I applied online. The process took 2 weeks. I interviewed at Splunk (San Jose, San Jose) in Mar 2024
Interview
There was a total of 5 interviews: 3 technical interview, 1 with the hiring manager and +1 with HR (initial contact + follow up calls)
Questions were okay, medium to hard questions but a lot of interviews for a very specific role and skills, salary range was in the average, I would say not good for this specialized position, declined due to this, had 40% more money in another company!
A lot of skills required and I felt salary was not accurate to what they were looking for.
Interview questions [6]
Question 1
How will you get advantage of SQLi to escalate privileges
I applied online. The process took 2 weeks. I interviewed at Splunk in Jan 2024
Interview
It was an awful experience, that left me questioning my abilities. Firstly, the virtual interviews were not recorded, the first interviewer was passively racist, they started by interrupting my response to the "tell me about yourself question" by saying "please i don't want long long answers, just straight to the point" they went ahead to ask the first question and after responding, they literally started yelling at me saying i was wasting their time and asked me to move to next question if i did not have the answer to the question, they went ahead to say even i answered correctly they preferred if i answered differently.
It became a bit of a back and forth in raised tones, with me trying to accurately respond to their satisfaction, i eventually succumbed and asked them what response they were expecting and they responded "i don't want to go into that now", and they proceeded to display a code snippet to identify vulnerabilities, after identifying they responded saying "well not all vulnerabilities are exploitable, so how do you convince a developer to fix code' i was exhausted at that point.
The first session had only 2 questions but lasted over an hour with the back and forth and leaving me confused at how this was a real interview that had just happened, the second session after 4 minutes and was slightly better after the interviewer noticed i was rattled and tried to calm me down.
The third interviewer was sitted on the floor and asked me to threat model a product, without the system design or architecture and spent over 20 mins trying to explain system design and stated "i have no white board to draw the application flow", i had to draw out the design and proceed to threat model.
The entire process was an uncoordinated and traumatising 4 hours , with me reaching out to the recruiters after weeks for feedback or acknowledgment of the interviews.
p.s - saw a notification from one of the team members rooting for individuals from a certain ethnicity for the same role. really sad experience.
Interview questions [1]
Question 1
TLS HANDSHAKE
threat modelling
api vulnerabilities
code snippet secure review
I applied online. I interviewed at Splunk (Hyderābād) in May 2023
Interview
The worst interview process ever, and if your interviewer is a Desi(Indian) guy, you can't stand your chance against their ego. The process consists of 3 rounds. 1. A shortlist technical round and then 2 hiring managers. 1. round was good because the interviewer was very humble and asked proper security questions. -2 and 3 round was taken by all desi guys, so the questions will be vague and will not make sense even if you answer them they will try to scare u and make u nervous so u get fail. Also when I asked them to follow back questions they said u are not taking my interview, like seriously! These guys are in the principal eng position and still don't know how to behave.
Interview questions [1]
Question 1
OWASP top 10 and mitigation, Xss mitigation (the interview girl didn't even know proper mitigation), Threat modeling, container security, TLS handshake-based vague questions.