
Expel Interview Questions
& Process
Real candidates share what happened, how many rounds they had,
and how the experience turned out.
Based on 39 interview experiences · FREE TO READ
Which role are you interviewing for?
16 roles · 39 reportsCandidate interview experiences
First-hand accounts from people who interviewed at Expel.
SOC Analyst
It was a 4 round interview process. Some questions were asked multiple times across different interviews. The final interview with the Senior VP was very disappointing as they seemed checked out. They sent a rejection letter with vague feedback about professionalism, even though the interviewers themselves used profanity and spoke poorly of other candidates and competitors throughout the interviews.
- Tell me about a time you faced a difficult situation at work and how you handled it.
SOC Security Specialist
It was a really bad interview experience. The interviewers asked unclear questions, trying to get specific answers rather than seeing if I could solve problems or think critically. They acted like they were super elite and expected deep knowledge of DFIR for an entry-level job, but they paid way less than average. The whole thing took 5 weeks, mostly waiting for them to reply after the third round. The first round was a quick 30-minute intro. The second was a 60-minute behavioral panel. The third was a 60-minute technical panel. I noticed some red flags: they mentioned a fast-paced, high-volume environment, but it felt like they were just understaffed and used it as an excuse. The total pay was below market for XDR roles, even less than they used to pay. They expect you to learn new things on your own time and money, with no room for upskilling at work. They were not communicative and the process felt disorganized. They should set up clearer steps for candidates and provide updates. They should also ask questions that test problem-solving instead of just memorization. And they need to offer competitive pay, not try to hide it with bonuses.
- Can you explain what CAs are and how they're distributed?
- What are HTTP status codes, and could you provide some examples?
- Could you explain email headers and what indicators of a malicious email you would search for, and why?
Senior Software Engineer
Had a fantastic experience from start to finish. Everyone I interacted with, from the recruiter to the hiring team and interviewers, was polite, professional, and accommodating. The interview structure was pretty standard for the tech industry, with about 6 interviews spread over roughly 3 weeks. What really stood out was how transparent everyone was. My tougher questions got honest answers, and the interviewers seemed genuinely invested in making sure it was a good fit for me, not just the company. Instead of a typical sales pitch, it felt more like intellectual conversations with good people to see if we could help each other out. It was really refreshing.
- What are the key traits you identify in a strong leader?
Detection and Response Engineer
So I applied for this job on LinkedIn and heard back from the recruiter pretty fast, like the next day. They asked about my background and what I wanted salary-wise, and then I got to pick dates for four interviews. Each was supposed to be an hour with two people, but most times it was just one. Since it's a remote role in Ireland, everything was over Zoom. It started with the hiring manager, who was nice and told me a lot about the job and the team, which was a good way to kick things off. Then came the first tech round with a team manager, doing a Python coding thing about app integrations, APIs, handling errors, and making code run better. It was tough but fun. Right after that, I had a round with a Principal Engineer talking about current threats, how to write detections, and some 'tell me about a time' questions. It felt a bit scripted, but the interviewer was cool. The third round was with a manager and another Detection Engineer, focusing on automating detection engineering. We talked about past automation work, hypothetical situations, and tools. It was pretty standard but made you think, and the interviewers were respectful. The last interview was back with the hiring manager, a mix of technical and situational stuff. They said I'd get feedback soon. But then... nothing. I got ghosted by the recruiters after all that. The interviewers themselves were great, but the lack of any follow-up, even a rejection, is super disappointing and makes the whole company look bad, especially after putting in all that effort.
- You're given a curl command with a valid Shodan URL. Could you write some code or pseudocode for this? Then, how would you enrich an alert using just that URL? Do you see any issues with the code you wrote? If it fails, how would you troubleshoot? How would you deal with the Shodan license's limit on GET requests? And if an analyst gets a bunch of alerts with different URLs, what's your strategy to make sure the enrichment is efficient and doesn't slow things down?
- Tell me about a situation where a detection you created actually saved an analyst time.
- Have you ever created a detection specifically to flag a certain threat actor?
Expel Interview Questions
Quoted word for word from Expel interview reports.
“Could you write Python code that replicates the HTTP request made by this curl command?”
Read reports →“What are the methods for detecting domain fronting?”
Read reports →“What are HTTP status codes, and could you provide some examples?”
Read reports →“What is the appropriate Logon Type for RDP?”
Read reports →“Can you explain what DNS is and its working mechanism?”
Read report →“Can you describe what happens when you type google.com into your browser?”
Read report →“What built-in features do EDR tools typically provide that can be used for investigating an event?”
Read report →“Could you explain what domain fronting is?”
Read report →“Where are common places to find persistence mechanisms?”
Read report →Formats, difficulty and experience
Across all 39 Expel interview reports.