Leadership
January 04, 2012· 1 min read

Interviewing Security Professionals

I was reading a recent 37signals post about why they don't hire programmers based on puzzles or parlor tricks, and it got me wondering what strange tricks I played on the security professionals interviewing with me.

I was reading a recent blog at 37signals called Why we don’t hire programmers based on puzzles, API quizzes, math riddles, or other parlor tricks and I was wondering what strange tricks I played on security professionals interviewing with me.

I’ve never asked anyone to get on the whiteboard and diagram a secure network. I’m not sure what they’d draw (although it might be an interesting exercise).

I’ve asked questions ranging from:

At some point it’s less about the particular questions I ask and more about asking questions the interviewer isn’t expecting. Over the past view years, even very junior candidates come prepped with SANS, OWASP, a flurry of data and articles, ready to answer all of the questions they think I’m going to ask.

Which is why I’m never surprised when they struggle to answer “So what are you passionate about?”

Just in case you’re a candidate prepping for an interview with me, the only trick question is the one you are not prepared for.

As originally posted at jayschulman.com on January 4, 2012.

More Leadership Posts

July 03, 2026

When AI Commoditizes IQ, EQ Becomes Everything

As AI handles analysis and research, emotional intelligence, judgment, and trust become your irreplaceable competitive a...

May 25, 2026

Trust as Valuation: Why Disclosure Now Beats Compliance

As synthetic data floods markets, companies with rigorous disclosure and independent attestation gain competitive advant...

August 29, 2026

Why Meta's AI Layoffs Backfired: The Judgment Problem

Meta's 220% code increase but only 36% shipping gain reveals the real AI crisis: eliminating middle management removed t...