Here is a sample response you can use and customize for a job interview, especially for a Senior IT
Infrastructure Security Officer or similar position in a bank or IT security department.
---
1. Introduce Yourself
"My name is Guesh Gebreher, and I graduated in Electrical and Computer Engineering from Mekelle
University in July 2016. I have over 8 years of professional experience working at the Information
Network Security Administration (INSA) as a Network and System Security Auditor and Digital Forensics
Investigator. Throughout my career, I’ve been involved in securing IT infrastructures, conducting
technical audits, responding to security incidents, and ensuring compliance with cybersecurity
frameworks. I’m passionate about strengthening organizational resilience against cyber threats and
contributing to a culture of continuous security improvement."
---
2. Why Do You Want to Work Here?
"I’m interested in working here because your institution is known for its strong commitment to
cybersecurity and innovation in the financial sector. I admire your mission and the strategic direction
you’re taking to enhance customer trust through secure digital services. With my background in security
auditing, incident response, and infrastructure protection, I believe I can bring immediate value and
grow professionally within your environment."
---
3. What Experience Do You Have?
"I have deep experience in IT security auditing, vulnerability assessment, firewall and network
configuration reviews, and implementation of compliance controls such as ISO 27001 and NIST. I’ve
conducted penetration tests, created information security policies, and led awareness training
programs. Additionally, I’ve been responsible for managing SIEM alerts, analyzing logs, and
recommending improvements for endpoint and perimeter defenses."
---
4. What Are Your Salary Expectations?
"I'm open to discussing a salary that reflects the responsibilities of the role and my experience. Based on
my background and the market rate for similar positions, I’m confident we can agree on a fair and
competitive package."
---
5. What Are Your Long-Term Career Goals?
"My long-term goal is to become a Chief Information Security Officer (CISO) or IT Security Consultant,
where I can lead enterprise-wide security strategies and influence high-level decisions to protect critical
infrastructure and data. I also plan to continue developing my skills through certifications like CISSP or
CISM."
---
6. Why Did You Leave Your Last Job (or Want to Leave)?
"I’m looking for a new challenge and an opportunity to grow further in the cybersecurity field. While I’ve
learned a great deal at my current position, I’m now seeking an environment where I can apply my skills
more strategically, contribute to a larger mission, and have room for professional development."
---
7. What Are Your Strengths?
Strong analytical and problem-solving skills
Deep understanding of network security and threat landscapes
Ability to lead and conduct comprehensive audits and risk assessments
Excellent communication and report-writing skills
A calm and focused mindset during incidents or high-pressure tasks
---
8. What Are Your Weaknesses?
"I used to be too detail-oriented, which sometimes slowed down my work. However, I’ve learned to
balance thoroughness with efficiency by prioritizing high-risk items and managing my time better."
---
9. How Do You Handle Conflict?
"I believe in addressing conflicts respectfully and professionally. I listen carefully to understand the other
person’s point of view, clarify misunderstandings, and aim for a solution that aligns with the team’s and
organization’s goals. I avoid personalizing issues and focus on facts and outcomes."
---
10. Describe a Challenge You Faced at Work
"Once during a security audit, I discovered serious misconfigurations in a bank’s firewall that could have
exposed customer data. I had to immediately notify stakeholders and work with the network team
under pressure to reconfigure the rules, without disrupting operations. It taught me the importance of
collaboration and clear communication during high-risk situations."
---
11. Other Common Questions You May Face
Question Short Sample Answer
How do you stay updated with cybersecurity trends? I follow threat intelligence feeds, attend
webinars, and study NIST, ISO updates, and CVE databases regularly.
What tools have you used? Wireshark, Nessus, Nmap, Metasploit, Splunk, Cisco ASDM, and ELK
Stack.
How do you respond to a security incident? Follow incident response phases: preparation,
detection, containment, eradication, recovery, and post-incident review.
---
Would you like a PDF version of this full interview preparation document or want me to tailor it for a
specific bank or company?
Here’s a customized full job interview preparation guide tailored specifically for the role of Senior IT
Infrastructure Security Officer at Buna Bank.
---
✅ Job Interview Preparation for Buna Bank
Position: Senior IT Infrastructure Security Officer
Organization: Buna Bank S.C.
---
1. Introduce Yourself
"My name is Guesh Gebreher. I hold a degree in Electrical and Computer Engineering from Mekelle
University, completed in July 2016. I have over 8 years of hands-on experience in IT security, working
primarily at the Information Network Security Administration (INSA) as a Network and System Security
Auditor and Digital Forensic Investigator. My background includes securing enterprise IT infrastructure,
performing vulnerability assessments, hardening systems, conducting audits aligned with NIST and ISO
standards, and responding to security incidents. I’m passionate about banking cybersecurity, and I
believe my experience makes me well-suited for this senior role at Buna Bank."
---
2. Why Do You Want to Work at Buna Bank?
"I want to work at Buna Bank because it’s one of Ethiopia’s rapidly growing financial institutions, and I
admire its focus on innovation and digital transformation. I’m excited about the opportunity to
contribute to a secure banking environment that protects customer trust and supports growth. Buna
Bank's vision aligns well with my career goals, and I’m eager to apply my security expertise to strengthen
your infrastructure."
---
3. What Experience Do You Have?
8+ years in infrastructure security, auditing, and incident response
Extensive experience with network devices (firewalls, routers, switches), server hardening, VPNs,
endpoint protection, and access control
Led audits on Cisco, Fortinet, Mikrotik, and Check Point infrastructures
Familiar with SIEM tools, log analysis, and threat intelligence
Created IT security policies, SOPs, DRP/BCP plans, and conducted security awareness training
Experience in compliance with ISO 27001, NIST 800-53, and banking regulations (e.g., NBE directives)
---
4. What Are Your Salary Expectations?
"I understand Buna Bank follows a structured salary scale, and I’m confident you’ll offer a competitive
package based on my experience and qualifications. I’m open to discussion but ideally expecting a
compensation aligned with a senior-level cybersecurity professional."
---
5. What Are Your Long-Term Career Goals?
"My long-term goal is to take on a leadership role in IT security—ideally as a CISO or IT Security Program
Manager—where I can shape policies, manage risk at the strategic level, and guide security teams. I also
aim to continue learning through certifications like CISSP and cloud security (e.g., AWS or Azure)."
---
6. Why Are You Leaving Your Current Job?
"I’m seeking new challenges and opportunities to grow in the financial sector. While I’m grateful for the
experience gained at INSA, I want to bring my skills into a banking environment where I can make a
tangible impact on financial systems' security."
---
7. What Are Your Strengths?
Strong technical knowledge of IT infrastructure security
Detail-oriented in audits and documentation
Proactive in identifying and mitigating risks
Calm under pressure, especially during incidents
Excellent teamwork and communication skills with IT and business teams
---
8. What Are Your Weaknesses?
"I used to take on too many responsibilities without delegating, which sometimes affected my workload.
Over time, I’ve learned to trust team collaboration and focus on prioritizing tasks effectively."
---
9. How Do You Handle Conflict?
"I approach conflict professionally and respectfully. I listen actively, avoid making assumptions, and
focus on facts. I always aim to find common ground and align with organizational goals. Security requires
collaboration, so I promote open communication."
---
10. Tell Us About a Challenge You Faced
"During a network audit at a government institution, I identified several critical firewall
misconfigurations that exposed sensitive systems. I had to immediately escalate and work overnight
with the network team to reconfigure the firewall without interrupting service. It taught me the
importance of fast, coordinated response and calm leadership during high-stakes situations."
---
11. Scenario-Based Question
Q: You receive a SIEM alert about suspicious login attempts on the core banking server. What is your
next step?
A:
Immediately review the alert details
Correlate with logs from firewall, server, and authentication systems
Identify the source IP, account used, and geolocation
Check if login attempts were successful
If suspicious, contain the threat (e.g., block IP, disable account)
Notify incident response team and document findings
Begin incident response procedure
---
12. Tools and Technologies You Know
Firewalls: Cisco ASA, FortiGate, Mikrotik
Security Tools: Nessus, Nmap, Wireshark, Metasploit
SIEM: Splunk, ELK, or similar
OS: Windows Server, Linux (Ubuntu/CentOS)
Protocols: SSH, HTTPS, IPsec, VLANs, ACLs
Backup & DR: Veeam, Acronis, Windows Backup, DR drills
Compliance: ISO 27001, NIST 800-53, NBE directives
---
13. How Do You Stay Updated in Cybersecurity?
"I read daily threat feeds like ThreatPost, use CVE and NIST databases, and follow experts on LinkedIn
and YouTube. I also attend webinars and am preparing for advanced certifications to keep my skills
sharp."
---
✅ Bonus Questions to Prepare
Question Tip to Answer
What is Zero Trust? "A security model that assumes breach and verifies every user/device trying to
access resources, regardless of location."
How do you secure a bank’s core infrastructure? "By segmenting networks, applying strict
firewall rules, hardening servers, enabling logging and SIEM monitoring, and performing regular audits."
What would you do during a ransomware attack? "Isolate affected systems, alert management,
preserve evidence, analyze scope, begin recovery using clean backups."
---
📄 Need This in PDF?
Would you like me to generate this full interview guide for Buna Bank as a downloadable PDF?
Or would you like me to add Amharic translations or prepare a PowerPoint version for self-
presentation?
Let me know!
What avout technical questions as it have job description ,Buna Bank
Job Position:
Senior IT Infrastructure Security Officer
Duties:
Implementing secure networks and understanding how components, such as antivirus software and
endpoint security solutions, work together to create a secure network.
Monitoring networks for security breaches and investigate violations when they occurs.
Protecting servers, computers, networks and data against threats, such as security breaches, computer
viruses or attacks by cyber-criminals.
Being proactive in ensuring the IT Infrastructure is secure, protected and up to date in the face of known
and emerging cyber threats 3.5 Quickly remediate the security incidents and communicate with the top
management to prepare for any business repercussions.
Making proactive and preventative housekeeping of the IT Infrastructureincluding VPN and WAN/LAN
connectivity.
Analyzing and troubleshooting the network logs and tracking the nature and resolution of problems.
Ensuring that the IT Infrastructure, its data, files and applications are protected against known threats
and attacks and reacting to emerging threats to minimize any risk of comprise to the IT Infrastructure
Maintaining Firewalls, Security Information Event Management and other security tools for security
threat management, and fosters security best practices within all areas of direct responsibility.
Ensuring that IT security audits are conducted periodically or as needed.
Preparing periodic activity and progress reports.
Exploring the latest information technology security trends.
Reviewing and making recommendations to provide adequate levels of IT security in line with best
industry practice and/or in response to new cyber threats.
Building a culture of pro-activity, business cooperation, continuous improvement, effective professional
relationships and exceptional service delivery.
Performing related duties as required and assigned by supervisor.
Thanks, Guesh! Based on the job description for the Senior IT Infrastructure Security Officer position at
Buna Bank, here are technical interview questions you’re likely to be asked — along with sample
answers, categorized by topic to match the duties listed.
---
✅ 🔐 Infrastructure Security – Core Questions
1. How would you design a secure network infrastructure for a bank?
Sample Answer:
I would use defense-in-depth principles. This includes network segmentation with VLANs, hardened
firewalls at the perimeter, internal firewalls between segments (e.g., separating user LAN from server
LAN), intrusion detection/prevention systems (IDS/IPS), VPNs for secure remote access, endpoint
protection, and centralized log management via SIEM. Access would be role-based and governed by the
principle of least privilege.
---
2. What are the critical components of endpoint security in a banking environment?
Answer:
Antivirus/Antimalware
Host-based firewalls
Patch management
Device encryption (e.g., BitLocker)
EDR (Endpoint Detection and Response) tools
DLP (Data Loss Prevention) policies
Application control (e.g., blocking unauthorized software)
---
✅ Monitoring, Detection, and Incident Response
3. How do you monitor a network for security breaches?
Answer:
By configuring a SIEM (e.g., Splunk or Elastic Stack) to collect and correlate logs from firewalls, servers,
endpoints, VPN, and authentication systems. I would also use IDS/IPS systems, analyze anomaly reports,
and review login attempts, traffic patterns, and system behaviors regularly.
---
4. How do you respond to a detected security incident?
Sample Steps:
1. Identify and verify the incident from logs or alerts
2. Contain the affected system or network
3. Notify relevant teams and management
4. Investigate the root cause using logs, forensics, and indicators of compromise
5. Eradicate the threat and apply patches or fixes
6. Recover by restoring from clean backups
7. Document and report findings, and update response plans
---
✅ 🌐 VPN, WAN/LAN Connectivity & Troubleshooting
5. How would you secure VPN access for remote banking staff?
Answer:
Use IPsec or SSL VPN with strong encryption
Enforce multi-factor authentication (MFA)
Restrict access based on roles
Monitor login activities and time-of-day restrictions
Ensure VPN client updates and endpoint compliance (e.g., AV installed)
---
6. How do you troubleshoot network connectivity and log issues?
Sample Approach:
Use ping, tracert, nslookup, netstat for diagnostics
Analyze firewall logs, DHCP leases, and router configs
Review SIEM or syslog entries for errors or dropped packets
Check for misconfigured IP addresses, subnet masks, or ACLs
Use tools like Wireshark to inspect traffic
---
✅ 🧱 Firewalls, SIEM, and Logging
7. What’s your experience with firewall configuration?
Answer:
I’ve configured and audited Cisco ASA, Fortinet, and Mikrotik firewalls. I set up NAT rules, ACLs, VPN
tunnels, and logging. I follow a “deny all by default” rule and only allow required ports, services, and IPs.
I also use zone-based policies and apply threat prevention features like DoS/DDoS protection.
---
8. How does a SIEM help in security management?
Answer:
A SIEM collects logs from various sources (firewalls, servers, endpoints), normalizes the data, and
performs correlation to detect suspicious behavior (e.g., brute-force attacks, failed logins, privilege
escalations). It’s essential for real-time alerting, forensic investigations, and regulatory compliance.
---
✅ 🧾 Policy, Audit, and Best Practices
9. What key areas do you check during an IT infrastructure security audit?
Sample Areas:
Patch levels of OS and applications
Firewall configurations and rule reviews
User access control and privileged accounts
Endpoint protection (AV, EDR, encryption)
Backup systems and test results
Logging, SIEM correlation, and incident response plans
Compliance with NBE, ISO 27001, and data classification
---
10. How do you stay updated on new cyber threats?
Answer:
I subscribe to threat intelligence feeds (e.g., US-CERT, SANS, CVE database), join cybersecurity forums,
follow vendors’ security bulletins, and attend virtual trainings/webinars. I also track the latest attack
trends like phishing, ransomware, and zero-day exploits.
---
✅ 🌍 Culture, Communication & Teamwork
11. How do you promote a culture of cybersecurity in your organization?
Answer:
By conducting awareness trainings, simulating phishing attacks, sharing threat reports with IT staff, and
integrating security into IT operations (DevSecOps). I encourage reporting of suspicious activities and
reward secure behavior.
---
12. How do you prepare security progress reports for top management?
Answer:
I prepare executive summaries with:
Current risk posture
Number of incidents, types, and resolutions
Audit findings and status of remediation
Ongoing projects (e.g., firewall upgrade, endpoint deployment)
Recommendations for investment or policy changes
---
🧪 Bonus: Scenario Question
Q: You receive multiple failed login attempts on the core banking server after-hours. What would you
do?
Answer:
Correlate the failed attempts in the SIEM
Identify source IP, username, geolocation
Check for successful login attempts from same IP
Block the IP at the firewall if it’s an external brute force
Disable the targeted user account temporarily
Investigate lateral movement or access to sensitive data
Document incident and inform management
---
Would you like a PDF version of these technical questions and answers, or a hands-on lab demo script
for Buna Bank (e.g., firewall audit, VPN test, SIEM setup)?
Great! Below is a hands-on lab demo script specifically designed for a Senior IT Infrastructure Security
Officer candidate preparing for Buna Bank — or similar financial institutions — to demonstrate expertise
in:
1. Firewall Security Audit
2. VPN Configuration & Testing
3. SIEM Setup & Log Monitoring
---
🧪 Hands-on Lab Demo Script for Buna Bank
---
✅ Lab 1: Firewall Audit (e.g., Cisco ASA, FortiGate, or Mikrotik)
Objective:
Verify secure configuration, access rules, logging, and threat protection.
Tools Needed:
Access to firewall GUI/CLI (Cisco ASDM, FortiManager, or Mikrotik Winbox/SSH)
Nmap on auditor’s laptop
Baseline firewall policy (provided by bank or sample template)
Steps:
1. Log into the firewall
ssh admin@<firewall-ip> # For CLI access
2. Check software version & firmware
show version # Cisco ASA
/system resource print # Mikrotik
3. Review security zones & interfaces
Ensure proper segmentation: Internal, DMZ, External
Check interface IPs and security levels
4. List all active firewall rules
show access-list # Cisco ASA
/ip firewall filter print # Mikrotik
5. Identify misconfigured rules
Look for:
any to any rules
Unrestricted admin ports (e.g., open SSH to world)
Lack of logging on deny rules
6. Perform Nmap scan from external test machine
nmap -Pn -sS <Public IP> # Verify exposed ports
7. Check logging configuration
show logging # ASA
/system logging print # Mikrotik
8. Check for default credentials or unused services
/user print # Review user accounts
9. Export report and findings
---
✅ Lab 2: VPN Configuration & Testing
Objective:
Configure and test secure remote access using IPsec or SSL VPN.
Tools Needed:
FortiGate/Cisco/Mikrotik VPN Server
VPN client (e.g., Cisco AnyConnect, OpenVPN)
Wireshark for packet capture
Steps:
1. Create a VPN user account
/user add name=vpnuser password=Strong@123 group=remote
2. Configure IPsec VPN (Example: Mikrotik)
/interface ipsec peer add address=[Link]/0 secret=YourSecret
/ip pool add name=vpn-pool ranges=[Link]-[Link]
/ppp profile add name=vpn-profile local-address=[Link] remote-address=vpn-pool
3. Enable encryption algorithms & set policies
AES-256
SHA-256
PFS group 14 or higher
4. Connect from remote client
Use OpenVPN or AnyConnect
Authenticate and test access to internal services
5. Capture traffic using Wireshark
wireshark & # Observe handshake and encrypted tunnel
6. Check logs for successful connection
/log print where message~"vpnuser"
7. Attempt brute-force from test machine (simulate threat)
hydra -l vpnuser -P [Link] <vpn-ip> ssh
8. Confirm account lockout or rate-limiting is enforced
---
✅ Lab 3: SIEM Setup & Log Correlation (Open Source ELK or Wazuh)
Objective:
Monitor logs, detect suspicious activities, generate alerts.
Tools Needed:
Wazuh SIEM or ELK Stack
Windows/Linux endpoint
Filebeat/Winlogbeat for log shipping
Suricata (optional for NIDS)
Steps:
1. Install Wazuh manager (Ubuntu Server)
curl -sO [Link]
sudo bash [Link] -a
2. Install agent on endpoint
./[Link] --server-ip <SIEM-IP>
3. Simulate failed login attempts (brute-force)
for i in {1..10}; do ssh invalid@server; done
4. Log shipping and alert generation
Logs are collected by the Wazuh agent
Events are parsed and shown in Kibana dashboard
5. Create alert rule for login failures
"rule": {
"level": 10,
"description": "Excessive login failures",
"id": 18107
6. Check alerts dashboard
Navigate to Security Events → Authentication Events
7. Generate a custom report
Export findings as PDF or CSV
---
🧾 Sample Output/Deliverables
Task Evidence
Firewall config audit Screenshot of ACLs, Nmap scan result
VPN setup Screenshot of successful login, VPN logs
SIEM detection Screenshot of alert dashboard, agent log
Report Written findings with severity, remediation, and screenshots
---
📎 Optional Add-ons:
Add Ransomware Simulation (e.g., EICAR test file)
**Backup & Restore Test using Veeam or rsync