviewed candidates to help select people I would eventually work alongside.
An impressive record of CTF placements used to make me think, “This person probably has strong technical skills.” These days, my first questions are a little different: “Which parts did they personally solve?” and “How well do they actually understand the solutions?”
Of course, even in the past, a team’s placement did not necessarily reflect every member’s individual ability. Team members could contribute to different degrees. With AI now contributing as well, I feel we need to be even more careful about judging an individual’s capabilities solely from the outcome.
That is not to say that “AI has made it easy for anyone to place in a CTF.” Making individual challenges easier to solve is not the same as making it easier to place in a competition. In events that permit AI, competing teams can use the same tools.
The significance of a placement also depends on the competition’s difficulty, format, AI usage rules, and the individual’s contribution. Not every CTF placement can be evaluated by the same standard.
Ultimately, my point is not that placements have lost their value, but that we need to look at the process behind the result as well.
So What Value Do CTF Placements Still Have?
1. They Can Demonstrate Effective AI Use and Collaboration
Having access to AI does not guarantee a placement. When competing teams also use AI, the ability to decide which challenges to focus on and how to use those tools becomes important.
Deciding what to delegate to AI, validating its suggestions, and changing the direction of an analysis when you get stuck all require skill. So do sharing information with teammates, dividing responsibilities, and producing results under time pressure. I believe these abilities deserve to be recognized as part of someone’s skill set.
However, a team’s placement does not automatically establish a candidate’s individual proficiency with AI or their ability to collaborate. Their personal role in achieving that result still needs to be clear.
For example, they should be able to explain which challenges they worked on, where AI helped, which judgments they made themselves, and how exchanging information with teammates contributed to solving the problems.
When I’m looking for someone to work with, I’m not interested simply in whether a candidate has used AI. I’m interested in someone who can use it to make their analysis more efficient while independently assessing whether the results are valid and explaining them to others.
That is why I think candidates should use interviews to explain their contributions and reasoning rather than merely emphasize their placements. At a minimum, they should have a solid understanding of the underlying vulnerability and why the solution works for any challenge they claim to have solved.
With that explanation, a CTF placement can still be a compelling credential.
2. They Can Demonstrate Interest in Security and Sustained Effort
The fact that placement history alone may be less useful for judging technical ability does not mean consistent participation has lost its value.
I see value in someone investing their own time in solving challenges, revisiting the ones they could not solve, and returning to try again in the next competition.
In particular, evidence of sustained participation and learning—not just one or two placements—would suggest to me that the person has translated an interest in security into action.
Of course, not participating in CTFs does not mean someone lacks passion. People can build their skills through bug bounties, independent research, open-source work, and other activities. They also have different circumstances and different amounts of time available.
So I would not say that “the person who gives up every weekend is the better candidate.” What matters to me is not how much time someone has sacrificed, but how consistently they have pursued their chosen activity and what they have learned along the way.
In that sense, ongoing CTF participation remains a valuable way to demonstrate interest and persistence.
Looking for Your First Job or Your Next Role? Build on Your CTF Experience
That is my personal perspective on CTF placements, based on my experience both as a practitioner and as an interviewer.
So what does this mean for someone looking for their first job or preparing to move to a new one?
Rather than focusing exclusively on accumulating CTF placements, I think it helps to apply the skills gained through CTFs to other activities. For those pursuing vulnerability research or penetration testing roles in particular, here are three worth considering.
1. Bug Bounties
“Can’t you just use AI for bug bounties too?” you might ask.
Yes. But I’m not recommending bug bounties because they involve less AI. I recommend them because they provide experience finding issues in real services or products, validating those issues, and explaining their impact.
Bug bounty work involves finding and reporting vulnerabilities while respecting each program’s authorized targets, scope, and testing policies. A clear description of the issue, along with reproducible steps or a proof of concept, is also an important part of reporting it.
Solving purpose-built challenges and finding and validating security issues in real services involve overlapping, but not identical, skill sets.
I have seen people with strong CTF results struggle to know where to begin when they first encountered professional security work. That does not necessarily mean they lacked technical ability. They may simply have needed experience adapting to an environment with different starting points and goals.
Understanding a real service and choosing a direction for analysis are important parts of that experience. So are determining whether an observed behavior is genuinely a vulnerability and explaining whom it affects and under what conditions. I believe these experiences can help demonstrate practical capability.
And what if AI helped you find it? Provided you stayed within the authorized scope and policies, verified the issue yourself, and can explain its cause and impact, I believe that work can still demonstrate your own capabilities.
Conversely, if you simply forward AI-generated findings without understanding them, even a bug bounty record would be a weak basis for judging your skills. The same standard should apply here as it does to CTFs.
2. In-Depth Vulnerability Research on a Specific Target
This overlaps considerably with bug bounty work. You might spend a long time analyzing a single product and then report your findings through a bug bounty program, so there is no need to treat the two as completely separate activities.
By a vulnerability research project, I mean choosing a target and an objective, then dedicating a period of time to investigating that target in depth.
For example, you might analyze the authentication and authorization logic of a particular open-source product or examine the attack surface and security controls around a specific feature. The work does not have to focus solely on discovering new vulnerabilities. You could also analyze the root cause and patch for a known vulnerability, then investigate whether similar issues remain.
The advantage of this kind of work is that it can show how deeply you understand and have analyzed a particular target.
Documenting the architecture you examined, the hypotheses you formed, what you tested, and why certain approaches failed allows you to show your analysis process as well as your results.
This kind of sustained work on a single target may be especially worth highlighting if you are aiming for a role that involves analyzing vulnerabilities in your employer’s own services or products.
Of course, simply saying that you completed a project is not enough. You should be able to distinguish verified findings from untested hypotheses and clearly explain the scope and limitations of your analysis. The work should take place in an authorized environment and stay within the permitted scope. Before publishing your results, you should also check the relevant policies and disclosure procedures.
With a solid record of that work, I believe a project can be far more persuasive than a single line on a résumé saying, “Conducted a vulnerability research project.”
3. Regular Blog Posts That Show Your Learning and Thought Process
I think a consistent record of learning-focused blog posts deserves closer attention during hiring.
However, a large number of posts, or neatly organized content, does not in itself verify someone’s skills.
“Can’t you just have AI write the blog posts too?” you might ask.
Yes. That is why, here too, I think the important question is not whether AI was used, but whether the posts reflect the author’s own experiments, judgment, and understanding.
I do not see a problem with using AI to polish the writing or organize the material. It would hardly be consistent to recognize AI use as a skill in CTFs and bug bounties while insisting that it must not be used in a blog.
What I would look for is not just a polished explanation, but evidence that the author has actually studied and experimented with the subject.
Why did they choose to study this topic? What did they expect at first? What actually happened? Where did they get stuck, and how did they work toward an understanding? Posts that address these questions can offer a clearer picture of how someone solves problems and learns.
Ultimately, of course, the author must be able to explain what they wrote. When asked technical questions, they should be able to explain the underlying principles and discuss how the results might change under different conditions.
A consistent body of posts like that can be a valuable way to demonstrate capability—one that offers a different perspective from an impressive list of achievements.
Ultimately, What Matters Is What You Did—and What You Understand
This is not an argument for giving up CTFs and collecting other credentials instead. Nor am I saying that bug bounties, research projects, or blogs are always better than CTFs.
Pursuing one activity in depth may be more valuable than doing a little of everything. What matters, in my view, is connecting your experience to the role you want and showing concretely what you can do.
CTF placements, bug bounty results, vulnerability research projects, and learning blogs all lead to the same question:
“What did you personally do, and what do you understand?”
I do not think an achievement should be discounted simply because AI was involved. Equally, an achievement alone is not enough to establish someone’s individual ability.
The same goes for CTF placements. When you can explain your contribution, your analysis process, and your technical understanding alongside the result, I believe they remain a meaningful credential.
These are my personal views and suggestions, based on my experience in security work and hiring. I hope they offer some help to those preparing for their first job or next role in the age of AI.