25 Security Engineer Interview Questions and Answers
25 security engineer interview questions with what each one tests and what a strong answer includes, plus which suit network, identity or generalist roles.
These 25 security engineer interview questions are for the person hiring: a security manager, Head of Security or CISO. They cover fundamentals, design and change decisions, and short hands-on tasks, and each comes with what it tests and what a strong answer includes. A table further down matches the questions to the kind of security engineer you are hiring.
“Security engineer” covers very different jobs. In one company it means firewalls and endpoint policy; in another it means identity and Active Directory; in a third it means a generalist who owns a bit of everything. A CV lists every tool either way, so the questions below focus on decisions and configuration, which is where the difference shows. For questions that apply to every cyber role, see the main list of cyber security interview questions.
Security engineer interview questions on the fundamentals
Use two or three to check the foundations. The design and hands-on sections tell you far more.
| Question | What it tests | What a strong answer includes |
|---|---|---|
| 1. What does defence in depth look like in an environment you have worked on? | Experience behind the principle | A real example of layered controls, such as email filtering, endpoint protection, network segmentation and monitoring, and how a failure in one layer was caught by another. |
| 2. What is the difference between a stateful and a stateless firewall, and what does a WAF add? | Network controls | A stateful firewall tracks connections; a stateless one judges each packet alone. A web application firewall inspects HTTP traffic for attacks such as SQL injection, but it does not replace fixing the application. |
| 3. How does Kerberos work at a high level, and where is it attacked? | Identity in Windows domains | A ticket-granting ticket from the domain controller, then service tickets for each service. Knows the common attacks: Kerberoasting of service account passwords, AS-REP roasting, and forged tickets after the krbtgt account is compromised. |
| 4. What is the difference between hardening and patching, and how do you set a hardening baseline? | Configuration discipline | Patching fixes known flaws; hardening removes attack surface through configuration. Starts from a recognised baseline such as the CIS Benchmarks, then documents exceptions with owners. |
| 5. How does PKI work, and what goes wrong with certificates in practice? | Real-world cryptography | Certificate authorities, chains of trust and trust stores. Then the practical failures: expired certificates causing outages, exposed private keys, weak revocation checking, and the case for automating renewal. |
| 6. What is network segmentation for, and how would you prove it works? | Testing, not assuming | Limits how far an attacker can move. Proves it by testing from each zone, for example scanning or reviewing flow logs, not by pointing at a network diagram. |
| 7. What does Zero Trust mean beyond the buzzword? | Clear thinking | Verify every request based on identity and device health, give least privilege, and assume a breach has already happened, as set out in NIST SP 800-207. Admits it is a direction, not a product. |
Design and scenario questions for security engineers
This is where engineering judgement shows. Listen for whether the candidate balances security against the business, and whether they think about how a change could break things.
| Question | What it tests | What a strong answer includes |
|---|---|---|
| 8. A business team needs an emergency firewall change tonight to open a port to the internet. Do you approve it? | Change judgement | Neither a reflexive yes nor no. Finds out what is really needed, then narrows it: specific sources, one port, one destination, an expiry time, logging and monitoring, and sign-off from whoever owns the risk. |
| 9. You inherit a firewall with 2,000 rules and nobody knows what half of them do. Where do you start? | Cleaning up safely | Uses hit counts and flow logs to find unused rules, flags any-to-any rules first, finds owners, and removes rules in stages under change control while watching for breakage. |
| 10. How would you roll out MFA to the whole company without breaking things? | Rollout planning | Inventories applications, blocks legacy authentication that bypasses MFA, phases the rollout, keeps break-glass accounts, uses phishing-resistant methods for admins, and prepares the help desk. |
| 11. A Group Policy change has disabled Microsoft Defender on half the estate. How do you find out what happened? | Investigating configuration changes | Finds the policy and who changed it, using directory change auditing, reverts it, and treats it as a possible attack until proven otherwise, because disabling defences is a common attacker step. |
| 12. Design remote access for 500 staff and 20 contractors. | Access design | Identity-based access with MFA and device checks, access to specific applications rather than the whole network, separate time-limited contractor access, and logging. Avoids a flat VPN onto everything. |
| 13. A new web application goes live next month. What do you put in place before launch? | Securing a service end to end | TLS configuration, authentication, rate limiting, secrets management, hardened hosts, a WAF where it fits, logging, and a security test before go-live. |
| 14. Leadership wants admins to stop using their everyday accounts for admin work. How do you do it? | Privileged access | Separate admin accounts, dedicated admin workstations for the most sensitive systems, a tiered admin model, just-in-time elevation, and no email or browsing on admin accounts. |
| 15. Logs show a Linux server’s SSH service being brute-forced from the internet. What do you change? | Practical hardening | Key-based authentication only, no root login, SSH reachable only from a bastion or VPN, rate limiting, and a check of whether any attempt succeeded. |
| 16. A critical patch breaks a business application. What do you do? | Risk trade-offs | Compensating controls such as isolating the system, a documented risk acceptance with an owner and an expiry date, pressure on the vendor for a fix, and a plan to patch. |
| 17. How do you know your security controls actually work? | Validation | Tests them: attack simulation, purple teaming against MITRE ATT&CK techniques, and control validation, rather than assuming a deployed tool is a working one. |
Hands-on security engineer interview tasks
Short tasks to run in the interview. Prepare each one with demo data. Watching a candidate review real configuration for ten minutes tells you more than any answer above.
| Task | What it tests | What a strong answer includes |
|---|---|---|
| 18. Here is a firewall export between a user network and a server network. What would you change? | Rule review and segmentation | Spots overly broad rules, rules shadowed by earlier ones, management ports open to users, and missing logging on denies. |
19. Here is the output of ls -la on a Linux web server. What is risky? | Linux permissions | Finds world-writable files, unexpected SUID binaries, configuration files with secrets that everyone can read, and files owned by the wrong user. |
| 20. Here is a Group Policy report. Which settings weaken the domain? | Windows hardening | Finds settings such as WDigest storing credentials in memory, SMBv1 enabled, overly broad Defender exclusions, and ordinary users with local admin rights. |
| 21. Here is a summary of a packet capture. Which traffic does not belong? | Network analysis | Spots DNS tunnelling (long, random subdomains), cleartext protocols carrying credentials, and connections to unexpected destinations. |
| 22. Write a script that lists local administrators across 50 servers. | Automation | Uses PowerShell remoting or Python sensibly, handles servers that do not respond, outputs to a file, and runs read-only. |
23. Here is an sshd_config file. Harden it. | Service hardening | Disables root login and passwords, restricts which users or groups can connect, limits authentication attempts and turns off features that are not needed. |
| 24. Here is a TLS scan of our website. What would you fix? | Web transport security | Disables TLS 1.0 and 1.1 and weak ciphers, adds HSTS, fixes the certificate chain and sets up renewal before expiry. |
| 25. Sketch a three-tier web application and show where the security controls go. | Architecture | Load balancer and WAF at the edge, application servers in their own zone, databases unreachable from the internet, tight rules between tiers, a bastion for admin access, and central logging. |
For task 23, a strong answer includes settings like these:
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
AllowGroups ssh-users
MaxAuthTries 3
X11Forwarding no
Which questions for which kind of security engineer?
Match the questions to what the person will own. Asking an identity specialist to design network segmentation, or a network engineer about Kerberos attacks, tells you little about the job you are filling.
| Kind of security engineer | What they own | Questions to use |
|---|---|---|
| Infrastructure and network | Firewalls, segmentation, remote access, Linux hosts | 2, 6, 8, 9, 12, 15, 18, 21, 23, 25 |
| Endpoint and identity | Active Directory, Group Policy, MFA, privileged access | 3, 4, 10, 11, 14, 20, 22 |
| Generalist | A bit of everything, often in a small team | 1, 5, 7, 13, 16, 17, 19, 24 |
Cloud and application security engineers need their own sets. The questions above still help with fundamentals, but cloud roles turn on identity and permission design in AWS, Azure or GCP (see these cloud security interview questions), and AppSec roles on code review (see these application security interview questions).
What are the red flags in a security engineer interview?
- Security at any cost. Rejects every change request, or proposes controls without thinking about what they would break.
- Tools instead of reasons. Answers “we’d buy a tool for that” without explaining what the tool should actually achieve.
- No testing. Assumes a control works because it was deployed.
- No change discipline. Would make production changes without a plan to roll back.
- Configuration they cannot explain. Has used a setting for years without knowing what it protects against.
Why a hands-on task beats any security engineer interview question
Describing least privilege is easy. Spotting the one rule that quietly allows lateral movement in a long firewall export is the job, and you only see it when someone does it in front of you. The hands-on tasks above help, but they are short and need careful preparation.
A hands-on assessment goes further: the candidate reviews real configuration, works in a live system, and has to justify what they find.
Used before the interview, this tells you who can do the work. The interview then focuses on design trade-offs, how they handle change, and anything the assessment flagged.
Frequently asked questions
What questions are asked in a security engineer interview?
Expect fundamentals such as firewalls, Kerberos and PKI, design questions such as remote access or privileged access, and change scenarios like an emergency firewall request. Good interviews also include a hands-on task, such as reviewing a rule set or hardening a configuration file.
What is the difference between a security engineer and a security analyst?
A security analyst mostly monitors and investigates: working alerts and responding to incidents. A security engineer mostly builds and maintains the controls: firewalls, identity, hardening and security tooling. Many smaller teams blend the two.
How technical is a security engineer interview?
It should be very technical, because the job is configuring and changing real systems. At least one part of the interview should involve real configuration, not only questions about it.
How do you assess a security engineer before the interview?
Give them a piece of the real job: a firewall rule set to review, a Group Policy configuration to audit, a host to harden or a packet capture to read. Score what they find and how they justify it, then use the interview to explore their reasoning.
How CyberHire tests security engineers before the interview
CyberHire is cyber technical screening that shows you who can harden the estate before you book an interview. Pick the ready-made security engineer assessment or paste your job specification and generate one. Candidates review real configuration and work in live systems: firewall rule analysis and an emergency change to approve or reject, Group Policy audits, Linux permissions and hardening, and packet capture analysis.
Every candidate is scored the same way, with integrity signals next to each score, and you see what they found and how they justified it. See how it works for security engineer hiring. If you would rather not build the assessment yourself, our team will build it with you.
Hiring a security engineer?
See who can harden the estate before you interview anyone.
Send us the job spec. Within 48 hours we send you a hands-on assessment built around it, in your branding, free. Real firewall rules, Group Policy and Linux hosts, scored the same way for every candidate.