
Candidate Reflects on Failed DevSecOps Interview and Subsequent Training
Failed a DevSecOps interview last month after 3 years in DevOps, didn't expect the security questions to hit that hard. The candidate had three years of DevOps experience in a fintech SaaS company, working with pipelines, containers, Kubernetes, and Terraform, but struggled with security-focused questions during the interview. They froze on threat modeling for a three-tier web app, provided weak answers on policy-as-code and secrets management, and received feedback that their security fundamentals were insufficient for a senior role. Afterward, they spent six weeks on structured training in DevSecOps topics like secure SDLC, SAST/DAST integration, and threat modeling frameworks. The post also mentions Glassdoor’s reported median DevSecOps engineer salary of $182,147 as of March 2026.