CareerPlanGet AI match score →

Security & Platform Engineering Intern - Orquesta

💼 Internship🗓 2026-06-24

Core

Building SOC 2 Type II audit controls and hardening security/operational standards for an AI agent platform across microservices and databases.

Role type

Security & Platform Engineering Intern

Builds

Production security controls, audit evidence, and hardened infrastructure for enterprise AI agents.

Domain

Cybersecurity, DevOps, Cloud Infrastructure, AI Platform Engineering

Deliverable

production ML models | infrastructure

Required skills

Python or TypeScript, Git (branching/PRs), system administration, documentation, incident response, CI/CD pipelines

Preferred skills

CTF/bug bounty experience, Docker/GitHub Actions, SOC 2/ISO 27001 knowledge, Open-source contributions, Cloud platforms (GCP/AWS/Azure), FastAPI

Technologies

GCP Secret Manager, AWS Secrets Manager, CloudWatch, Datadog, Loki, Postgres, TimescaleDB, Neo4j, Dependabot, Trivy, gitleaks, Bandit, CodeQL, Prometheus, Grafana, FastAPI, Cloudflare, Syft

Responsibilities

Migrate secrets to managed vaults, implement centralized log aggregation, design and test automated backup/restore procedures, integrate security scanning tools into CI, configure monitoring and alerting, create incident response runbooks, define branch protection rules, implement rate limiting and WAF, enforce encryption at rest and TLS, generate SBOMs.

Seniority

Intern, final-year student

Rewrite
## About the role Most internships put you on a hello-world side project that gets archived the day you leave. Not this one. Orquesta is preparing for our SOC 2 Type II audit — the security and operational standard that decides whether enterprises will let our AI agents touch their data. As an intern, you'll work alongside the founding engineering team to actually build the controls that get us there. Every PR you ship is evidence that goes into the audit binder. This is the kind of work most engineers don't get to touch until they're 5+ years in. You'll see how a real production system gets hardened, monitored, recovered from failure, and made audit-ready — across ~10 microservices, two databases, a vector store, an LLM agent layer, and a Next.js front end. If you've done security CTFs, contributed to OSS, written a non-trivial deploy script, or rebuilt your home lab three times because you wanted to learn it properly — you'll have a great time here. ## What you'll actually ship Pick 3–5 of these (the rest become someone else's problem after your internship): - Secrets vault migration — get every service off dev-key-change-in-production and onto GCP Secret Manager or AWS Secrets Manager. Write the rotation runbook. - Central log aggregation — ship our structlog JSON output to CloudWatch / Datadog / Loki with ≥1-year retention. Wire the audit trail into a queryable surface. - Automated backups + restore drill — design backup jobs for Postgres + TimescaleDB + Neo4j, then actually run a restore drill and document what you broke. - Dependency + container + secret scanning — wire Dependabot, Trivy, gitleaks, Bandit, CodeQL into every CI workflow. Triage and fix the first wave of findings. - Monitoring + alerting — stand up Prometheus + Grafana (or Datadog), define SLOs for the core services, write alert rules that page when they matter and stay quiet when they don't. - Incident response toolkit — runbooks per service, on-call rotation doc, post-mortem template, "first incident" simulation exercise. - Branch protection + CODEOWNERS — define and roll out the GitHub ruleset across ~10 repos; figure out how to do it without blocking the team's velocity. - Rate limiting + WAF — slowapi middleware on FastAPI services + Cloudflare in front of the prod ingress. - Encryption at rest + TLS everywhere — migrate to managed DBs with encryption flags, add TLS to internal service-to-service calls. - SBOM pipeline — generate Syft SBOMs in CI, attach to releases, run automated license audit. You won't do all of these. You'll do a handful end-to-end, and they'll be real. ## About the company Orquesta is an early-stage AI company building technology to help organizations make better decisions and operate with greater intelligence. Founded by a former Meta and JPMorgan technology leader, we're assembling a small team of exceptional builders shaping the future of enterprise software. ## Must have - Currently in your final year (B.Tech / B.E. / M.Tech / MS) or a final-year project / capstone you can point at - Solid programming foundation in Python or TypeScript (one is enough — you'll learn the other on the job) - You've used Git beyond git push — branches, PRs, conflict resolution, reading a diff - You've spun up something non-trivial yourself — a home server, a CTF box, a side project deployed somewhere, an OSS contribution that got merged - You read documentation when you're stuck, then try things, then ask one sharp question — in that order ## Strongly preferred (any one or two) - CTF / bug bounty / security write-ups — HackTheBox, picoCTF, HackerOne reports, anything that shows you think like an attacker - DevOps / SRE-adjacent experience — Docker, GitHub Actions, a deploy script you actually wrote, Linux comfort - Compliance curiosity — you've read the SOC 2 / ISO 27001 / NIST CSF docs even though no-one made you - Open-source contributions — even small ones; we care more about the conversation in the PR than the line count - Cloud familiarity — GCP / AWS / Azure free tier, you've broken and fixed something on it - Python web framework experience — FastAPI, Flask, or Django (we use FastAPI) ## What you'll get from us - Real mentorship — weekly 1:1 with a senior engineer, code review on every PR, async help any time - A finished thing to show — at the end you'll have shipped controls that protect real customer data and went into a SOC 2 audit. That's a hell of a resume line - A reference letter that says something specific, not "diligent worker" — co-signed by the founder - PPO consideration — if it's working both ways, we'd love to make you a full-time offer at the end ## What we'll be looking for - You'd rather understand the why than copy a snippet that works - You read other people's code carefully when reviewing, you catch the thing the original author missed - You're not allergic to writing runbooks, post-mortems, design docs. Half this internship is documentation - You can hold your ground in a code review but also change your mind when you're wrong - You spotted three things in this JD that could be done better and are already thinking about how ## How to apply When you apply, share: - Resume / LinkedIn (one page is plenty) - A link - GitHub profile, a write-up, a CTF solution, a deploy you're proud of. Anything that shows you've actually built something - A 5–8 sentence note answering: Pick one of the "What you'll actually ship" items above. Why that one? What's the first thing you'd want to understand before starting? What's a question you'd ask the team in week 1? No cover letter. No "Dear Hiring Manager". Just the three things above. We read everything. If you've shipped something interesting, lead with that, we'll skip the GPA paragraph.
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Wellfound ↗