Information Security Intern
Core
Engineering internship focused on real production tasks in vulnerability assessment, penetration testing, and governance, risk, and compliance for a fintech's mobile apps, backend, and cloud infrastructure.
Role type
Early-career Information Security Engineer (Intern)
Builds
Security assessments, remediation tickets, compliance evidence, and security controls for financial products
Domain
Fintech / Information Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information security fundamentals (CIA triad, OWASP Top 10), HTTP/TLS/DNS/TCP/IP, authentication/authorization patterns (OAuth 2.0, JWT), Linux command line, Git workflows, technical writing
Preferred skills
Programming (Python/Go), CTF participation, Burp Suite/OWASP ZAP usage, vulnerability scanners (Nessus, Trivy), mobile app security, container security (Docker/K8s), DevSecOps tooling, SIEM/SOC exposure, SQL basics, cryptography fundamentals, security frameworks (PCI DSS, ISO 27001), risk management concepts, audit basics, GCP security
Technologies
Python, Go, Burp Suite, OWASP ZAP, Nessus, OpenVAS, Trivy, Grype, Semgrep, CodeQL, Snyk, Docker, Kubernetes, GCP, Vanta, Drata, OneTrust
Responsibilities
Triage SAST/DAST/SCA findings, reproduce and document vulnerabilities, contribute to secure code reviews, participate in threat modelling, run scoped assessments, maintain security tooling configs, support compliance programs (PCI DSS, ISO 27001, SAMA), maintain security policies, support vendor assessments, prepare for audits, contribute to security awareness content, work on PII handling and encryption reviews
Seniority
Intern, full-time engagement