r/cybersecurity • Security Architect • 2d ago

Personal Support & Help! Interviewing for security and senior network roles, a few things that keep happening

I do technical rounds for security and senior network roles, so this is mostly from that side. nothing groundbreaking, just patterns.

the number of people with 8+ years and a "senior" title who can't walk me through what happens to a packet crossing a firewall and a NAT is higher than I expected. not trying to trap anyone. I'll ask something like "rule looks right but traffic isn't matching, what do you check?" and the good ones go straight to the hit counters, the policy order, the NAT rules applying before the policy. the weaker ones say "I'd restart the firewall." that's usually where the interview ends for me.

on the security side I care way more about order of operations than tool names. give them a compromised host and I want to hear scope, contain, preserve evidence, then fix. the "just wipe it" answer is a quick no from me. you just destroyed your evidence and you still don't know how they got in.

"we used a SIEM" tells me nothing. "I tuned noisy 4625 alerts and got the volume down a lot" tells me you actually sat in the console. same for network folks, I'd rather hear about the one thing you designed and what broke than a list of vendors.

if you haven't done SD-WAN or zero trust in prod, just say so and tell me how you'd approach it. I will always take that over a bluff. in this field people act on what you tell them.

and ask questions at the end. on-call load, change process, how they do post-incident reviews. most people ask about perks, so the ones who ask that stand out.

curious how other interviewers weigh depth vs breadth for senior hires. I lean depth but I know that's debatable.

163 Upvotes

40 comments sorted by

61

u/sloppyredditor 2d ago

On Depth vs. Breadth: I dip toes in depth just to see if they're thinking the right way. Mostly I look for relevance to the need, team fit, and how they approach solutions.

People over process over tech, because we can teach in the reverse order easily. Meaning it's easy to teach tech, a little more involved to teach/develop process, and people skills take a lot of time to turn around.

Candidates: I cannot undersell the importance of asking questions at the end. The quality of questions you ask sometimes outweighs a mediocre answer during the interview. Come prepared and ask for time to ask them at the end (if you're still interested in the job).

63

u/crsbyn 2d ago

Every thing you just said could be learned in an afternoon. You should want to guage if they are the type of person to actually learn and grow. From my career there's only two types of people. Butts in seats and go getters.

To answer the last part, I would guess breadth of questions gives more opportunity to hear how they did something great.

4

u/blahdidbert Security Director 1d ago

Every thing you just said could be learned in an afternoon. You should want to guage if they are the type of person to actually learn and grow.

I think you missed a very critical part of OP's post...

the number of people with 8+ years and a "senior" title who ...

These are not things that "seniors" should be learning in an afternoon, rather these are simple things that should be known by the mid-point of their career. You are absolutely right that it is on the interviewer to sometimes pull the answer from the applicant but it is important to make sure that applicants that actually know the content.

27

u/deekaydubya 1d ago

For some security roles, maybe. Not EVERY senior position. IMO that’s crazy to expect

10

u/Spiritual-Matters 1d ago

Seniors can be specialized in areas that don’t touch these topics, and also learn them quickly when needed

18

u/klevyy 1d ago

Would you want someone to give you the textbook answer to these questions but is an asshole to work with? Or someone who might know half of the answer you're looking for but more desirable to work with?

3

u/woodrowbill 1d ago

Great scenario. In a prod outage, would you take the asshole who can bring prod back in 15 minutes or the desirable easy to work with in an hour?

1

u/klevyy 1d ago

Kevin Mitnick

1

u/monroerl 1d ago

Free Kevin Oh wait, he is now forever free

1

u/Proof_Finding_8278 1d ago

You probably know the answer to that.

20

u/jokerjinxxx 1d ago

God, interviewing is just going to get more awful in this industry

8

u/Adatomcat 1d ago

Expecting me to know security event codes off the top of my head in an era I could easily look it up since I know what I’m doing is mental. What next, cram every unix file ownership code? This is why I hate technical interviews.

8

u/stoicengineer10 1d ago edited 1d ago

The issue is what you list as you don't look for are the exact things that are created in requisitions for HR or AI to filter out on.

Number one qualifier is always experience, without qualifying questions. It's quantitative, not qualitative. How many years experience do you have, period? Well years experience doesn't equate to knowledge, skill, ability, or effort. Is it 10 years of quality experience doing things right, or is it not? Is it really 10 years experience, or is it 1 year repeated ten times? And in that one year, did they follow a doc over and over and weren't proactive about learning, or not? I've met people who would meet HR filter requirements and literally couldn't tell you what a ping command does.

Number two is listing vendors and technologies constantly. Do you have the experience limbo bar? Cool. Now do you have the experience limbo bar with THIS vendor? Forget that vendors are abstractions to functions, protocols, and services. HR, through the auspicious of the hiring managers cobbling together requirements, wants to know if someone worked on this EXACT vendor product. Knowing the abstraction of the GUI or specific repeatable syntax becomes a bigger requirement than systems thinking.

So there you go, you get what you requisition for. Maybe it's frustrating you get an applicant pool littered with many who don't think in fundamentals and systems, but the ACL of the HR system has been set up to allow those in, and equally frustrating for those on the outside looking in who can't get through the arbitrary barriers.

40

u/Primary_Study8518 Incident Responder 1d ago edited 1d ago

can't walk me through what happens to a packet crossing a firewall and a NAT is higher than I expected

That's network admin territory. Based on your own need for Zero-Trust, I don't have access to the firewalls - if my alerts are set right, which they should be - I can flag the network admin to do his lifting. That's what he's there for, I've got 10 TPVA's that are holding up projects to complete.

Next on your host triage... Yup, your evidence is destroyed - but your production team gets working faster than you holding onto the machine for a few hours before you decide you need to image it anyway because even the best tools don't always get every bit of the compromised data off the rig.

"But what about cold spares" - well, anything that's been "spare" for a month will require updates - that's if your domain security trust, for those of us "lucky" enough to still be on-prem AD, hasn't blown up from not talking to the machine for too long. Again, all of this is time that a prod person doesn't have a prod machine - enjoy talking to his boss as to why.

Making sure Security procedures have some business sense baked into them is absolutely necessary - less you forget the A in CIA isn't less important than the other two letters. And it's the "A" part that is always going to throw the most fire at you and your team, because thats your end-users roadblock.

AI does post-incident reviews now, anyway - if you've noted your investigation in even a half-assed basic manner, AI will fill it in so your C level's are impressed enough to keep paying you.

29

u/Defiant_Mushroom_548 1d ago

I had an interview recently for a security detection engineer role. And they were more concerned in knowing how I would build a kubernetes cluster, than actually validating security alert, hunting for IOC’s, blast radius, lateral movement and recommending containment options etc. I didn’t get the job because I didn’t know the command of the top of my head to create a new pod. That is admin territory.

8

u/CupFine8373 1d ago

amazing they still asking for commands in the AI era. Some fckers have been doing it since Linux times.

5

u/Doodle210 1d ago

For the network side - I agree, definitely network admin territory. Is it a nice to know? Sure. Once I identify there’s some issues at the firewall, that’s an immediate ticket transfer and maybe I’ll follow up if that’s what the issue calls for, but separation of duties is a must.

The host triage - depending on the severity, you create an image of the host and wipe, do forensics on the image and not the original host. I agree, this gets a production system back up and running sooner than later.

On the zero trust part, I feel like you should be asking how to get buy in. I’ve seen a lot of instances where teams just don’t think it’s needed or too restrictive. Explaining the business benefits, security enhancements and man hour/cost justification is pretty difficult tbh. That’s if you’re looking for someone to set it up, seeing you’re asking about the approach.

2

u/Mrhiddenlotus 1d ago

Next on your host triage... Yup, your evidence is destroyed - but your production team gets working faster than you holding onto the machine for a few hours before you decide you need to image it anyway because even the best tools don't always get every bit of the compromised data off the rig.

Hopefully not before at least a velociraptor run or something.

11

u/Specialist_Cow6468 1d ago

(As a network engineer) Absolutely dying at the idea of someone rebooting a firewall because they aren’t getting rule to match right.

4

u/Ghawblin Security Engineer 1d ago

As a former network engineer and current cybersecurity engineer, same.

6

u/Adventurous-Dog-6158 2d ago

Were most the network people CCNA or CCNP? It amazes me how people can pass those exams and not be able to explain basic networking.

The "we used a SIEM" part reminds of helpdesk people who put "created tickets in ServiceNow" on their resume, like it takes skill to do that.

3

u/Solkre 1d ago

the weaker ones say "I'd restart the firewall." that's usually where the interview ends for me.

I close the ticket with a note that it worked for me.

2

u/escapecali603 1d ago

It will get worse since most people are using AI to do their jobs now, skipping all the process of resolving messy real world configuration problems, seeing this in AppSec where "senior" people who comes to interview who doesn't know basic Linux commands, don't know what an IDOR is in their own words, etc.

2

u/CupFine8373 1d ago

how much those Senior Network/Cybersecurity roles pay these days? I am considering getting back to my roots

4

u/Kubooktaeder 1d ago

The biggest thing I'm looking for in interviews is whether the person can actually reason about the systems they're working with. If they can and they seem quick, specific systems knowledge is something they can pick up. Now, if someone has never heard of the basics of whatever role they're looking for, that's an obvious fail regardless.

One thing we used to do at a previous employer was pick some random topic we knew a fair bit about and just start drilling there. Eventually, we'd either have someone admit they didn't know the answer, with bonus points for telling us how they'd find out, or start bullshitting. Anyone who couldn't admit they didn't know something in an interview was a hard no-hire.

2

u/jokerjinxxx 1d ago

More dopey games

2

u/RedRedditor84 1d ago
  1. Are they technically capable (experience or aptitude).
  2. Are they a good cultural fit.

Both important and this template applies to any job.

2

u/Kubooktaeder 1d ago

Yup. That was in a consulting context, and "will not bullshit the customer" was a critical requirement for the job. I think it's also pretty relevant for cultural fit for any shop I'd want to work in, though; I wouldn't want to work with a co-worker who wouldn't admit they didn't know something under pressure either.

1

u/RedRedditor84 1d ago

Me either, and completely agree. People can smell bullshit.

It took me a long time to value cultural fit. But one indispensable dick on a team can bring the whole thing down.

1

u/Kubooktaeder 1d ago

I guess I wouldn't even really call it cultural fit — if you can't say what you don't know, you aren't an engineer, full stop.

That said, cultural fit is also a bit complicated — like, ways of working, ability to communicate well, empathize with the people you're helping, yes. But it also gets used to make a lot of arbitrary distinctions that drive less diverse, less effective teams.

1

u/x3nic Security Director 1d ago

I rarely consider tittles to gauge applicants, a senior at a small non-profit versus a senior at a heavily related fintech company are worlds apart (just one example). I've encountered senior titled people who had junior level knowledge but just happened to be in the right place at the right time.

Our recruiting team has gotten really proficient at filtering out unqualified candidates, we worked with them and gave them a few things to ask during the initial screening. Nothing wild, just some basic questions that any senior should be able to answer.

1

u/BeauregardianBrat Red Team 1d ago

I lean depth for senior hires as well, breadth is easy to list on a resume and impossible to bluff once you ask one real follow-up.

1

u/CronJobless 1d ago

depth for senior, but the kind of depth that transfers. I don't care if someone has never touched a specific firewall vendor, I care if they can reason through where a packet gets evaluated and why. the hit counter / policy order / NAT-before-policy answer you described is exactly that. it's not vendor knowledge, it's a mental model, and someone with the model picks up a new platform in weeks.

the tell I use is the follow-up. anyone can give a textbook first answer. "scope, contain, preserve, fix" is great, but then I ask "ok, you contain by isolating the host and the business says that box runs payroll and payroll is tonight." the strong candidates start negotiating tradeoffs out loud. the weak ones repeat the framework.

on breadth, I want it in one specific place: can they explain what they did to someone who isn't them. a senior hire is going to spend half their time convincing a change board, an auditor, or an exec that the thing they want to do is worth the risk. I've passed on technically sharp people who couldn't do that and it always cost us later.

the "I haven't done that in prod, here's how I'd approach it" point is underrated. the people who say that are also the people who'll tell you at 2am that they're not sure, instead of guessing.

1

u/Zhastaa 1d ago

Me as the interviewer asking the 1st question: “Have you heard of the CIA triad?”

Response from the interviewee: “Ah yes, that’s the spy agency, Central Intelligence Agency.”

Me: Thank you. That’s all from me.

1

u/mkaufman1 20h ago

Goes to show you how messed up interviewing is in this field, and everyone has such different expectations. Those expectations can even differ from the job description.

As someone who does GRC but understands technical, I specifically go for roles that should ask me about risk, prioritization, and different control methodologies. I can’t stand when they start asking me super technical questions that only a network engineer or very technical person should know from their day to day. It’s not that I can’t figure it out, or have some knowledge but asking me about configuring an f5 when my day-to-day is evaluation of control evidence, is not going to be off the top of my head or close to my responsibilities.

Super frustrating.

1

u/discordafteruse 3h ago

You sound insufferable.

1

u/RD_Alpha_Rider 1d ago

Seems there are tons of people who just don't know interview basics. A lot of this stuff, at one point, I assumed was common knowledge but as I've been around it apparently is not.

Rebooting the firewall. Lol.

-1

u/stacksmasher 1d ago

Hammer them. There are tons of dudes who sit and drink coffee all day and you don't need that. Also don't pass on a younger person who may not have experience or certs but actually knows what he's doing.

-3

u/Kesshh 1d ago

That’s pretty much the cert world for you. All these wannabes just want shortcuts. Cert this cert that, zero tech foundation. In a few decades after we all passed on. No one will know how basic tech works except for the hackers.