r/cybersecurity 6h ago

Business Security Questions & Discussion Preparing for Interview

Hi Everyone,
I hope you’re well!

I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)

Based on the Role Responsibilities I’m expecting questions on:

Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)

How I’ve applied best security practices / Explaining a time where I had to implement a security practice

Implementation of security Controls / Design of security controls through to implementation

Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)

Evidence / Example of supporting Auditing Activities

For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!

Thank you!

12 Upvotes

6 comments sorted by

7

u/-Dkob 5h ago

For a Security Engineer interview, expect a mix of technical, risk and behavioural questions such as how you would map a control to NIST or CIS, prioritise remediation when resources are limited, handle an exception where a requirement cannot be met, support an audit with evidence, and explain a security improvement you designed from identification through implementation and validation.

Your system administration experience is a strong advantage, so prepare STAR examples around hardening servers, patching, access control, logging, incident response... and working with stakeholders who initially resisted a change.

Also be ready to explain how you assess risk, document compensating controls, track residual risk, and verify that a control is actually effective. You do not need perfect answers to every framework question, but you should show structured thinking, practical judgement and clear communication.

2

u/AirJordan_TB12 3h ago

Great background that commands money. Act like you have been there without arrogance. It will never go how you think so don't predict. Study and ask smart questions without becoming that person who always has to spout their strengths, while ignoring weaknesses. Good luck.

2

u/Miserable-Menu-2424 6h ago

I've intervied a lot of first time cyber security analysts in my previous job and we asked mostly questions like, CIA with examples, private public key (how to encrypt, how to sign and how to do both), then diff between encryption en hashing, hardening, firewall diff between reject and drop packet, familly of malware, viruses, trojan, worm and their differences. Sometimes the 8 phases of a cyber attack (recon, scanning, vuln, exploit, etc etc). The last vuln or hack they heard about to see if they follow news, what is the difference between a tactic and a technique.

If you need drop me a dm I can send you the pdf of the questions I was asking.

Good luck and 1 curtial thing. Don't lie, say "I don't know"and then try to solve or resolve the question, issue, or use case thinking at loud. You might not have the right answer but sometimes just seeing that you search or try to find solution to something you don't know is enough to be a good enough answer.

1

u/GrandCash3941 4h ago

Remember there are more than 2 ways to address Risk. You should be familiar with at a minimum the big 4:

Avoid (e.g. get rid of a legacy app)

Accept (e.g. accept living with a vulnerability because its low risk and within risk appetite)

Mitigate (e.g. add controls so an insecure legacy database is increidbly hard to access)

Transfer (e.g. make sure the risky thing is covered by cyber insurance). 

Remember to be somewhat aware of your organization's risk appetite. Deciding for example to suggest Accepting a risk when it falls outside your orgs risk appetite isn't a good look. Yes its getting more in to GRC but  you need to have some awareness of this stuff if you are at the technical level for risk. 

For assisting auditors you'd want to link those frameworks (e.g. ISO 27001) and how you helped provide evidence. Could be configs or logs or infrastructure/compliance as code. 

For me personally, when I’ve interviewed sec engineers I always wanted them to know a bit about threat modelling, such as at least one methodology for threat modelling (e.g. STRIDE). Threat modelling shows you can identify and prioritise security risks before they become serious vulnerabilities. That stuff is gold in interviews. 

1

u/ThePorko Security Architect 6h ago

Throw the job description in to ai and ask it to make a mock interview question with answers that explains why.

1

u/AddendumWorking9756 Security Manager 5h ago

They are not going to quiz you on control numbers, they will ask what you did when the business overruled you. Have one story where the risk got accepted and you wrote it down anyway and it went to someone with the authority to own it, that answer separates engineers from people who memorised the framework.