Explain risk to people who do not want to hear it.
Threat modeling, incident response, and the art of saying no without becoming the blocker.
Security interviews test whether engineering teams will listen to you.
What Vera actually is
A phone call with someone who is not there. You say the thing out loud, they answer the way a real person would, and you get to do it again — as many times as it takes, with nobody listening.
15 minutes free · no card needed
15 minutes free · no card needed
Not practising doesn’t save you anything.
The ticket, the evening, the weeks of applying — all of it is spent before anyone says a word. The practice is the only cheap part, and the only part that changes how the rest goes.
15 minutes free · no card needed
What she'll actually ask
She asks these the way a real person would, then follows up on whatever you say.
- Walk me through how you would threat model this feature.
- Tell me about a risk you raised that got overruled. What did you do?
- How do you prioritize vulnerabilities when everything is marked critical?
- Describe a security incident you responded to.
- How do you get engineering teams to actually fix things?
More about this one
Security engineering loops test technical depth and something harder: whether you can raise risk without becoming the team everyone routes around. Rounds cover threat modeling, incident response, and behavioral questions about a time you were overruled on a risk decision. Vera runs them by phone, playing an engineering partner who pushes back on your recommendation, so you practice the version of the conversation that actually happens at work.
What she listens for
- threat model
- attack surface
- severity triage
- incident response
- least privilege
- security review
- risk acceptance
- defense in depth
“The 'you got overruled, what did you do' question is the one that decides these interviews and I had never said my answer out loud.”
Related practice
Common questions
Does Vera cover offensive security or CTF-style questions?
It handles the conversational rounds — threat modeling reasoning, incident narration, risk communication. Hands-on exploitation practice needs a lab, not a call.
Is this useful for AppSec versus GRC roles?
Both, with different prompts. GRC loops lean harder on risk communication and stakeholder management, which this format suits well.
Can it play a hostile stakeholder?
Yes, and it is worth asking for. The dismissive engineer is the most realistic practice partner.
What if I am bad at it?
Everyone is, on the first one. That is the entire reason it happens here and not there.
What if I do not know what to say?
She asks the first question and follows up on whatever you answer. You never start from a blank page.
What if it is awkward?
It is, for about twenty seconds. Then it is a conversation, and nobody heard the twenty seconds.
Ready to try it?
Your first 15 minutes are free. No card required.