I applied online. I interviewed at Spotify in Nov 2020
Interview
Applied online. Arranged an initial call with the HR, upon a first cancellation. Arranged the first technical one hour video call with one of the Security Engineers from the team.
The interview started without me having any chance to introduce myself, until only the very end - even after my questions to the interviewer.
Tackled all the technical questions and the interviewer seemed very satisfied with them. Except of the typical kind of questions like symmetric/asymmetric cryptography, CSRF etc. there was also a code review challenge. According to their saying, I found the most critical bugs in the code. What I found weird however, was the fact that the interviewer asked me if I wanted to continue to the next question on keep working on that one - like I was the one leading the process.
In brief, all technical questions were tackled. Despite that, and after me having to follow up, they told me that they had decided to move on with another candidate.
Asked for feedback and I received something along those lines: "was interested in more offensive security. Our team won’t have that work.". This is just disappointing from a company of this level. The job advertisement has in its main points the knowledge of tools like Burp and IDA - therefore, even if we assume this is true - because I had not mentioned anything related - the position requires the knowledge of the "offensive security" side. It also just makes no sense, given the fact that I clarified my interest in malware analysis and low-level stuff.
Had also to follow up 3-4 times to receive this piece of art as a response.
At least you could be honest with your reasons and appreciate a bit more the invested time of your candidates in the process. It is quite disappointing to see this kind of response from a company like Spotify. Apparently, it makes me and possibly other candidates consider if we are ever going to apply again there.
Interview questions [1]
Question 1
Symmetric/asymmetric cryptography, CSRF, Code review of an authentication function.