Back to the community

GitHub behavioral interview questions

Researched interview questions, process detail, and difficulty signals for GitHub, compiled by the Primly research team.

6 experiences Difficulty 3.5/5 Technology / Developer Tools

Security Engineer (Application Security)

virtual · Difficulty 4/5

Candidates report an initial recruiter screen that covers scope preferences within security, experience with modern web and cloud threat models, and alignment with GitHub’s developer-first products including Copilot and enterprise offerings. The hiring manager interview typically centers on prioritization, influencing engineering teams, and how risk is communicated and reduced in a product organization with a large developer audience. Many candidates describe a technical round that tests application security fundamentals through architecture review, threat modeling, or vulnerability triage scenarios that resemble GitHub’s surface area, such as OAuth apps, webhooks, CI workflows, and multi-tenant services. A panel stage often follows with cross-functional partners, where candidates walk through secure design tradeoffs, incident learnings, and building guardrails such as secure defaults, security reviews, and automated detection. Final conversations frequently emphasize collaboration style, decision-making under ambiguity, and how candidates would scale security via tooling and enablement rather than gatekeeping, with timelines often spanning a few weeks depending on interview panel availability.

  • Given a feature that allows third-party GitHub Apps to request permissions and receive webhooks, what would a threat model cover and what mitigations would be prioritized first?
  • How would an SSRF report in a service that fetches repository URLs be triaged, validated, and scoped for impact in a multi-tenant environment?
  • A team wants to ship a new GitHub Actions feature that executes user-provided code in runners. What controls would be required to reduce abuse and credential theft risk?
  • Describe a time an engineering team disagreed with a security recommendation. How was the discussion handled and what outcome was driven?
  • What does 'security as enablement' look like in practice for a developer tools company, and how would success be measured over time?

Technical Support Engineer

virtual · Difficulty 3/5

Candidates report starting with a recruiter screen focused on availability, location and time zone alignment, and motivation for supporting developers on GitHub products like GitHub.com, GitHub Enterprise Server, Actions, and Packages. The next step is typically a hiring manager conversation that probes troubleshooting approach, written communication, and comfort navigating ambiguous customer reports. Many candidates describe a practical assessment or work sample, often framed as responding to a customer ticket or triaging an issue using logs, reproduction steps, and documentation, with emphasis on clarity and accuracy. Panel interviews commonly follow, conducted virtually, mixing scenario-based support cases with collaboration questions about partnering with engineering, product, and incident response during outages. Final steps often include reference checks and a discussion of shift expectations and on-call or incident support participation, with the overall loop commonly taking a few weeks depending on scheduling and the volume of candidates.

  • A customer says their GitHub Actions workflow suddenly started failing after working yesterday. What questions would be asked first, and how would the issue be narrowed down before escalating?
  • How would a minimal repro be created for a report that cloning over SSH fails for one repository but works for others?
  • Write a reply to a frustrated administrator who cannot push to a protected branch in GitHub Enterprise Server. What information would be included and what tone would be used?
  • Describe a time a complex technical problem had to be explained to a non-expert. How was understanding confirmed and what was documented?
  • When should a support engineer treat an issue as a potential security incident, and how should that be handled to protect customer data and trust?

Developer Advocate

virtual · Difficulty 3/5

Recruiter screen, hiring manager video, conference-talk presentation (deliver a 20-min technical talk), behavioral, and final with director. DevRel at GitHub is high-visibility and global.

  • Walk me through a developer-facing campaign you led.
  • Tell me about handling negative feedback from the dev community.
  • Describe partnering with engineering on a feature launch you advocated for.
  • How do you stay credible with senior engineers?