The other day, while interviewing a candidate for my team, it occurred to me that I’ve probably conducted somewhere between four and five hundred interviews over the course of my career. I’ve directly hired well over a hundred people, and considering that most hires involve four or five candidates, that estimate is probably about right.
One advantage of sitting on this side of the table is that patterns become obvious. Most people only experience interviews as candidates, so every one feels unique. I’ve seen enough of them that I know what tends to work, what tends to go wrong, and perhaps most importantly, how people accidentally sabotage what could have been an excellent interview.
Most of what follows applies to any technical interview, though some examples are naturally specific to information security.
The interview isn’t you versus me
The first thing I’d like every candidate to understand is that I’m not your enemy.
Pretty much everyone I’ve ever interviewed is nervous. I understand why, there’s a lot riding on the interaction. A job can shape the next several years of your life. But by the time you’re talking to me, I’ve usually already decided you’re capable of doing the work, or at least capable of growing into it. Otherwise we wouldn’t be having the conversation. I also have work that needs to get done, so I genuinely want someone in that chair to succeed.
That leads to something people often miss: sometimes the interviewer is trying to help you.
If I keep coming back to a particular project on your résumé, there’s probably something about it that I think is interesting. If I ask you to elaborate on an answer, it often means you’re close but you’ve missed an important point, and I’m giving you another opportunity to get there. Don’t assume every follow-up question is a trap. Sometimes it’s exactly the opposite.
The same goes for the little things people panic over. Technical issues happen. People need to reschedule. Life gets in the way. I absolutely want people to be reliable, but I think candidates dramatically overestimate how catastrophic these situations are. I’ve hired people who accidentally ghosted an interview. It’s not ideal, but a sincere explanation goes a long way.
And while we’re on the subject of things candidates worry about far more than interviewers do: I really don’t care what you look like. Dress appropriately for the role, certainly, but unless you look like someone who’d be arrested on sight walking into a Chuck E. Cheese, you’re probably fine.
Tell me about you
This is probably the single most common mistake I see.
Candidates constantly answer questions by saying, “Well, we…” and then proceed to describe what their previous organization accomplished. The problem is that I’m not interviewing your organization. I’m interviewing you.
Tell me what you actually built, the calls you made along the way, and where it went sideways. Sometimes candidates seem to have no identity outside their former employer. It’s a little like going on a first date with someone who spends the entire evening talking about their ex.
If your coworker designed the system, that’s perfectly fine, just tell me what your role was. If you haven’t personally done something, I’d much rather hear, “I haven’t done that, but here’s why I think I could,” than twenty minutes describing somebody else’s work.
The same principle applies when you don’t know the answer to a question- Just say so.
One of my favorite answers is, “I don’t know, but here’s how I’d figure it out.” That tells me you have good judgment and know how to move forward safely when you’re outside your experience. What doesn’t help is trying to answer a completely different question because you learned somewhere that admitting ignorance is a weakness.
Likewise, don’t exaggerate. You’d be surprised how often people lie in interviews. I’m not a perfect lie detector, but I’ve spent my career investigating technical claims and, in many cases, deception. Most experienced interviewers develop a pretty good instinct for it. Even if you manage to convince me, reality has a way of catching up once you’re hired.
I’m hiring judgment, not trivia
Technical ability matters, but judgment matters more.
I love hearing hacker stories. I love clever exploits. But if you spend five minutes telling me how you bypassed your company’s security controls without also telling me how you fixed the problem, you’ve accidentally made yourself sound like a liability instead of an asset. Tell me about the exploit, but tell me about the remediation too. That’s the part I’m really hiring.
Lately I’ve noticed the same thing happening with AI.
Candidates increasingly spend several minutes explaining what ChatGPT or Claude can do. That’s interesting, but I’m hiring a human being. I already have Claude.
Tell me what you contributed. Did you design the prompts? Build the workflow? Validate the outputs? Catch hallucinations? Make sure the process complied with security requirements? Explain the engineering you brought to the table. If your entire pitch is that AI can do the work, you’ve accidentally argued against hiring yourself.
One final thing: don’t feel like you have to agree with me.
I actually enjoy working with people who challenge my assumptions. Strong opinions are healthy. But if you confidently explain why some technology I happen to know a great deal about is terrible, expect me to ask you why. If you’ve thought it through, we’ll probably have a fun conversation. If you’re just repeating something you heard online, it usually becomes obvious pretty quickly.
Finish the interview like you belong there
Near the end of almost every interview, I’ll ask if you have any questions.
Please have some.
Ask about the problems we’re actually trying to solve, or what security culture looks like here day to day. Better yet, ask something that shows you thought about what this organization does before you walked in. It’s one of the easiest opportunities in the interview to show expertise I might never have thought to ask about. If you really can’t think of anything, a great fallback would be “what is the most pressing problem someone in this role can solve?”, or simply ask “So what might I not know about securing a company like this?” or “What might I not know about developing software at a company like yours?”.. whatever fits the role you are applying for. Give the interviewer a chance to talk a bit about their world- people love talking about themselves particularly when it’s on topic, so throwing a little bit of pointed interest their way will build rapport.
The same goes for talking about hobbies. I genuinely enjoy hearing about the interesting things people do outside work. I’ll happily listen to you talk about your hamster farm, but unless you can connect that story back to why it makes you a better engineer, analyst, or security professional, you’re spending precious interview time on something that doesn’t strengthen your case.
On the other hand, if your hamster farm has its own monitoring network, custom communication protocols, and automation systems, now you’ve got my attention.
The biggest thing I’ve learned
After hundreds of interviews, here’s the pattern I’ve noticed. I’m almost never looking for the smartest person in the room. I’m looking for someone I’d trust six months from now when something important breaks.
Someone who’s honest about what they know and what they don’t, who takes ownership of their work, who demonstrates good judgment, and who’s curious enough to keep learning.
Ironically, many of the strongest candidates undersell themselves because they’re afraid of sounding arrogant. Meanwhile, somebody with half their experience walks into the room completely convinced they’re the obvious choice.
Don’t become that person, but don’t let that person beat you either.
An interview is one of the few situations in life where you’re expected to talk about your accomplishments. Tell me about the problems you’ve solved, the decisions you’ve made, and what you learned getting there. You don’t have to pretend you’re perfect, and you don’t have to bluff your way through things you don’t know. In fact, I’d rather you didn’t.
In every interview, assume you are the best candidate I will interview. Maybe not the most qualified, maybe not the one with the biggest name school or former employer, but assume you are my best choice and tell me why, warts and all.
I will always go with the candidate who gives me the best reason to hire them, and that reason is almost always that they can do the job at hand, know their limitations and they’re honest.

Leave a Reply