Phase 12 - Staff-Level Security Practice, Portfolio, VRP, and Interviews
Duration: 4 weeks (Month 24)
Objective: demonstrate technical judgment, organizational influence, client trust, and a
coherent body of evidence for senior security roles.
Deep guides: WARMUP.md defines staff-level output and evidence; HITCHHIKERS-GUIDE.md turns labs into defensible reports, presentations, roadmaps, and interview demonstrations.
Required Theory
- Assessment strategy, architecture review, risk framing, prioritization, roadmap and investment design, control ownership, metrics, exceptions, and governance.
- Consulting skills: discovery, listening, disagreement, decision records, difficult findings, executive presence, multinational/time-zone delivery, and knowledge transfer.
- Mentoring, security champions, reusable paved roads, conference/research writing, and responsible public disclosure.
- Senior interview patterns: coding/review, threat modeling, product design, cloud/platform design, incident leadership, domain depth, executive communication, and behavioral judgment.
Required Build Work and Sources
Create a portfolio index generator or evidence linter that checks every flagship project for scope, threat model, reproducible setup, test evidence, limitations, remediation, and secret scanning. Use Markdown linting, link checking, repository secret scanning, and a small Python/Go script with tests.
Lab 01 - Security Portfolio Evidence Linter supplies that implementation as a tested learner/reference lab, including required evidence sections, secret canaries, and lab-versus-production claim checks.
Runnable lab portfolio
The labs test public-artifact hygiene, finding defensibility, severity/remediation quality, and staff-level prioritization across risk reduction, breadth, dependency leverage, effort, and adoption.
Review the target company's public security architecture, engineering blog, incident reports, VRP/safe-harbor policy, product documentation, regulatory context, and role description. Use only public information and distinguish direct evidence from inference. Revisit the primary sources from the chosen specialization rather than cramming interview summaries.
Four-Week Final Sprint
| Week | Work | Deliverable |
|---|---|---|
| 1 | full review of Aegis Transit Cloud | scope, architecture, threat model, findings, retest plan |
| 2 | influence and roadmap | engineer workshop, executive briefing, 12-month security roadmap |
| 3 | research and portfolio | flagship curation, blog post, conference proposal, VRP readiness review |
| 4 | interview loops and onboarding | seven domain mocks, STAR bank, role matrix, 30/60/90-day plan |
Final Capstone - Staff Security Review
Act as security lead for a fictional launch combining:
- multi-tenant cloud/Kubernetes platform;
- Android field application with offline storage and native parser;
- sandboxed customer job execution;
- OT telemetry gateway;
- LLM operations assistant with tools.
Deliver:
- engagement charter and stakeholder map;
- architecture, data flows, assets, trust boundaries, and top abuse cases;
- prioritized findings with engineering fixes, detections, owners, sequencing, and residual risk;
- two deep technical reviews and one incident scenario;
- 30-minute engineering remediation workshop;
- 10-minute executive briefing with three investment options;
- 12-month roadmap and success metrics;
- final portfolio index, resume bullets, and 30/60/90-day joining plan.
VRP Readiness Gate
Before any real program:
- completed Phase 00 and Phase 08;
- can parse scope and safe-harbor language conservatively;
- uses dedicated accounts, synthetic data, rate/cost limits, and encrypted notes;
- stops at minimum proof and can write a maintainer-ready report;
- has a plan for accidental data, service instability, duplicate findings, and disclosure;
- accepts that no finding is better than unsafe testing.
Interview Circuit
Run each as a timed session with written feedback:
- Android: component, Binder, WebView, storage, native crash.
- Cloud/Kubernetes: tenant isolation, IAM, supply chain, detection, recovery.
- Application security: authz, design review, SDLC adoption.
- Incident response: first hour, evidence, containment, executive cadence.
- Systems/isolation: malicious workload runner and shared-kernel risk.
- AI security: indirect injection and tool authorization.
- Threat modeling: cross-domain architecture in 45 minutes.
Use ../interview-prep/README.md for the full question bank.
Core final questions:
- Which three security risks would you address first in the capstone, and why?
- What control would you decline to build, and what would you do instead?
- Describe a containment decision that protects evidence but risks availability.
- How would you measure whether your security roadmap changed engineering outcomes?
- Explain one technical risk to a developer, a customer executive, and an auditor.
Portfolio Quality Gate
Choose 6-8 flagship artifacts. Each must run or render cleanly, state authorization, contain a threat model, include tests/evidence, show remediation, disclose limitations, and have a concise demo. Remove weak, duplicate, unsafe, unverifiable, or secret-bearing work.
Communication Evaluation
- Developer report: exact component, reproduction, root cause, code/config fix, regression test.
- Incident update: known, unknown, risk, actions, blockers, next update.
- Executive memo: exposure, business consequence, options, recommendation, investment, owner.
- Customer presentation: assumptions, shared responsibility, milestones, evidence, open decisions.
Measures
- Final review scores at least 28/32 on the master rubric.
- Mock interview average reaches 3/4 with no domain below 2.
- All resume metrics trace to an artifact or recorded exercise.
- The roadmap contains owners, dependencies, cost ranges, adoption strategy, and leading/lagging measures.
- Eight STAR stories survive follow-up questions and include mistakes or tradeoffs, not hero tales.
Common Mistakes
- Presenting breadth with no defensible depth.
- Turning every risk into a critical finding.
- Recommending tools without operating models or owners.
- Giving executives implementation detail without a decision.
- Claiming production experience from a lab instead of describing it accurately.
- Publishing volume instead of curating signal.
Stretch Goals
Submit an authorized upstream security improvement, deliver a local meetup talk, mentor another learner through one phase, produce a bilingual technical/executive glossary for a target region, or arrange an independent review panel for the final capstone.