What interview questions should you ask when hiring a DevSecOps engineer?


622 views2 Upvotes30 Comments

CTO in Education, 1,001 - 5,000 employees
I would require the candidate to elaborate which tools is he/she is using and what they think of these tools in term of security.
Computer Science Lecturer in Education, 51 - 200 employees
What are you most excited about accomplishing with DevOps in this organization?

What languages can you code in?
What are the top DevOps tools you have experience with?
What will you do in the first three months of being a DevOps engineer?

Talk about a recent professional achievement using DevOps practices?

SVP - Software Engineering in Finance (non-banking), 201 - 500 employees
I would certainly ask around their tooling, but that also changes over time. I would also ask the person how they think about automation in general.
The reality is that a good DevSecOps person will think obsessively about taking manual steps out of the process through automation. I would also ask about how they monitor and ensure the automated processes work and what they would do to build resiliency “when” (not “if”) you run into prod support issues.

On the Sec part of DevSecOps, I would ask the person around how they would implement authentication and authorization to ensure the workflows are secure from outside intruders and internal team members doing things they shouldn’t be doing.
2
Chief Technology Officer in Software, 51 - 200 employees
Questions around Devops and Security. Focus around configuration management , containerization , continuous integration , automation testing , branching, Jenkins, version control. Flavour of docker and ansible. 

If basics are the point , the resource is hired. 
Director of IT in Education, 1,001 - 5,000 employees
Questions surrounding the origin story of how the applicant chose this field; responses can indicate their level of commitment and willingness/desire to continually invest in self-improvement/growth.

Moving forward through the employment journey, asking them to expand on their challenges, resolutions, accomplishments AND failures.

Ask additional questions to get a sense of interpersonal skills & level of team player aptitude.
Director of IT in Education, 1,001 - 5,000 employees
Questions surrounding the origin story of how the applicant chose this field; responses can indicate their level of commitment and willingness/desire to continually invest in self-improvement/growth.

Moving forward through the employment journey, asking them to expand on their challenges, resolutions, accomplishments AND failures.

Ask additional questions to get a sense of interpersonal skills & level of team player aptitude.
Secure Facilities Information Technology Manager in Manufacturing, Self-employed
I would focus on what currently are the tools they are using, with a deep dive into what they like and don't like about it. 
Director of IT in Manufacturing, 10,001+ employees
Can you describe a maturity model framework of DevOps and now to assess a current state for an organization 
Director of IT in Healthcare and Biotech, 1,001 - 5,000 employees
Why is security important in DevOps?
Why do you want to work in DevOps security?

How do you measure success of your projects?

What tools have you used?

Director of IT in Healthcare and Biotech, 501 - 1,000 employees
What tools are you currently familiar with - which do you prefer and why?
What are/were your top five initiatives at your current/last organization?
What methodologies do you implement in order to ensure effective and quality implementations?
In your own words, what are the responsibilities of a DevSecOps engineer?
Of these responsibilities, what do you feel are the top three most important?
How did you end up in this field of engineering?

Content you might like

Attack Detection & Analysis22%

Vulnerability assessment and patching54%

Security Awareness Training15%

Incident Response8%

Other (comment below)0%


507 PARTICIPANTS

1.2k views4 Upvotes1 Comment