
Bishop Fox Penetration Tester Interview Questions
& Process
Real candidates share what happened, how many rounds they had,
and how the experience turned out.
Based on 7 interview experiences · FREE TO READ
Candidate interview experiences
First-hand accounts from people who interviewed at Bishop Fox.
Penetration Tester
The interview process had 4 parts. First, an HR/screening interview to introduce myself and see if it was a good fit. Second, a technical interview covering crypto, web, and network topics. Third, a cloud application pentest. Fourth, a final interview to discuss my report. Overall, the experience was very negative. After I passed everything, they initiated a background check that included all my previous employers. I received an offer which I accepted, but after 3 months of follow-ups, they decided not to proceed. It was a huge waste of time, showing a complete lack of respect and unprofessionalism. Don't bother with this company.
- Can you explain how HTTPS works?
- Regarding HTTPS, is the encryption method asymmetric or symmetric?
- What is Cross-Site Scripting (XSS)?
Penetration Tester
First, there was a phone chat with a recruiter, who was really nice and kept things fun even when the conversation went off track. Then, a coding challenge came up that involved an English/grammar test. Simultaneously, I had to review 4 code samples riddled with more than 20 bugs/vulnerabilities and write a report detailing these vulnerabilities.
- Review 4 code samples that have over 20 bugs/vulnerabilities and write a vulnerability assessment report on them.
Penetration Tester
I had to explain some common vulnerabilities and how they could be used to get stuff done. The catch was, I had to explain it like I was talking to an executive who didn't know much about tech.
- Tell me about a hack or exploit you found that was particularly successful during an assessment.
Bishop Fox Penetration Tester Interview Questions
Quoted word for word from Bishop Fox interview reports.
“Regarding HTTPS, is the encryption method asymmetric or symmetric?”
Read reports →“What is Cross-Site Scripting (XSS)?”
Read reports →“Can you explain how HTTPS works?”
Read reports →“Describe how to exploit XSS.”
Read reports →“Which of the OWASP Top 10 is your favorite?”
Read report →“Are you a professional, or are you a script kiddie?”
Read report →“Tell me about a hack or exploit you found that was particularly successful during an assessment.”
Read report →“Can you provide technical information relevant to this role?”
Read report →Formats, difficulty and experience
Across all 7 Bishop Fox interview reports.