I have gone through 2 rounds,
Round 1 - with Developer who want to understand my overall knowledge on AppSec with respect to SAST, DAST, IaC, Containers, etc. I was shortlisted
Round 2 - Interviewed by a Security Guy, a lot of confusion with respect to expectations and job title.
1. Questions were focused on Pentesting
2. Question on Secrets Manager
3. Web app pentest questions asked
4. which vulnerability can be found in Pentesting but not in SAST, I told DOS, but I am sure interviewer was expecting me say SSRF (but SSRF can be found through SAST as well)
5. He was on to containers / IaC, I told him I worked on that but not in deep, (Not sure if this is their rejection criteria)
6. Later he talked about some OS based pentesting questions (I thought this job description was about AppSec, most questions are relevant with job requirement in their Linkedin)
7. Job requirement mentioned that required skills in atleast ONE of the below areas - SAST, DAST, IAC, Secrets Management, etc. I have experience more than a few, not sure why I was rejected