Security interviews. 9 titles, each with its own model.
Each page shows the competency model, the questions that test it, what changes with seniority, and where candidates lose the interview.
Last reviewed
Every Security title
9 titlesWhat the report looks like for Security
- The situation in one sentence: where, what was short, and by how much.
- The decision that was yours rather than the team’s, and what you chose not to do.
- One number or one consequence that shows it worked.
Every competency is scored out of five with a line you actually said as evidence, and the weakest answers are rewritten as structure and specifics, never a script.
What Security interviewers keep scoring
Threat modelling & risk-based prioritisation
Identifies realistic threats to a system, assesses likelihood and impact, and prioritises controls by risk rather than by checklist or headline.
Secure design & code review
Finds and fixes vulnerabilities in architecture and code (authentication, authorisation, injection, secrets, crypto misuse) and helps developers avoid them.
Detection & incident response
Detects intrusions from logs and telemetry, contains and eradicates them methodically, preserves evidence, and communicates clearly during an incident.
Vulnerability & attack-surface management
Keeps the organisation's attack surface known and patched: asset inventory, scanning, prioritisation by exploitability, and driving remediation across teams.
Identity, access & cloud security
Designs and operates authentication, authorisation and cloud controls that enforce least privilege without stopping people from doing their jobs.
Influencing without blocking
Gets engineering and business teams to adopt secure practices by making the secure path easy and framing risk in their terms, rather than by saying no.
Compliance, privacy & governance
Maps controls to regulatory and contractual requirements (POPIA, GDPR, PCI DSS, ISO 27001) so that compliance evidence comes from real security work, not paperwork.
Judgement under pressure & honest disclosure
Makes sound calls when a breach, disclosure or executive demand creates pressure, and tells the truth about security posture even when it is unwelcome.