interview prep

Obsidian Security Interview Guide for Engineers

Obsidian started in 2017 as a SaaS security posture company, built by a team that had already done hard security exits: co-founders Glenn Chisholm (from Cylance, sold to BlackBerry) and Ben Johnson (who co-founded Carbon Black, acquired by VMware), while CEO Hasan Imam ran revenue at Shape Security (F5) before taking over. That pedigree matters for the interview because it sets the bar for who they hire. These are people who have seen what a real detection product costs to build, and the loop reflects it.

The company’s current story is AI agents. In August 2026 Obsidian raised an $85 million Series D at a $1.1 billion valuation (The Next Web), a round the company says was led by Crescent Cove Advisors, with existing investors participating (Pulse 2.0, which names Greylock and Menlo; The Next Web lists Wing, GV, and Norwest among prior backers). That put it in unicorn territory on the back of the “securing AI agents” wave. The product has moved from scoring SaaS configurations to enforcing runtime controls over what AI agents are allowed to do: Obsidian has extended native governance to Anthropic’s Claude Code and Cowork, letting security teams restrict agent access to production data and sensitive files and block unsanctioned MCP or tool usage at execution time (company blog). They report 60 of the Fortune 500 as customers. For competitive context, Obsidian sits in the SaaS-security-posture and non-human-identity space alongside AppOmni, Valence, and Reco, adjacent to the compliance-automation world you’d see at a company like Vanta.

What the interview actually looks like

Public data on Obsidian’s loop is thin, and most of what exists is secondhand aggregator content, so treat specifics as directional. From the Glassdoor reviews that do exist plus the shape of the job postings, a backend or security engineer should plan for something like this: a 30-minute recruiter screen, an online coding assessment that candidates describe as tricky (examples written to trip you up on edge cases rather than only the happy path), then a set of technical and behavioral Zoom rounds. More than one candidate has described five conversations, one of them with the CEO, where the discussion is mostly about background, judgment, and whether you actually understand the problem space rather than another algorithm grind.

That ratio is the thing to internalize. A Series D security-infrastructure company is not optimizing its loop to find the person who memorized the most coding patterns. They are optimizing to avoid a bad hire who writes a policy-enforcement path with a subtle bypass in it. So the coding bar is real but not exotic, and the depth questions are where offers are won or lost.

The loop runs remotely over Zoom, which helps if you aren’t local to Newport Beach or Palo Alto. Obsidian doesn’t state its visa-sponsorship policy publicly, so if you need sponsorship or you’re interviewing from outside the US, confirm work-authorization and remote eligibility with the recruiter on that first call rather than assuming.

The coding and systems rounds

The assessment and live coding tend toward practical data manipulation: parsing and normalizing event logs, deduping and joining records across sources, walking a permission or group-membership graph, rate-limited API ingestion. Obsidian’s core asset is a knowledge graph that ties identities, apps, and activity together, so graph traversal and set reasoning show up more than heavy dynamic programming. Know your hash maps cold, be comfortable with BFS/DFS over an adjacency list, and be able to reason about database indexing when a query over millions of audit events gets slow.

Example prompts in the spirit of what they ask:

  • Given a stream of SaaS audit events, detect when a single identity performs an action outside its normal set of apps within a time window.
  • You ingest from dozens of third-party APIs, each with its own rate limit and pagination. Design the ingestion layer so one slow tenant can’t starve the others.
  • Given groups that contain users and other groups, resolve the full effective membership for a user, and handle cycles.
  • Model an agent’s requested permissions against a policy and decide allow/deny at request time with sub-millisecond latency.

The system design round, when it happens, is grounded in their actual problem: multi-tenant data collection from external SaaS and identity providers, a graph store, and a policy engine that has to make allow/deny decisions in the request path. That last part is where a classic rate limiter design conversation becomes relevant, because runtime enforcement has the same latency and fail-open-versus-fail-closed tradeoffs. A workable sketch of the hot path looks like this:

on agent_request(agent, action, resource):
    policy = cache.get(agent.id)          # in-memory, the fast path
    if policy is None:                    # cache miss
        policy = policy_store.fetch(...)  # network call, can time out
    decision = evaluate(policy, action, resource)
    audit_log(agent, action, resource, decision)
    return decision                       # allow / deny

The interesting line is the cache miss. Expect to defend what happens when policy_store.fetch is unreachable: do you block the agent (safe, but you’ve just broken production) or let it through (available, but you’ve created the exact gap you were hired to close). There is no clean answer, and they want to hear you reason about it, probably landing on fail-closed for high-risk actions and a short cache TTL so the window of staleness is bounded. If you want a broader warm-up on this style of problem, the system design interview guides hub covers the patterns.

Security depth: where they actually screen

This is the round that separates Obsidian from a generic backend interview. You should be able to talk concretely about OAuth and SAML token flows, what a refresh token compromise looks like, how session hijacking works in a SaaS context, and why non-human identities (service accounts, API tokens, and now AI agents) are harder to govern than human users. The agent angle is current and specific: be ready to discuss what the Model Context Protocol is, why an agent with broad tool access is a privilege-escalation risk, and how you would detect an agent reaching for data far outside its task. You don’t need to have built this before, but you need the mental model. Candidates who treat “AI security” as a buzzword get found out in about two questions. The AI-era interview guide is worth a read for how this category of question is being asked across the industry right now.

If your background is pure backend with no security exposure, that’s fine, but don’t fake it. Say what you know, reason from first principles about trust boundaries and least privilege, and show you can learn the domain. That reads far better than a shallow recitation of acronyms.

The behavioral loop is not a formality

With this many conversations weighted toward background and judgment, your stories carry real weight. They want evidence you’ve owned something end to end, handled an incident or a security tradeoff under pressure, and can disagree without being difficult. Prepare three or four concrete stories with measurable outcomes and rehearse them in STAR format so you’re not reconstructing them live. A founder conversation usually probes motivation and whether you understand why the company exists, so have a real answer for why securing AI agents interests you beyond the valuation headline.

Comp and how to negotiate

Under California’s pay-transparency law (SB 1162), roles that can be performed in California should carry a posted salary range, so you’ll likely see a number on the listing. Expect it to be wide enough that it’s only a starting point, and remember it says nothing about equity, which is the figure that actually matters at this stage. Pull recent data points for comparable Series C/D security startups on levels.fyi and Blind to sanity-check the base. A $1.1 billion valuation sets a high strike price, so push on share count and the current 409A, understand your vesting and what happens on a liquidity event, and model the whole package rather than fixating on base. Our total comp calculator helps you compare an offer across base, bonus, and equity, and the salary negotiation guide covers how to anchor when the posted range is too wide to be useful.

Attribute Detail (Obsidian Security, as of October 2026)
Founded 2017
Headquarters Newport Beach, CA, with a Palo Alto office
Category AI-agent and SaaS identity security (runtime governance over agent permissions, MCP/tool usage, non-human identity)
Latest round $85M Series D, August 4, 2026, reported as led by Crescent Cove Advisors
Valuation $1.1 billion (unicorn)
Participating investors Greylock, Menlo, Wing, GV, Norwest (existing backers)
Customers Reported 60 of the Fortune 500
AI governance surfaces Native controls for Anthropic Claude Code and Cowork; Microsoft Copilot guardrails; MCP server inventory
Typical eng loop Recruiter screen, online coding assessment, technical + security rounds, multi-person behavioral loop (can include CEO), remote over Zoom
Comp data CA listings should carry a posted range (SB 1162) but run wide; benchmark via levels.fyi and weigh equity

Sources: round size and valuation per The Next Web; lead investor and named participants (Greylock, Menlo) per Pulse 2.0, prior backers per The Next Web (Aug 2026); product details per the Obsidian Security blog; founding history per VentureBeat.

How to prep in a weekend

If you have a few days, split them. Spend the most time on the security depth round, because that’s the differentiator and the part you can’t cram the night before: read Obsidian’s own blog posts on agent governance and MCP so you can speak their language, and make sure you can explain OAuth flows and least-privilege design without notes. Keep coding sharp with graph traversal, hashing, and streaming/windowing problems rather than hard DP. Write your behavioral stories down. And look at the broader AI-native company interview guides for how loops at this stage tend to run, the AI-startup interview difficulty index for where this loop ranks against its peers, and the full company guides index if you’re interviewing in parallel.

The candidates who do well here aren’t the ones with the fastest array-reversal. They’re the ones who, when asked what happens when the policy engine times out mid-request, pause and actually think about who gets hurt either way.

newsletter

What's actually being asked right now

Interview patterns & comp trends, straight to your inbox.

No spam. Unsubscribe anytime.

newsletter

What's actually being asked right now

Interview patterns & comp trends, straight to your inbox.

No spam. Unsubscribe anytime.

1972 Soviet postage stamp commemorating the Mars 2 probe

worth a read

Mars For The Rest of Us — a weekly-or-more deep dive on the technical side of Mars exploration: rocket propulsion, microbiology, mission architecture, and everything in between. Written by Maciej Ceglowski.

Read it on Substack →
Scroll to Top