Round and Around We Go: Interviews, What Do You Know?

Erin Barry

BSidesSF 2025 — Here Be Dragons · Day 2 · Main

Overview

Erin Barry, VP of Security Talent at Code Red Partners, brought a year's worth of real hiring data from 30 security engineering and leadership placements to debunk myths and lay out hard truths about the security job market. The average time-to-hire is 48 days — nearly seven weeks — the process is widely acknowledged as broken, and the most common rejection reasons have nothing to do with technical skill. Her talk is part data briefing, part field manual for candidates navigating an increasingly competitive and opaque hiring landscape. ---

Watch on YouTube

Visual summary for Round and Around We Go: Interviews, What Do You Know? by Erin Barry
Visual summary for Round and Around We Go: Interviews, What Do You Know? by Erin Barry

Key moments

  1. 2:53 Interview process anatomy: four sequential stages each a potential rejection gate
  2. 4:01 Technical interview identified as where most candidates fail the process
  3. 5:17 Alarming trend: security engineer roles now demanding medium LeetCode proficiency
  4. 5:26 Unicorn problem: companies demand software engineer + security engineer + leader hybrid
  5. 11:23 Brutal stat: average 48 days (7 weeks) from first call to signed offer letter
  6. 11:53 Fastest hire: 9-day process yielded $235K base salary, disproving speed-salary correlation
  7. 12:24 Cautionary case: 138-day interview process — candidate left within six months
  8. 13:07 Market data: average base salary $261K for pre-IPO SF security engineering hires

Round and Around We Go: Interviews, What Do You Know?

Speaker: Erin Barry

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: https://www.youtube.com/watch?v=1AOVKe-jJ00

Reading time: ~7 minutes

TL;DR

Erin Barry, VP of Security Talent at Code Red Partners, brought a year's worth of real hiring data from 30 security engineering and leadership placements to debunk myths and lay out hard truths about the security job market. The average time-to-hire is 48 days — nearly seven weeks — the process is widely acknowledged as broken, and the most common rejection reasons have nothing to do with technical skill. Her talk is part data briefing, part field manual for candidates navigating an increasingly competitive and opaque hiring landscape.

Introduction

The security industry talks constantly about the talent shortage, but rarely examines what the hiring process itself looks like from the inside. How long does it actually take? What do candidates get paid? What kills an otherwise strong application? At BSidesSF 2025, Erin Barry — VP of Security Talent at Code Red Partners, a recruiting firm specializing in permanent, direct-hire security engineering and leadership placements at pre-IPO and public tech companies — brought receipts.

Barry's dataset covers 30 security engineering and security leadership hires made between March 2024 and March 2025, all in the United States, placed through her team at companies ranging from Series A startups to one public company. The sectors skew toward AI, crypto, fintech, and SaaS — the companies driving most security hiring activity in San Francisco right now. The result is a rare ground-level view of what candidates and hiring managers are actually experiencing, rather than what either side would like to believe.

The Four-Stage Gauntlet (and Why Every Stage Matters)

▶ Watch: Types of Interviews (02:00)

Barry mapped the typical security hiring process into four stages, and immediately flagged the most common misunderstanding: these are not equally weighted checkpoints.

Stage 1: The introduction call. This can involve a corporate recruiter, an HR generalist, or the hiring manager. The stated goal is a loose fit assessment — excitement level, career direction, surface-level alignment. Candidates routinely dismiss this as a formality. They shouldn't. "People will get declined all the time for a corporate recruiter call," Barry noted. If a recruiter hasn't provided prep documents before this call, that's a signal about the company — and candidates should ask for them.

Stage 2: The technical interview. This is where most candidates wash out. Depending on the role, it may be a live coding session on CoderPad using LeetCode or HackerRank, or a take-home assessment that can consume a week or two of evenings. Barry flagged a troubling trend: security engineering roles increasingly require passing medium-difficulty LeetCode problems. "That's a software engineer. I don't think that's a security engineer." Candidates should ask explicitly what format the technical interview takes before showing up.

Stage 3: The on-site interview. What sounds like one interview is typically three to four sequential conversations compressed into a single day or half-day: technical assessment, role fit, cultural fit, and opportunity to evaluate the team. Barry's advice: treat this as a mutual audition. "People want to hear your excitement questions." This is the most realistic setting in which candidates can assess whether they actually want to work there.

Stage 4: The executive sign-off. A final conversation — with a founder, a member of the C-suite, or the CISO — whose explicit purpose is the final hiring decision. If you've cleared the on-site, this is a closing step, not a new evaluation. But it still requires showing up prepared.

The sequence is unforgiving: failing the technical interview means you never reach the on-site. Failing the intro call means you never reach the technical interview. Barry's instruction: "Treat each step with equal importance."

The Numbers: Time-to-Hire and Base Salaries

▶ Watch: Year in Numbers — Time to Hire (10:30)

Barry asked the audience to guess the average time from first recruiter contact to signed offer letter before revealing her data. Guesses ranged from five days to three months. The actual average: 48 calendar days, or roughly 34 working days — approximately seven weeks.

The range is wide. The shortest time-to-hire in the dataset was 9 days, and it produced a $235,000 base salary — disproving Barry's initial hypothesis that faster processes correlate with lower offers. The longest was 138 days, stretching through the winter holidays. That candidate left within six months. "Is anyone shocked? I'm not," Barry said. Processes that drag past 12 weeks are a red flag on both sides.

▶ Watch: Base Salary Breakdown (15:45)

On compensation: the average base salary across 30 hires was $261,000, with most packages supplemented by equity, stock options, cryptocurrency tokens, or other components. The floor was approximately $150,000, clustered among candidates in lower cost-of-living locations outside major tech hubs. The ceiling — an individual contributor based in San Francisco — significantly exceeded the average, in a process that took 44 days.

Geographic compensation compression is real and consistent. Companies routinely apply geo-tagging: candidates outside major tech markets receive lower offers regardless of skill level. The 150k-floor cohort in Barry's data skewed toward non-tech-hub locations.

Barry's structural observation: "The best way to get a bump in your base salary is to find a new job." The data bore this out — nearly all significant compensation increases in the dataset came through job changes, not internal promotions.

Rejection Trends: Why Good Candidates Fail

▶ Watch: Why Candidates Get Rejected (21:00)

Barry described the rejection trends section as the most important part of the talk, and the data surprised even her. The most common rejection reasons were not technical skill gaps. They were behavioral.

Not researching the company. Candidates who joined hiring manager calls without basic knowledge of the company were rejected immediately. "What do you know about the company? Nothing. Guess what? You're rejected." Barry's minimum bar: 15 minutes of research, including recent news. This applies equally to recruiter calls — the "I just Googled the company" response is specifically noted as something hiring managers dislike.

Using AI during live interviews. Candidates were caught using AI assistance in live technical interviews across the past year, including candidates with top-tier CS degrees. "You will probably get caught," Barry warned. "Security is very small. People talk. Just don't do it." She argued it is better to fail honestly than to cheat — being caught follows a candidate's reputation in a way a bad technical interview score does not.

Being difficult to work with. Barry reported seeing multiple candidates rejected by corporate recruiters or scheduling coordinators before ever reaching the hiring manager — purely on the basis of being argumentative or dismissive toward administrative staff. "Recruiters remember you. I remember people that were mean to me years ago." In a small industry, this has career-long consequences.

Failing to demonstrate curiosity. Hiring managers consistently penalize candidates who project a know-it-all posture. "Nobody likes to know it all." The preferred signal: asking questions, expressing interest in the company's specific security problems, and being willing to say "I'm not sure" rather than guessing. Barry's note to candidates who aren't naturally curious: "If you need a job, get curious."

Inability to explain their own resume. If a candidate cannot articulate the project, tool, or achievement listed on their resume — including the business impact — they should remove it. "If you can't explain it, do not put it on your resume." Hiring managers want to hear how a candidate made the organization better: cost savings, risk reduction, process improvement. Side projects and personal labs count and should be listed.

Practical Advice for the Current Market

▶ Watch: Tips and Resources (29:15)

Barry closed with tactical guidance she's observed driving actual outcomes.

Build something findable. Two candidates in the dataset had their processes significantly accelerated after submitting vulnerabilities to the companies they were applying to. "That's amazing," Barry said. One was fast-tracked through the entire process. Bug bounty programs exist partly for this reason. Candidates willing to go beyond the application and demonstrate real work get noticed.

Use existing templates. The University of Michigan's publicly available résumé resource library — freely accessible without attending Michigan — was Barry's top recommendation for résumé formatting. Simplicity, impact statements, quantified achievements, and demonstrated scope are the elements that convert. "We're not reinventing the wheel."

Study careers you want. Barry cited LinkedIn career research as a legitimate preparatory tool: find someone in the role you want, examine their career path, and reverse-engineer the steps. "You don't need to reinvent the wheel. Copy people. If someone has the career you want, take a look at it."

Work to your medium. Not every candidate needs a LinkedIn presence or a public speaking record. "If you're the best damn coder on the East Coast, show that GitHub." Match your visibility strategy to your actual strengths rather than imitating the generic advice to do everything.

Her closing citation was "Wilson's Law" — her framing of the principle that prioritizing knowledge and intelligence generates sustained earning power. In a competitive market, consistent learning compounds over time in ways that short-term credential chasing does not.

Notable Quotes

"If your recruiter or HR person doesn't give you prep information prior to your interview, they are not a good recruiter. They are setting you up to fail. It is their job to hire — you failing a technical interview makes them look bad."

— Erin Barry, ▶ 05:20

"Security is very small. People talk. If you are hard to work with or argumentative, you will be rejected before you even meet a hiring manager, no matter your background."

— Erin Barry, ▶ 22:40

"The average is literally seven weeks to get an offer. You are not alone. Some of the most talented engineers will still be put through the most strenuous processes. I don't love it. I think it's a really broken process — that's kind of why I wanted to present today about it."

— Erin Barry, ▶ 31:00

Key Takeaways

  • Seven weeks is normal. The average time-to-hire in this dataset was 48 days. Processes running longer than 12 weeks are a two-way red flag — about the company's decisiveness and the candidate's likely retention.
  • Average base salary for security engineering and leadership roles in this dataset was $261,000, with significant geographic compression pulling down offers for candidates outside major tech markets. Equity and token packages often supplement these figures substantially.
  • The most common rejection reasons are behavioral, not technical: failing to research the company, using AI assistance during live interviews, being difficult with recruiters or coordinators, projecting a know-it-all posture, and being unable to explain resume entries.
  • Every stage deserves full preparation. The intro call with a corporate recruiter is not a rubber stamp — candidates are routinely eliminated at this stage. Asking recruiters for prep materials is appropriate and expected.
  • Side projects, home labs, and vulnerability disclosures are legitimate differentiators. Companies weight demonstrated initiative heavily, particularly for candidates whose day-job experience is less compelling. Bug bounty submissions to target companies have directly accelerated hiring processes.
  • Résumé and LinkedIn optimization doesn't require originality. Studying the career paths of people in target roles and borrowing their vocabulary and structure is a legitimate and effective strategy. The University of Michigan's free résumé templates are a recommended starting resource.

Reviews

Dr. Zero (Offensive Security Researcher) — PASS

A recruiting professional's year-in-data talk about security hiring timelines and rejection patterns. Average time-to-hire is 48 days, average base is $261K, most rejections are behavioral not technical. Useful career advice for junior practitioners, wrong venue for this audience.

Heather Calloway (CISO) — SOLID

Barry brought a year of real hiring data — 30 placements, 48-day average time-to-hire, $261,000 average base — and the most common rejection reasons are behavioral, not technical. For security practitioners actively navigating a job search, this is a practical briefing. For hiring organizations, it's a diagnostic.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons