Pre-Screening Interview Questions to Ask a DeFi Risk Analyst

Last updated on

Most large losses in this sector came from risks that were visible beforehand to someone who looked. These questions separate analysts who read the contracts from those who read the documentation.

TL;DR, what to screen for

The best pre-screening questions for a decentralised finance risk analyst test four things: risks they identified before a loss rather than after, whether they read contract code rather than project documentation, whether oracle and liquidity risk are assessed concretely, and whether they understand how positions correlate in a crisis. Ask what they refused to approve.

  • Risks found early
  • Code not documentation
  • Oracles and liquidity
  • Correlation in a crisis

Why pre-screen DeFi risk analysts before the investment interview

The failures in this sector are well documented and were mostly foreseeable: an oracle that could be manipulated within a single transaction, a liquidity pool with an exit nobody could take at size, a governance token concentrated enough that one holder could pass anything. Analysts worth hiring read the contracts and can name a protocol they declined. A short screen asks for that, because the documentation always describes a safe system.

What actually matters when screening DeFi Risk Analyst candidates

  1. 01

    Technical command

    Test command of AMM mechanics, collateral factors, liquidation curves and oracle design; ask how they model bad debt on Aave or Compound style lending markets.

  2. 02

    Deals and deliverables that closed

    Probe concrete deliverables: risk parameter recommendations passed by governance, Gauntlet or Chaos Labs style simulations, listing memos, or dashboards built on Dune and Nansen.

  3. 03

    Risk judgement

    Assess how they weigh depeg scenarios, bridge exposure, thin liquidity on long-tail collateral, and admin key or multisig centralization when sizing a position or limit.

  4. 04

    Explaining it to decision-makers

    Judge how they brief treasury committees, DAO delegates or non-technical investors on exploit exposure and stress test results without collapsing into jargon.

Pre-screening questions to ask DeFi Risk Analyst candidates

12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.

Risks found early

3 questions
  1. 01Can you discuss a situation where you identified a significant risk and how you addressed it?

    Listen for

    A specific mechanism identified before any loss, with what they recommended and whether it was acted on.

    Risks identified after a public incident, or analysis that only ever confirmed a decision already made.

  2. 02Can you provide an example where you audited a protocol and found critical issues?

    Listen for

    Findings from reading the code with the vulnerability class named, and what happened after they reported it.

    Audit experience that turns out to be reading someone else's audit report.

  3. 03Can you describe your experience with risks associated with flash loan attacks?

    Listen for

    The mechanism understood, including how price manipulation within a single transaction enables the attack.

    The attack named with no understanding of how it works, or treated as a solved problem.

Code not documentation

3 questions
  1. 04What is your experience analysing smart contracts for vulnerabilities?

    Listen for

    Code read directly with specific vulnerability classes checked, rather than reliance on published audits.

    Assessment based on documentation and audit badges, or no ability to read contract code.

  2. 05What key indicators do you consider when evaluating a protocol's security?

    Listen for

    Upgrade keys, admin privileges and timelocks examined, since these determine who can change the rules.

    Security judged by audit status alone, or admin key control never examined.

  3. 06Can you explain how you conduct stress testing on protocols?

    Listen for

    Scenarios that combine a price shock with liquidity withdrawal, rather than testing each in isolation.

    Stress testing described as historical volatility, or scenarios that assume orderly markets.

Oracles and liquidity

3 questions
  1. 07How do you evaluate the risk of liquidity pools?

    Listen for

    Depth assessed against realistic exit size, with impermanent loss and concentration of providers considered.

    Liquidity judged by headline total value, or exit assumed possible at the quoted price.

  2. 08How do you handle the risk of oracle failure in these systems?

    Listen for

    Feed sources examined for manipulation resistance, with the reference market's own liquidity considered.

    Oracles assumed reliable, or single-source price feeds not identified as a risk.

  3. 09What strategies do you use to assess risks associated with decentralised exchanges?

    Listen for

    Slippage, routing and the exchange's own contract risk assessed rather than volume alone.

    Exchange risk assessed by trading volume, or contract risk of the venue itself not considered.

Correlation in a crisis

3 questions
  1. 10How do you evaluate systemic risk across interconnected protocols?

    Listen for

    Dependency between protocols mapped, with the recognition that diversification fails when they share collateral.

    Positions treated as independent, or shared dependencies between protocols never traced.

  2. 11How do you analyse governance risks in decentralised organisations?

    Listen for

    Token concentration examined against the threshold needed to pass a proposal, with timelock protections checked.

    Governance treated as decentralised by default, or voting concentration never examined.

  3. 12How do you ensure compliance with regulatory frameworks while assessing these risks?

    Listen for

    Sanctions and regulatory exposure considered alongside technical risk, with jurisdiction-specific obligations named.

    Regulation treated as unsettled and therefore ignored, or sanctions screening never mentioned.

How to score responses

Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.

  1. Technical command

    35%

    5Explains loan-to-value calibration, oracle latency risk and liquidation cascade math with reference to specific protocols and on-chain data sources.

  2. Deals and deliverables that closed

    25%

    5Cites named parameter proposals or risk reports they authored, with the forum thread, vote outcome and observed effect on protocol solvency.

  3. Risk judgement

    25%

    5Ranks risks by loss severity rather than novelty, and names a token or protocol they refused to approve plus the reasoning.

  4. Explaining it to decision-makers

    15%

    5Translates simulation output into clear solvency implications, states assumptions and confidence, and holds position under governance forum pushback.

The largest losses came from mechanisms visible beforehand to anyone reading the contracts. A one-way video screen asks what they refused to approve.

Try it on Hirevire

Screening FAQ

Process basics

How long should a pre-screening round for this role take?

Fifteen minutes across eight to ten questions, answered async. Enough to establish risks they found, test whether they read contract code, and hear how they assess oracle and liquidity exposure.

How technical does this role need to be?

Enough to read contract code. An analyst working from documentation and audit summaries is assessing what a project says about itself, which is exactly what failed in the largest incidents.

Evaluating answers

What is the strongest signal when screening this role?

Something they refused. Analysts doing real work decline protocols, and can explain the specific mechanism that worried them. Anyone whose assessments all passed has been documenting rather than assessing.

How do I judge their oracle thinking?

Ask how a price feed could be manipulated. Real answers cover single-source feeds, thin liquidity on the reference market and manipulation within one transaction. This is the mechanism behind many large losses.

Go deeper on this role

Sanat Hegde
Sanat Hegde
Founder, Hirevire

Sanat has been hiring since 2012 and watching the recruitment industry change up close ever since, and turned that screening process into Hirevire's video screening platform. LinkedIn

Trusted by 500+ Companies

Screen DeFi Risk Analyst candidates on Hirevire

Turn this question list into an async video screen in minutes. Every applicant answers the same contract, oracle and liquidity questions on camera, so you compare scepticism rather than familiarity.