i have a tech screen at Meta for security analyst coming up next week w 20 mins of tech questions and 20 of threat modeling. i’ve never done a threat modeling interview before so im wondering if i need to draw something or if its all verbal

like
Posting as :
works at
You are currently posting as works at

Also MITRE ATT&CK

like

I would make sure you can speak to understanding the process and that it’s a structured approach. Also familiarize yourself with common techniques like STRIDE, OWASP Threat Dragon, and Microsoft SDL Threat Modeling. Understand how these techniques can be used to identify different types of threats. Good luck!

Related Posts

How much are your biweekly paychecks after taxes, insurance, 401k contributions, etc. and how much of each paycheck do you tuck into savings?

likesmarthelpful

Okay guys give me a list of things to lower my taxable income. Make yearly with wife 200k.

like

Are y’all waiting to do a mega backdoor Roth to see what they do about build back better this year or just moving forward with it?

like

Is there a definitive guide to cost of living? The obvious cost of living centers (SF, NYC, LA etc.) get covered a lot, but I’m wondering where my city falls. It’s a modest Midwest city with ~100k residents but is a relatively touristy spot. It often feels like a MCOL area but I’m not sure how to adequately judge that, and it would be helpful to know when comparing salaries and the like.

Welcome and thank you for joining this bowl. I'm hoping that this will be a place where fishbow-lers can respectfully share their experiences of toxicity at companies that continue to harbor these little "corporate terrorist". But most importantly, I want people to be heard without being censored, which is what Glassdoor, Indeed and LinkedIn seem to be doing on behalf of some companies.

like

Billables are low this month. Like I have 65 billable hours in so far. I’ve messaged partners over the last week to try and get more cases but there are tons of new associates who were just onboarded and were at a low point for business. I’m freaking out

like

Feel like I’m going to turn out to be a loser doing ID and be making crap money forever.

like

Hi, I am looking to be referred into some top consulting firms. I am a Project Coordinator at Nielsen with 1 YOE. I have applied thru various job portals but the application does not seem to be viewed or going forward. Would be really helpful if my fellow fishes can refer me. I will be happy to discuss further on this and share my CV. Have a good day!

like

Can anyone please share the exact address of the AMEX Bangalore office location?!

Hi friends,
What is the minimum criteria for IJP at KGS and how much is it feasible?
Will it be better to look outside or go with IJP?

EY FAAS vs KPMG AAS, which one is better?

like

Wanting to switch from litigation to in house. What should I make sure I do before I start applying? Do referrals from someone inside a company matter that much when applying? I'm burnt out, I need an escape from billables. Help me out!

like

Amazon recruiter reached out and wants to know my general compensation expectations before first interview. Very little info available on role but seeing $150k-$250k total compensation reported. Is this too wide of a range to give them?

like
like

Hello

I've been interviewed by @Amazon on 8th July and even after multiple follow up emails, there's no update. Any suggestions?

like

What technical skills are a necessity for product managers?

like

Hello Team,

GBT team inform to submit the card details for travel and hotel booking. When I am trying to submit the details getting some issue like enter your RSA securid passcode as well as help me how I can login into concure application.

like

Does anyone know about fidelitys platform, base, compensation and goals?

like

🎇What’s your biggest win from 2021?

Drop it below, let’s celebrate 🥳

like

Additional Posts in Cyber Security Bowl

CCSP (cloud security certification) is it worth to do ?

like

Security TPM on-site at big tech, how would you prepare/review? No coding. Expect high level q’s on vuln. Analysis& arch. design from security POV. I do NOT have an engr. Background. 1wk to prep

like

On a phone call today, my client suggested our project team provide 24/7 coverage for scanning support. My team size is two, including myself.

Post Photo
likefunnysmart

What other professional services firms have people who have technical skills. Most the people I work with are security paper pushers who couldn’t tell you basic security shit.

like

Any tips or tricks for CSX certification?

like

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

As more and more companies institute a work from home policy, I think it will gradually become the norm. As a 28 year old man who wants to settle down soon, which city would you recommend I look into, assuming me and my partner can work from home? I work in Cybersecurity so would prefer to be closer to the jobs in my field without having to live in the same city.

like

Laterals to Deloitte Cyber from other B4: Can you describe your interview process and what each one entailed? TIA!

like

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

Views on carbon black as a product?

helpful

Has anyone made the move from cyber security at the Big4 to cyber security for media companies? For example Disney or Warner Bros.

How did you manage it?

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Would you expense a speeding ticket on your way to an IR?

funnylike

Anyone else at CyberArk Impact this week? Anything exciting going on?

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

Georgia Tech Cybersecurity masters or the analytics masters? Currently in a cyber role at Deloitte. I was thinking it might be better to do the analytics master and get a CISSP. I feel like there is more value in the cissp than a MS cybersecurity

like

Anyone ever heard of or worked for Sygnia?

like

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal