Here are 30 fundamental concepts that come up in every security role interview:
1. Security Compliance Frameworks (ISO 27001, SOC 2, NIST)
2. Threat Modeling Frameworks (STRIDE, PASTA)
3. Security Automation & Orchestration (SOAR)
4. Vulnerability Management & Patch Cycles
5. Container Security (Docker, Kubernetes)
6. Identity and Access Management (IAM)
7. Encryption Standards (AES, RSA, TLS)
8. Penetration Testing Methodologies
9. Secure API Design & OAuth 2.0
10. Security Hardening Techniques
11. Authentication vs Authorisation
12. Public Key Infrastructure (PKI)
13. Incident Response Lifecycle
14. Defense in Depth Strategy
15. Zero Trust Architecture
16. Firewall Rules & ACLs
17. Least Privilege Principle
18. DDoS Mitigation Strategies
19. OWASP Top 10 Vulnerabilities
20. Security Logging & Monitoring
21. SQL Injection & XSS Prevention
22. Network Segmentation & VLANs
23. Supply Chain Security & SBOMs
24. Certificate Management & Rotation
25. Cloud Security Posture Management
26. Endpoint Detection and Response (EDR)
27. Intrusion Detection vs Prevention Systems
28. Cryptographic Hashing (SHA-256, bcrypt)
29. CIA Triad (Confidentiality, Integrity, Availability)
30. Security Information and Event Management (SIEM)
Bookmark this for your next interview prep.
What would you add to this list?
Thanks to Saed for creating this list from his security interview experience. I hope it helps someone out here.