<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Job Interview in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25499#M2137</link>
    <description>&lt;P&gt;Interesting such a question came up. However one thing to consider in the future might be to have a well documented Limited Liability or Indemnity Agreement where for instance you can code to their hearts content but should anything happen because of their rush to production there is no legal recourse on their part.&amp;nbsp; Even if you would have dropped this bombshell my guess is they probably would have been dazed and confused and would have probably not have moved things further.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2019 17:00:05 GMT</pubDate>
    <dc:creator>RRoach</dc:creator>
    <dc:date>2019-07-17T17:00:05Z</dc:date>
    <item>
      <title>Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22427#M2053</link>
      <description>&lt;P&gt;Had my third phone interview with a company yesterday for a Full Stack Developer role. Never thought my security experience and CISSP would be a detriment to getting hired. The interviewer noticed my CISSP and security experience on my resume and asked me if I was willing to put security aside in the name of building and deploying fast to production. The person I was talking with was one of the CIOs and heading up the new project. I explained that perhaps adding in security from the beginning would save time in the long run and not expose them to possible breaches and rework. Nope, they were going to bolt on security afterward. Got the rejection two hours later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I honestly wish them luck because they are going to need it. Lots of it.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 16:24:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22427#M2053</guid>
      <dc:creator>JohnC</dc:creator>
      <dc:date>2019-05-17T16:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22428#M2054</link>
      <description>&lt;P&gt;Unfortunately, security and convenience are on the two ends of the spectrum, and looks like the company decide to forgo security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like the well-quoted saying (attributed to John Chambers):&amp;nbsp; &lt;I&gt;There are two types of companies: those who have been hacked, and those who don’t yet know they have been hacked.&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the company you interviewed is, or will be very soon, the second type.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 16:49:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22428#M2054</guid>
      <dc:creator>Chuxing</dc:creator>
      <dc:date>2019-05-17T16:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22430#M2055</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/358979237"&gt;@JohnC&lt;/a&gt; I think you dodge a bullet there John. Either that or they were testing you to see if you would say that leaving security out of it was okay. Have you had any feedback from the company/agency?The job was not meant to be. There are plenty nmore out there with your name on. Good luck with the search.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 17:08:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22430#M2055</guid>
      <dc:creator>Gonif</dc:creator>
      <dc:date>2019-05-17T17:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22431#M2056</link>
      <description>&lt;P&gt;In my job hunting I have learned a few new terms like "unicorn", "purple squirrel" and "ghosted/ghosting".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have since coined my own term:&amp;nbsp; "porridge".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's from the story of "Goldilocks and the 3 Bears", where the porridge is "too hot" or "too cold".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had to deal with several companies who didn't want to talk with me because I was "too security", "too risk", "not security enough", etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess you got hit by being "too security".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 18:33:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22431#M2056</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-05-17T18:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22434#M2057</link>
      <description>&lt;P&gt;Dude, was that the type of company that you wanted to work for? There are many more out there that will value your AppSec skills.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 19:54:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22434#M2057</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2019-05-17T19:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22441#M2061</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/358979237"&gt;@JohnC&lt;/a&gt;,&amp;nbsp;if that was just a test question --- and I sincerely hope it was --- there may have been other factors that contributed to your rejection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand, if they actually intended to trade security for convenience, be glad you didn't grab that --- coz you'd probably have had a very hard time there, given the CIO's attitude.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even worse, should security flaws be found in the developed system at a later stage, that organization might just turn the developers into scapegoats...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 20:46:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22441#M2061</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-05-17T20:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22466#M2062</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/358979237"&gt;@JohnC&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;The interviewer noticed my CISSP and security experience on my resume and asked me if I was willing to put security aside in the name of building and deploying fast to production. The person I was talking with was one of the CIOs and heading up the new project.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Sorry, &lt;STRONG&gt;one&lt;/STRONG&gt; of the CIOs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As others have pointed out, you have had a fortunate escape.&amp;nbsp; Yes, it is disheartening to lose a job (prospect), but it would have been possibly much worse to lose your soul by working for these clowns.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Over the years I have come to disregard most of the "advice" on how to handle job interviews.&amp;nbsp; Best to be honest.&amp;nbsp; If they are that stupid (and remember George Carlin's advice to consider how stupid the average person is--and then to recall that half of them are dumber than &lt;STRONG&gt;that&lt;/STRONG&gt;) then it would be painful working for them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;I honestly wish them luck because they are going to need it. Lots of it.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;And you are lucky not to be involved ...&lt;/P&gt;</description>
      <pubDate>Sat, 18 May 2019 18:08:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22466#M2062</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-05-18T18:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22506#M2066</link>
      <description>&lt;P&gt;It's as likely a 'need to find excuses' to exclude a candidate.&amp;nbsp; For some reason many companies find it necessay to manufacture a reason; like being 'too security', being 'overqualified', 'not a good cultural fit' etc&amp;nbsp; &amp;nbsp;And then some people have forgotten or never bother to think that security is generally a facilitator of many service, rather than the converse.&amp;nbsp; Where would the www be without SSL/TLS?&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 09:55:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22506#M2066</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-05-20T09:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22894#M2088</link>
      <description>&lt;P&gt;The key bit here is maybe that he posed the question as an either or, but it doesn't have to be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My response would be 'If we have a risk, I'm more likley to be able to identify, understand and escalate that risk (quickly &amp;amp; efficiently) to my line manager with a clear picture of the potential consiquences, It would then be the leaderships desicion as to whether the risk is prohibative and needs aditional controls, or is within the risk appatite of the company'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An understanding that controls have costs, that to understand if it's worth securing you need to know the cost and the value,&amp;nbsp; is imho one of the core teachings of CISSP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 12:57:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22894#M2088</guid>
      <dc:creator>ResetE</dc:creator>
      <dc:date>2019-05-29T12:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22925#M2091</link>
      <description>&lt;P&gt;Sounds like the interviewer never heard of SecDevOps.&amp;nbsp; A DevOps approach focusing on IaC and SaC, has a good potential to improve overall security posture and respond to vulnerabilities quickly.&amp;nbsp; So it's simply not a case of speed or security, but speed with security.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 07:03:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/22925#M2091</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-05-30T07:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25499#M2137</link>
      <description>&lt;P&gt;Interesting such a question came up. However one thing to consider in the future might be to have a well documented Limited Liability or Indemnity Agreement where for instance you can code to their hearts content but should anything happen because of their rush to production there is no legal recourse on their part.&amp;nbsp; Even if you would have dropped this bombshell my guess is they probably would have been dazed and confused and would have probably not have moved things further.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 17:00:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25499#M2137</guid>
      <dc:creator>RRoach</dc:creator>
      <dc:date>2019-07-17T17:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25694#M2146</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/783051913"&gt;@Steve-Wilme&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Sounds like the interviewer never heard of SecDevOps.&amp;nbsp; A DevOps approach focusing on IaC and SaC, has a good potential to improve overall security posture and respond to vulnerabilities quickly.&amp;nbsp; So it's simply not a case of speed or security, but speed with security.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I thought it was DevSecOps??&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you have some DevOps wags who say security is already in it, so you don't need to talk about 'SecDevOps' or 'DevSecOps' as separate things...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have to wonder about the level of knowledge of some of the infosec 'leaders' I've met with on interviews.&amp;nbsp; I dealt with one CISO when interviewing for an infosec analyst role that would have deal heavily with third party risk management who, surprisingly to me, didn't seem to understand the different SOC reports (1,2,3, etc) nor had ever heard of Shared Assessments' SIG Report.&amp;nbsp; Sigh.&amp;nbsp; (oh, and they decided to reject me for 'better candidates'... yeah, right).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 14:49:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25694#M2146</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-07-22T14:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25705#M2148</link>
      <description>&lt;P&gt;Your post is very informative.&amp;nbsp; However, I do not wish anyone luck that wants to bolt on security later and that trashes a good person like yourself, just for wanting to do what basic due care requires.&amp;nbsp; I wish you an even better opportunity later since I applaud your honesty and integrity.&amp;nbsp; &amp;nbsp;We need strong laws at the international, national, state and local levels of government that make it a civil and criminal offense to do that kind of software engineering.&amp;nbsp; How is it that a totally irresponsible engineering approach is accepted?&amp;nbsp; If any avionics, automotive, or other traditional industry took that kind of approach to any other discipline other than information technology, they would get sued to the point of bankruptcy.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to see liability lawyers start suing information technology firms like they do the medical industry, world-wide, so there is nowhere to hide, so as to stop all this nonsense.&amp;nbsp; &amp;nbsp;The likely failure that will ensue in the situation you describe will be the burden of disaster placed on the unfortunate consumer of their miscreant product.&amp;nbsp; I hope that the GDPR regulators get wind of this and watch them like a hawk and when their irresponsible plan backfires that they get fined and sued out of existence.&amp;nbsp; &amp;nbsp;Where is the Ralph Nader we need for the software industry?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due care and due diligence is mandatory for all other professions except for application developers and hosting organizations of all these deformed applications.&amp;nbsp; It is time now for this lax state of affairs for software engineering to stop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 18:10:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25705#M2148</guid>
      <dc:creator>Frank_Mayer</dc:creator>
      <dc:date>2019-07-22T18:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25706#M2149</link>
      <description>&lt;P&gt;We need a Ralph Nader type crusader for the software industry.&amp;nbsp; It is ridiculous that in the 21st Century that the software engineering based industries and information technology firms still operate with the buyer beware approach of the 19th century.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 18:06:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/25706#M2149</guid>
      <dc:creator>Frank_Mayer</dc:creator>
      <dc:date>2019-07-22T18:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/47663#M3351</link>
      <description>the citation is to my knowledge (also) attributed to Robert Muller, former director of the FBI&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:49:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/47663#M3351</guid>
      <dc:creator>RRehm</dc:creator>
      <dc:date>2021-09-28T15:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Job Interview</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/47664#M3352</link>
      <description>Same once happened to me avoiding being too technical, so at the end I got the response that I wasn't technical enough. And I was applying for a strategic role on how to develop the DB solution in a more secure way.&lt;BR /&gt;&lt;BR /&gt;Maybe it is just an excuse for saying I don't like you...</description>
      <pubDate>Tue, 28 Sep 2021 15:53:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Job-Interview/m-p/47664#M3352</guid>
      <dc:creator>RRehm</dc:creator>
      <dc:date>2021-09-28T15:53:26Z</dc:date>
    </item>
  </channel>
</rss>

