
How to interview (founding) security engineers
How do you hire your startup’s first security engineer?
Over the last few months, I’ve been through half a dozen interview processes for founding security engineer roles. Here’s what I think actually works, and what’s a waste of everyone’s time.
In short:
- Use your standard engineering interviews.
- Tweak the system design interview more towards security.
- Use the behavioural interview to understand how they’ll work with (and not against) your engineers.
Don’t use “what’s insecure about this HTTP handler” puzzles.







