Candidates report starting with a recruiter screen that confirms domain fit (SOC, detection engineering, incident response), work authorization, and role scope within a regulated financial environment. A technical video interview commonly follows with a security leader or senior engineer, focusing on hands-on detection logic, incident triage, and security tooling familiarity. Many candidates report a deeper technical round that can resemble a working session, such as walking through a recent incident, interpreting logs, or designing detections for common attacker behaviors in enterprise Windows and cloud environments. A final stage often includes interviews with cross-functional stakeholders, such as infrastructure, IAM, risk, or application security, to evaluate collaboration and documentation rigor. End-to-end timelines are often reported around 3 to 6 weeks, with variability driven by stakeholder scheduling and internal risk and compliance checks before an offer is finalized.
Given endpoint telemetry showing suspicious PowerShell execution and an unusual outbound connection, how would you triage the alert and decide containment steps in a financial institution environment?
Describe how you would build and validate a detection for credential dumping or lateral movement. What data sources would you rely on and how would you minimize false positives?
Walk through an incident you led where business impact and regulatory expectations constrained response actions. How did you communicate decisions and document evidence?
How would you approach securing service accounts and privileged access for systems that support custody and asset servicing workloads, while maintaining operational uptime?
What does strong security culture look like in a highly regulated firm, and how do you influence engineering teams to adopt controls they may see as friction?
Client Service Representative (Asset Servicing)
virtual
· Difficulty 2/5
Candidates report an initial recruiter screen (15 to 30 minutes) focused on availability, location preferences, shift coverage, and basic fit for an asset servicing client support environment. The next stage is typically a hiring manager video interview that tests communication clarity, issue triage, and understanding of how custody and fund accounting operations interact with client expectations. Some candidates report a second panel-style virtual round with 2 to 3 interviewers from client service and adjacent operations (for example, fund accounting, transfer agency, or custody processing) to evaluate cross-team handoffs and attention to detail. The process often includes standard background checks and may include verification steps aligned to regulated finance roles. Timelines commonly range from about 2 to 5 weeks end-to-end depending on team urgency and internal approvals.
Walk through how you would handle a client escalation where a NAV or position report looks incorrect and the client needs an answer within the hour.
Describe a time you had to explain a complex process or policy to a non-expert customer and what you did to confirm they understood.
What do you think BNY Mellon does in custody or asset servicing, and where does client service fit into that model day to day?
Tell an example of when you caught an error before it impacted a customer. What checks did you use and what was the outcome?
How do you prioritize when you have multiple client inquiries, an internal processing cutoff, and incomplete information from another team?
Risk Manager
virtual
· Difficulty 3/5
Recruiter screen, hiring manager video, case study, behavioral, and final with director. Enterprise Risk at BNY is well-resourced.
Walk me through identifying a risk pattern at custody scale.
Tell me about advising business on a risk-driven decision.
Describe partnering with technology on a risk-control implementation.