Interview questions · Tech & engineering

Computer & Information Systems Manager Interview Questions

The twelve questions a CIO or head of IT actually asks a Computer & Information Systems Manager - from uptime and incident management to budget defense, vendor negotiation, and a technology roadmap under a real constraint. Each with a strong sample answer, the scoring framework, and prep pitfalls.

By Marcus Thompson, Head of Tech Careers · Updated July 9, 2026 · ~13 min read

The short version. A CIS / IT Manager interview is judged on four things fast: operational rigor (uptime, incident response, change management), business partnership (translating IT to the CFO and CEO), team leadership (hiring, coaching, and retention in a hard-to-hire discipline), and roadmap judgment (what did you say no to, and why). A CIO is not looking for your favorite framework. They want to know that the systems stayed up, the auditor left happy, the budget defended, and the team was better a year later. Answer with STAR, keep numbers in every story, and never blame vendors or the last CIO. Practice with mock interview.

The scoring framework a CIO actually uses

A Computer & Information Systems Manager (or IT Manager) interview loop - recruiter screen through final with the CIO or CTO - is a check on four things a hiring CIO needs to be sure of before writing an offer. If each column has concrete, quantified evidence, you land the job. Anchor your prep to this frame.

ColumnWhat the CIO is scoringWhat proves it
Operational rigorUptime, incident response, change control, patching cadence, backup and restore.SLA numbers, MTTD/MTTR, P1 incidents per quarter, DR test results, change failure rate.
Business partnershipTranslating IT to the CFO and to a business owner.Cost/user, budget defended, TCO story, one time you said "no" and one time you said "yes fast."
Team leadershipHiring, coaching, retention.Team size, open reqs closed, time-to-fill, voluntary attrition, promotions from your team.
Roadmap judgmentWhat you shipped, what you killed, what you deferred.Two decisions you own with dollar or risk consequence.

1. "Walk me through your current infra scope."

Strong answer. "I run IT for a 1,400-person SaaS company across four US offices. Portfolio is identity (Okta), endpoint (Jamf and Intune, 1,600 devices), collab (Google Workspace), SIEM (Splunk), and ticketing (Jira Service Management). Cloud footprint is AWS primary with a small Azure tenant for a legacy app. Team is 14 - two engineers on identity and endpoint, three on infra and network, four on service desk, three on business apps, and two on security. Budget is $8.4M annual - roughly 55% payroll, 30% SaaS, 15% hardware and services."

2. "Tell me about a major incident you managed."

Strong answer. "Last October our identity provider had a 47-minute regional outage during the workday. Detection was 3 minutes via internal synthetic monitoring, ahead of the vendor's page. I opened a bridge with three of my engineers, we cut over authentication for two critical apps to a secondary IdP we had pre-configured for exactly this scenario, and we posted status internally within 8 minutes. Full recovery in 43 minutes. Business impact - roughly 220 support cases avoided because comms were early. Post-mortem produced two changes: a documented dual-IdP posture for our top-10 apps, and a quarterly failover drill."

3. "How do you defend an IT budget?"

Strong answer. "I present three numbers to the CFO every cycle: cost per user, cost as a % of revenue, and a run/change split. Last year we came in at $6,120 per user, 2.3% of revenue, 68/32 run/change. I defend against benchmarks (Gartner mid-tier SaaS) and against a targeted decision - 'here is where I would cut $400K without hurting reliability, and here is where I would add $600K to move MTTR from 40 minutes to 22.' Framing budget as decisions with named consequences, not line items, gets the conversation out of subtraction and into strategy."

4. "How do you handle vendor negotiation?"

Strong answer. "Three steps. First, I never enter a renewal without a real alternative shortlist scoped and priced, and the vendor knows it. Second, I anchor on multi-year with usage guardrails, not on discount percentage - a 20% headline discount without a usage cap is a bad deal. Third, I bring procurement in from day one, not at signature. Last year on our SIEM renewal, I brought a 90-day pilot with a challenger and closed a three-year at 34% below vendor's opening, with a soft cap on ingested data."

5. "How do you decide what to prioritize?"

Strong answer. "Three lenses: reliability (does the change reduce a real risk?), business unlock (does it enable revenue or reduce cycle time for a named team?), and compliance clock (is there a hard date?). I run a monthly portfolio review with the CFO and the head of Ops - one page, top 20 items, RAG'd, dollars and dates. Anything that is not on the list does not get engineered. Anything that is on the list gets a single owner and a review cadence. I killed our BI-tool consolidation last year - two vendors made sense on paper, none of them made the business faster, and every hour on it was an hour off endpoint zero-trust."

6. "Walk me through a security incident."

Strong answer. "Q1 last year, a phishing campaign harvested credentials on 14 employees over 36 hours - MFA blocked most but two accounts were compromised before we hard-rotated. My SIEM alerted on the anomaly, we ran the compromise checklist (rotate, session-kill, forensic pull, comms), and I reported the incident to the CISO and legal within an hour of confirmation. No data exfiltrated. Follow-ups: we moved to phishing-resistant MFA (WebAuthn) on the top 15% risk-tier of users within 60 days, and we shortened session lifetimes on privileged sessions from 24h to 2h."

7. "How do you hire an IT engineer?"

Strong answer. "Four rounds. Recruiter screen, tech screen with a senior IC on the team (I do not run the tech screen; I trust the ICs), a systems-design conversation with me (I am checking judgment on tradeoffs, not depth of implementation), and a values round with a cross-functional partner. My rubric weights judgment, communication, and operational maturity. Last year I closed 6 hires - time to fill averaged 62 days, first-year retention is 100%, one internal promotion. The biggest single change I made was writing the JD around outcomes ('own our identity plane and reduce MTTR on IdP failures') rather than tool checklists."

8. "Tell me about a project that missed."

Strong answer. "Our Zero Trust network segmentation project slipped from Q3 to Q1 next year. The miss was scope - I under-estimated the number of legacy apps that would need adapter work, and I did not have engineering budget for the adapter build in the original plan. I owned the miss, brought a revised plan to the CFO with a phased rollout that captured 70% of the risk reduction in Q3 and deferred the last 30% behind the adapter work. That version shipped. The learning: partner integration risk should have been in the original TCO."

9. "How do you partner with the business?"

Strong answer. "I run a business-partner model - one senior engineer paired with Sales, one with Finance, one with Product/Eng. Each has a monthly cadence with their partner leader, a shared roadmap on one page, and a quarterly business review. Last year my Finance-partner engineer led our NetSuite performance work that took our close from 8 days to 5. That is the model."

10. "First 30/60/90 days."

Strong answer. "Days 1-30: listen and read. 1:1 every direct report, one skip-level per week, sit in on service-desk queue, read the last four post-mortems and the auditor's most recent letter. Days 31-60: two low-risk operational wins - patching hygiene and a MFA baseline audit. Days 61-90: written point of view on the top-three risks, the org shape, and the budget I would defend for FY26."

11. "Compliance and audit."

Strong answer. "I run SOC 2 Type II annually and I sat next to our external auditor through the last two cycles. My playbook: continuous evidence collection (Drata for the boring 60% of controls), monthly control owners reviewing exceptions, and a mock audit six weeks before the real one. We closed the last audit with zero findings and one management letter comment on offboarding lag, which we closed the following quarter."

12. "Why this company, why now?"

Strong answer. "You are at the stage where IT becomes a strategic partner, not just an SLA. Your public roadmap says international expansion and a data-residency initiative - both are IT-shaped problems and both are exactly the work I want to lead next. The team here is small but experienced, and the CFO has publicly said IT is one of three priority hires this fiscal. That is a role I can do the work in for the next three years."

Prep mistakes to avoid

Framework-only answers. "I use ITIL" is a claim. "I used ITIL change severity to decide whether we needed a CAB review for the IdP swap" is evidence.
Blaming the vendor. A CIO expects vendor problems and expects you to have owned the response.
No numbers on operational rigor. Uptime, MTTR, ticket volume, change failure rate.
Skipping business impact. Cost/user, run vs change split, budget defended.

Practice the answers out loud.

Run a live mock interview with a Marqee strategist who has hired at this level.

Book a mock interview ->

Frequently asked questions

What frameworks should I reference?

ITIL v4 for service management and change control, NIST CSF or ISO 27001 for security posture, COBIT for governance if you have run one, and a lightweight change advisory board process. Reference frameworks in the context of a specific decision - 'I used the ITIL change severity matrix to decide whether to require a CAB review for our identity-provider swap' - not as an abstract belief.

How much technical detail should I go into?

Enough to prove you can steer an engineer, not enough to sound like an IC. A CIO expects you to name the identity provider, the endpoint suite, the SIEM, the ticketing system, and the cloud - but not to whiteboard the config. If you get pulled deeper, say 'happy to go under the hood - here is the architecture and the tradeoff.' If you dodge every technical follow-up, the CIO will assume you were carried by your engineers.

How do I answer 'tell me about a major outage'?

Own the timeline. Set the context (business impact - $ per minute, users, region), the detection lag, the response steps (bridge, comms, remediation), the mean time to recover, the root cause you found, and the two systemic changes you made after. A strong answer names actual times and dollar impact and closes with one process change and one technology change. Avoid finger-pointing at vendors or engineers.

What questions should I ask the CIO?

Diagnostic - 'What are the three loudest complaints from the business today?' 'Which system do you least trust and why?' 'What is the audit story right now?' Strategic - 'Where do you want IT to be an accelerator versus a guardrail in 12 months?' 'How is IT budget set - top-down or bottoms-up?' Team - 'What are the openings and where are they hardest to fill?' Avoid the platitude questions.

What is a realistic salary for this role?

Per the U.S. Bureau of Labor Statistics (2024), Computer and Information Systems Managers earn a national median near $169,510, with most between roughly $99,000 and $239,000. Metro, industry (financial services and tech tend higher), org size, and the specific portfolio (security, cloud, enterprise apps) all move the number. Base is usually 70-85% of total; the rest is bonus and, in some public and pre-IPO companies, equity.

Should I mention certifications?

Yes, briefly. PMP, ITIL v4, CISSP, CISM, and cloud manager-level certs (AWS/Azure/GCP) all pass a resume filter. In the interview, do not lead with them - lead with what you have shipped and defended. Certs are a floor signal, not a differentiator, at this level.