Ahh, so they're not actually looking for seniors then? Sounds like they want people who are "passionate" enough to spend months prepping for an interview so they can milk them dry without the risk of pesky things like "free time" and "family" getting in the way.
Tongue in cheek analysis aside:
- A phone interview to weed out timewasters.
- A RELEVANT technical take-home task that could be done feasibly in a few hours.
- A long, informal, in-person chat to determine "culture fit" and personality.
- Actually checking references.
That's all you need, anything more is just self-importance - or worse - time wasting.
It has the AM/FM trust problem wherein a business will always trust paper contracts and lawyers over Fucking Magic like this.
Edit: Good example, estate transfers and mortgages are a potentially quite good use-case for blockchain. Why is nobody using it? Because it's Fucking Magic.. nobody with a sensible risk profile is going to replace a "contracts and lawyers" process that works well-enough with Fucking Magic.
This is a great start, but maybe they should do something about their use of lignite coal. It kind of defeats the point of an electric vehicle if the power it uses is being produced by burning about the dirtiest fuel out there..
Can't speak to my current employer as it's above my pay-grade to know, but at Job-1 we did the following:
- All "hot" keys were stored in an offline credential manager in specific vaults depending on who needed access to them. Only staff with actual clearance could request temporary access to a vault (fully background checked, 1 year employment, etc).
- Copies of each vaulth and our master CA cert were written to 4 encrypted USB sticks. Two stored on-site in the fire-safe and two off-site at our safety deposit box that only c-level staff could access. (We had the same process with our tokens and master logins for AWS).
- Any work using those keys was on a pair-up basis, so at least two people, one doing the work and the other observing.
- We had a detailed policy around this that covered each step in the process and who needs to approve them; everyone who could feasibly need to access the keys was briefed annually as part of our security awareness training.
We handled a LOT of sensitive financial data, so this was the most appropriate way that we could find that maintained both sensible availability and key control.
So in order to get to the keys you needed:
- Access to the fire safe (Senior Ops, Senior Security and C-Level only).
- The LUKS passphrase for the USB sticks (Senior Security and some C-Level only).
- The passphrase for the specific vault (Senior Security and some C-Level only).
I don't know how the passphrases were managed by our sec team, but I know that the C-Level staff had physical envelopes in their home safes.
I would love to see a version of this for GCP an other cloud platforms (DO, Heroku, especially), would you be open to a collaboration there assuming I can code in your lingua franca?
Tongue in cheek analysis aside:
- A phone interview to weed out timewasters.
- A RELEVANT technical take-home task that could be done feasibly in a few hours.
- A long, informal, in-person chat to determine "culture fit" and personality.
- Actually checking references.
That's all you need, anything more is just self-importance - or worse - time wasting.