Candidatei-me por meio de recrutador(a). O processo levou 2 semanas. Fui entrevistado pela Sigmasoft em mai. de 2025
Entrevista
The interview process consisted of three rounds.
L1 focused on assessing technical fundamentals like OWASP, vulnerability types, and secure coding concepts.
L2 was a hands-on round where I was asked to identify and exploit real-world web and API vulnerabilities in a lab setup.
L3 combined technical depth with managerial questions, including scenario-based problem-solving, risk prioritization, and communication with stakeholders.
Overall, the process was structured to evaluate both depth of knowledge and practical application.
Perguntas de entrevista [1]
Pergunta 1
I cleared all interview rounds successfully.
L1 covered fundamentals like OWASP Top 10, secure coding, and application security basics.
L2 was a hands-on practical round where I demonstrated exploitation techniques such as IDOR, SSRF, and misconfigured access controls in a real-world-like environment.
L3 included both technical and managerial discussions, where I explained my approach to threat modeling, remediation strategy, and communicating risks to developers and leadership.