I interviewed for a Senior Product Security Engineer position and found a significant mismatch between the published job description and the actual interview process.
The job description heavily emphasized application security, threat modeling, anti-abuse initiatives, SSDLC improvements, incident response, fraud prevention, cryptography, and security architecture. Based on the description, I invested considerable time preparing around product security and application security topics relevant to the role.
However, during the interview, the hiring manager explained that the role was primarily focused on building and designing large-scale Java web services and handling large datasets. The interview itself was almost entirely centered on software engineering, with little to no discussion of application security, threat modeling, secure design, abuse prevention, vulnerability management, or other areas typically associated with a senior product security position.
There were also some scheduling challenges during the recruiting process, including a missed recruiter meeting that required rescheduling and delays joining scheduled calls.
The interviewers themselves were professional and the technical discussions were reasonable, but I believe the role would be more accurately represented as a Security Software Engineer or Backend Engineer within a security organization rather than a traditional Product Security Engineer role.
My recommendation to future candidates is to clarify early in the process how much of the role is focused on software engineering versus product security, and what percentage of the interview process evaluates each area.