- Developer security management issue - what’s your call?
- Technologies are changing; how comfortable are you?
- How do you keep yourself updated in the security domain?
- What personal achievement are you most proud of?
- Tell me one critical bug you found in the AppSec domain and one in the Infra domain.
- What would you do typically on the first day of your job?
- How will you scale security scope for heavy application-focused projects
- How will you convince the engineering team to fix 1000s of issues that your tool found
- What security measure would you take from a data integrity perspective
- What interests you about this role?
- What is your typical routine in office?
- How do you keep your team updated with work, etc.?
- What would be your first 30, 60, 90 days goal for product security?
- Why are you looking for a change?
- What are your biggest strengths?
- What are your most significant weaknesses?
- Where do you see in the next five years?
- Any serious issues you fixed/worked on in the last quarter/year? How did you resolve it? Have you learned anything from it?
- What are the significant challenges you have faced recently?
- What are your salary expectations?
- What are your career goals?
- What do you consider to be your most significant professional achievement?
- Describe your dream job.
- What is your leadership style?
- What questions do you have for me?
- What do you expect me to accomplish in the first 90 days?
- Market seems unstable, how do you keep attrition rate low?
- OWASP top10 understandings
- Crypto algorithms, primitives
- Stream Cipher vs Block Cipher
- Encryption vs Hashing vs Encoding vs Obfuscation
- Why XoR is very important in the Crypto world
- Network Protocols
- Could you explain what is phishing? How can it be prevented?
Phishing is a technique that deceives people into obtaining data from users. The social engineer tries to impersonate a genuine website webpages like Yahoo or facebook and will ask the user to enter their password and account ID.
It can be prevented by:
- Having a guard against spam
- Communicating personal information through secure websites only
- Download files or attachments in emails from unknown senders
- Never e-mail financial information
- Beware of links in e-mails that ask for personal information
- Ignore entering personal information in a pop-up screen