
Security Innovation Interview Questions
& Process
Real candidates share what happened, how many rounds they had,
and how the experience turned out.
Based on 17 interview experiences · FREE TO READ
Which role are you interviewing for?
6 roles · 17 reportsCandidate interview experiences
First-hand accounts from people who interviewed at Security Innovation.
Security Consultant
The process started with a recruiter reaching out, and putting me in touch with the direct hiring manager. The first interview was very conversational and was to seek what interest do you have with general experience. Following I was given a live site to find as many vulnerabilities as possible in 4 hours. Most were all validated manually, by XSS, SQL injection, ect. Next came a technical interview with an engineer, he ask questions surrounding some basic protocols, and questions around how does the web work, including encapsulation for protocols. If you have a strong SOC and have went through training such as GWAPT with strong knowledge you will do great. By far my favorite and extensive interview process yet.
- You are connecting to _____ site from a browser. Explain everything that happens.
Security Engineer
Applied and got invited to their penetration testing skills assessment site, then after completing that, a more comprehensive cyber range. My score was good and I was invited to a series of zoom interviews on programming, different security domain skills, and culture fit. I liked that they had skills tests upfront instead of relying on my resume going through some black box matching algorithm, and everyone I spoke to was super friendly. This sounds like a really positive place to work. When I was rejected, they gave me helpful feedback on what I could improve, which is very valuable to me as someone trying to get into this field.
- Looking at this small piece of server code (about 20 lines of JS, if I remember correctly), can you identify any potential vulnerabilities?
Software Engineer
I was given a task to build a custom URL shortener, which was pretty open-ended. I built it how I thought it should be done. There was a minor issue with my code's naming, but I believe I met all the expectations. However, they informed me I wouldn't move to the next round. It's frustrating to spend my weekend on a working solution that gets rejected just for naming issues. They seem to expect very specific answers for open-ended problems, which they might change. This is the only place so far that rejected a working solution.
- Could you design a custom URL shortener that includes a user interface?
Information Security Analyst
We started with some really interesting and challenging CTF challenges, then there was a single 2-hour interview with several interviewers who asked very tough questions, always asking for elaboration and clarifications. It was a very fun experience!
- How would you calculate the entropy for various codes?
Security Innovation Interview Questions
Quoted word for word from Security Innovation interview reports.
“How does asymmetric encryption function?”
Read reports →“Tell me if a given integer is prime.”
Read reports →“What role does Diffie Hellman play?”
Read reports →“What are the methods for protecting against XSS attacks?”
Read reports →“How would you calculate the entropy for various codes?”
Read report →“What occurs at each stage of the TLS and Diffie Hellman exchange?”
Read report →“Can you explain how salts work and their proper usage in password hashing?”
Read report →“Can you explain how HTTPS functions?”
Read report →“Can you describe the entire process that occurs from typing a URL into a browser and hitting enter?”
Read report →Formats, difficulty and experience
Across all 17 Security Innovation interview reports.