IT Professional Position

IT roles hold administrative credentials, reach production data, and can grant access to others. Screening should reflect what those credentials open.

Find a section

Home / Screening by Position / IT Professional

Federal Law (FCRA)

The Fair Credit Reporting Act (FCRA) establishes the federal minimum requirements for employment background checks, including disclosure and authorization requirements, consumer rights, and the adverse action process. Many states impose additional requirements that employers must also follow.

Read FCRA Overview

Recommended Screening Components

The components below reflect common elements of an IT screening package. Requirements change based on the systems the role can reach and what data those systems hold.

Typically Recommended Often Recommended Usually Required Not Common
Screening Component What It Covers Recommendation
Confirms the applicant is the person the report was run on. Matters in remote hiring.
Names and addresses associated with the applicant, which identify where to search.
Criminal records in the counties where the applicant has lived and worked.
Broad multi-state coverage that points toward records a county search would miss.
Federal court records, where computer fraud and data theft cases are prosecuted.
Past employers and dates, which establish the systems the person has administered.
Degree or program completion. Many qualified IT professionals hold no degree.
Technical certifications, confirmed through the issuing body. Most carry expiration dates.
Payment history, ordered for roles reaching payment systems or financial data.
Sanctions and enforcement lists, checked where customer agreements require it.
Records from countries where the applicant lived or worked. Common in distributed teams.
Fingerprint-based check, required for access to criminal justice and federal systems.

Screening components should always be job-related and consistent with applicable federal, state, and local laws.

Notes on This Package

Certifications verify quickly and expire quietly. Cloud platform, security, and networking certifications are confirmed through the issuing body’s public verification portal, usually within minutes. Most carry expiration dates and renewal requirements, so a credential earned four years ago may be inactive while still sitting on the resume.

Degrees are the weaker signal here. Many capable IT professionals are self-taught, came through a bootcamp, or left a program unfinished, and none of that is unusual in this field. Verification returning nothing is common rather than notable, which is why certifications and employment history carry more weight.

Computer crimes are prosecuted federally. Unauthorized access, data theft, and computer fraud are commonly charged under federal law and filed in federal court. A package limited to county coverage will not reach them, which makes a federal search more relevant here than in most positions.

Access can outlive employment. Administrative accounts, service accounts, shared credentials, and personal access keys survive a departure unless every one is found and revoked. This is why organizations screen the roles that hold those credentials rather than the roles that sit high on the org chart.

Privileged Access

What an IT role can reach determines the package, and access rarely matches seniority.

What privileged means

A privileged account can change configurations, read or alter data at scale, and bypass the controls that limit ordinary users. Domain administrators, database administrators, cloud platform owners, and support staff with password reset authority all hold it. A senior engineer with read-only access to one application does not.

Granting access to others

Identity and access management roles decide who gets which permissions. That authority is broader than any single system, since a person who can grant access can grant it to themselves. Organizations commonly screen these roles at the same depth as the most sensitive system they can reach.

Contractors and managed providers

Outsourced help desks, managed service providers, and contract administrators frequently hold the same credentials as employees. Screening reaches them through the vendor agreement, and customer security audits expect that standard to match what the organization applies to staff.

Where Screening Changes

The same job title carries different requirements depending on the setting.

Technology Customer security frameworks treat personnel screening as an audited control, and enterprise agreements specify components and re-screening intervals.
Financial Services Federal law bars people convicted of dishonesty offenses from insured institutions, and payment system access adds its own screening requirement.
Healthcare Staff reaching systems that hold patient records are covered by the organization’s exclusion checks and privacy obligations.
Government Access to criminal justice data requires a fingerprint check and recertification, and federal work adds suitability or a clearance.
Professional Services Consultants working in client environments are screened to the client’s standard before access is granted.
Manufacturing Systems holding export controlled technical data limit access to U.S. persons, verified by the employer from documentation.

Screening Considerations

Privileged Credentials

Administrative accounts can alter configurations, reach data at scale, and bypass ordinary controls. Screening depth follows those credentials rather than the seniority of the position.

Access Granting Authority

Roles that assign permissions can assign them to themselves. Identity and access management positions are commonly screened to the level of the most sensitive system they can reach.

Certification Verification

Issuing bodies publish verification portals keyed to a candidate identifier, so confirmation is fast. Expiration dates matter, since lapsed credentials are common and do not appear on a resume.

Identity Verification

A background report searches records under the name and Social Security number provided. Identity document verification confirms the applicant is that person, which matters most when hiring is fully remote.

Federal Criminal Coverage

Unauthorized access and data theft are commonly prosecuted federally. County and state searches do not reach the federal court system.

Contractors and Vendors

Managed providers and contract administrators hold employee-level credentials. The vendor agreement sets the standard, the vendor runs the checks, and customer audits expect the standards to match.

Customer Requirements

Enterprise agreements commonly specify components, lookback periods, and how recent a report must be. Re-screening during employment requires its own disclosure and authorization.

Distributed Teams

Remote hiring spreads searches across states and countries. Screening rules follow the worker’s location, and records outside the United States have their own availability limits.

Common Questions

Are background checks required in IT?

No federal rule requires one. Requirements come from customer contracts, security audits, and company policy, with government systems as the exception.

Does a security certification include vetting?

No. Certifications confirm a person passed an exam and met experience requirements. No criminal history is reviewed.

How are certifications verified?

Through the issuing body’s verification portal, usually keyed to a candidate identifier. The portal also shows whether the credential is current.

Is a degree expected?

Often not. Many qualified professionals are self-taught or came through a bootcamp, so verification returning nothing is common in this field.

Why add a federal criminal search?

Because computer fraud and data theft are commonly charged federally. Those cases are filed in a court system county searches do not reach.

Should credit be checked?

Where the role reaches payment systems or financial data. Several states restrict employment credit checks to positions meeting a defined exception.

Who screens managed service providers?

The provider, as their employer. The vendor agreement sets the standard, and audits examine whether it matches the internal one.

What does identity verification add?

It confirms the applicant is the person whose records were searched. A criminal search cannot answer that question on its own.

Worth Knowing

Security Certification Is Not a Background Check

Issuing bodies test knowledge and confirm work experience. They do not review criminal history or verify employment and education. The employer must still run the screening.