Aller au contenuAller au pied de page
  • Emplois
  • Entreprises
  • Salaires
  • Pour les employeurs

      Boostez votre carrière

      Découvrez votre salaire potentiel, décrochez des emplois de rêve et partagez vos témoignages de manière anonyme.

      employer cover photo
      employer logo
      employer logo

      Synchrony

      Employeur impliqué

      À propos
      Avis
      Salaires et avantages
      Emplois
      Entretiens
      Entretiens
      Recherches associées: Avis sur Synchrony | Offres d’emploi chez Synchrony | Salaires chez Synchrony | Avantages sociaux chez Synchrony
      Entretiens chez SynchronyEntretiens d’embauche pour Cyber Threat Analyst chez SynchronyEntretien chez Synchrony


      Glassdoor

      • À propos
      • Récompenses
      • Blog
      • Nous contacter
      • Guides

      Employeurs

      • Compte employeur gratuit
      • Centre employeur
      • Blog pour les employeurs

      Informations

      • Aide
      • Règles de la communauté
      • Conditions d'utilisation
      • Confidentialité et choix publicitaires
      • Ne pas vendre ni partager mes informations
      • Outil de consentement aux cookies

      Travailler avec nous

      • Annonceurs
      • Carrières
      Télécharger l'application

      • Parcourir par :
      • Entreprises
      • Emplois
      • Lieux

      Copyright © 2008-2026. Glassdoor LLC. « Glassdoor », son logo, « Worklife Pro » et « Bowls » sont des marques déposées de Glassdoor LLC.

      Entreprises suivies

      Tenez-vous au courant des dernières opportunités et profitez de conseils d’initiés en suivant les entreprises de vos rêves.

      Recherche d’emplois

      Obtenez des recommandations et des mises à jour personnalisées en démarrant vos recherches.

      Entretien pour Cyber Threat Analyst

      9 août 2019
      Candidat à l'entretien anonyme
      Stamford, CT
      Aucune offre
      Expérience négative
      Entretien facile

      Candidature

      J'ai postulé via un recruteur. Le processus a pris 6 semaines. J'ai passé un entretien chez Synchrony (Stamford, CT) en juill. 2019

      Entretien

      This company has no integrity whatsoever. I was offered a role and after 3 weeks(i rejected all my other offers at hand at that point) i was told that the position is no longer available due to a budget freeze! After a day or so i was contacted about the same role through a different vendor and considering the security advances the first interviewer bragged about i wanted to work with their team so gave it another shot. Turns out their security team is a big JOKE! This time after 3 successful rounds the last round was with two lead engineers- shame they are even called that. The interviewers were not qualified to be interviewing senior candidates they had at best diploma level security knowledge - i have no idea how their security team is even running with people like this? If you are a security professional please read the interview questions and decide for yourself if you want to get this low with this low level team.

      Questions d'entretien [5]

      Question 1

      1.The technical leads asks me to explain attacker life cycle as to how he gets in to lateral movement. Then i start talking about MITRE matrix and then he cuts me off saying "oh that is only used after the attacker gets into the network"- what a shame! Security team that has no minimum knowledge! when in realty mitre has a pre-attack and post attack matrix. The attack framework talks about Techniques from initial access to command and control.
      Répondre à cette question

      Question 2

      The interviewer talked about using brute force for lateral movement .. ->which is not stealth and most attackers do NOT use this technique instead they leverage existing tools on the network such as vulnerable remote access tools
      Répondre à cette question

      Question 3

      They asked me about DLP triage and incidents-- no where in my resume nor requirements DLP was mentioned, which shows that they had no clue what they are even interviewing for?
      Répondre à cette question

      Question 4

      Asked about privilege access .. when trying to explain from attacker perspective they cut me off to say in a large environment an attacker would use user accounts with lower privileges to admin accounts and then establish lateral movement - which is just one vector? I guess that is all he knew?
      Répondre à cette question

      Question 5

      For initial access i talked about drive by downloads/watering hole techniques and methods to mitigate and detect it. After a while the other interviewer asks me - tell me a way an attacker from the outside would get into an organization?? well, drive by downloads is one such technique. I also mentioned valid accounts and spear phishing. Also when i mentioned drive-by downloads the interviewer mentioned that this technique is after an attacker has access to the system (LOL *BANGS MY HEAD TO THE WALL*). This technique is USED for initial compromise. How are these people even security professionals?
      Répondre à cette question