Talked with at least six different people, mostly focused on how well I would fit into the organization. Technical aspects of interview were well done, with live code discussions. Good emphasis on quality of life as a consultant and a growing industry.
Domande di colloquio [1]
Domanda 1
Describe a vulnerability that you found in an application and how you talked with the customer about it?
Ho presentato la mia candidatura tramite un selezionatore. La procedura ha richiesto una settimana. Ho sostenuto un colloquio presso Aspect Security (Baltimore, MD) nel mese di set 2015
Colloquio
Interview consisted of recruiter asking from a pool of questions:
What’s the difference between Java and Javascript?
What are the difference between fuzzing and sniffing?
What 1 does not fit? Coldfusion, java, asp, html
What 1 does not fit? AES256, Blow Fish, SHA1
Describe Cross Site Scripting
What are some common mitigations for SQL Injection?
Describe the common use of an application proxy for penetration testing.
Explain the differences between a GET and POST request
Do you have any experience with Dynamic and Static Code Analysis? Which tools have you used?
Any advantages of using JSON instead of XML?
Afterwards I was informed that the next step would be to talk with one of their Senior AppSec Engineers and after that step would do a practical part of the interview.
Domande di colloquio [1]
Domanda 1
What’s the difference between Java and Javascript?