Why pre-screen DeFi risk analysts before the investment interview
The failures in this sector are well documented and were mostly foreseeable: an oracle that could be manipulated within a single transaction, a liquidity pool with an exit nobody could take at size, a governance token concentrated enough that one holder could pass anything. Analysts worth hiring read the contracts and can name a protocol they declined. A short screen asks for that, because the documentation always describes a safe system.
What actually matters when screening DeFi Risk Analyst candidates
- 01
Technical command
Test command of AMM mechanics, collateral factors, liquidation curves and oracle design; ask how they model bad debt on Aave or Compound style lending markets.
- 02
Deals and deliverables that closed
Probe concrete deliverables: risk parameter recommendations passed by governance, Gauntlet or Chaos Labs style simulations, listing memos, or dashboards built on Dune and Nansen.
- 03
Risk judgement
Assess how they weigh depeg scenarios, bridge exposure, thin liquidity on long-tail collateral, and admin key or multisig centralization when sizing a position or limit.
- 04
Explaining it to decision-makers
Judge how they brief treasury committees, DAO delegates or non-technical investors on exploit exposure and stress test results without collapsing into jargon.
Pre-screening questions to ask DeFi Risk Analyst candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Risks found early
3 questions01Can you discuss a situation where you identified a significant risk and how you addressed it?
Listen forA specific mechanism identified before any loss, with what they recommended and whether it was acted on.
Risks identified after a public incident, or analysis that only ever confirmed a decision already made.
02Can you provide an example where you audited a protocol and found critical issues?
Listen forFindings from reading the code with the vulnerability class named, and what happened after they reported it.
Audit experience that turns out to be reading someone else's audit report.
03Can you describe your experience with risks associated with flash loan attacks?
Listen forThe mechanism understood, including how price manipulation within a single transaction enables the attack.
The attack named with no understanding of how it works, or treated as a solved problem.
Code not documentation
3 questions04What is your experience analysing smart contracts for vulnerabilities?
Listen forCode read directly with specific vulnerability classes checked, rather than reliance on published audits.
Assessment based on documentation and audit badges, or no ability to read contract code.
05What key indicators do you consider when evaluating a protocol's security?
Listen forUpgrade keys, admin privileges and timelocks examined, since these determine who can change the rules.
Security judged by audit status alone, or admin key control never examined.
06Can you explain how you conduct stress testing on protocols?
Listen forScenarios that combine a price shock with liquidity withdrawal, rather than testing each in isolation.
Stress testing described as historical volatility, or scenarios that assume orderly markets.
Oracles and liquidity
3 questions07How do you evaluate the risk of liquidity pools?
Listen forDepth assessed against realistic exit size, with impermanent loss and concentration of providers considered.
Liquidity judged by headline total value, or exit assumed possible at the quoted price.
08How do you handle the risk of oracle failure in these systems?
Listen forFeed sources examined for manipulation resistance, with the reference market's own liquidity considered.
Oracles assumed reliable, or single-source price feeds not identified as a risk.
09What strategies do you use to assess risks associated with decentralised exchanges?
Listen forSlippage, routing and the exchange's own contract risk assessed rather than volume alone.
Exchange risk assessed by trading volume, or contract risk of the venue itself not considered.
Correlation in a crisis
3 questions10How do you evaluate systemic risk across interconnected protocols?
Listen forDependency between protocols mapped, with the recognition that diversification fails when they share collateral.
Positions treated as independent, or shared dependencies between protocols never traced.
11How do you analyse governance risks in decentralised organisations?
Listen forToken concentration examined against the threshold needed to pass a proposal, with timelock protections checked.
Governance treated as decentralised by default, or voting concentration never examined.
12How do you ensure compliance with regulatory frameworks while assessing these risks?
Listen forSanctions and regulatory exposure considered alongside technical risk, with jurisdiction-specific obligations named.
Regulation treated as unsettled and therefore ignored, or sanctions screening never mentioned.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical command
35%5Explains loan-to-value calibration, oracle latency risk and liquidation cascade math with reference to specific protocols and on-chain data sources.
Deals and deliverables that closed
25%5Cites named parameter proposals or risk reports they authored, with the forum thread, vote outcome and observed effect on protocol solvency.
Risk judgement
25%5Ranks risks by loss severity rather than novelty, and names a token or protocol they refused to approve plus the reasoning.
Explaining it to decision-makers
15%5Translates simulation output into clear solvency implications, states assumptions and confidence, and holds position under governance forum pushback.
The largest losses came from mechanisms visible beforehand to anyone reading the contracts. A one-way video screen asks what they refused to approve.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for this role take?
Fifteen minutes across eight to ten questions, answered async. Enough to establish risks they found, test whether they read contract code, and hear how they assess oracle and liquidity exposure.
How technical does this role need to be?
Enough to read contract code. An analyst working from documentation and audit summaries is assessing what a project says about itself, which is exactly what failed in the largest incidents.
Evaluating answers
What is the strongest signal when screening this role?
Something they refused. Analysts doing real work decline protocols, and can explain the specific mechanism that worried them. Anyone whose assessments all passed has been documenting rather than assessing.
How do I judge their oracle thinking?
Ask how a price feed could be manipulated. Real answers cover single-source feeds, thin liquidity on the reference market and manipulation within one transaction. This is the mechanism behind many large losses.
























