Q: How will you secure a CI/CD pipeline? Q: Developers sometimes see security tooling/controls as a bottleneck, how will you approach such discussions? Q: There are 10 things to do when it comes to securing things, how will you prioritize them? Q: How would you design a secure 3-tier web application?