Pi Sigma Logo
Back to open roles
Internship3 openings

Security Engineer Intern.

About the role

You'll work on an AI-driven security platform that automates reconnaissance and vulnerability assessment. This is hands-on offensive and defensive security work.

What you'll do

  • Run and tune authorized security assessment workflows against approved targets
  • Triage assessment output: separate true positives from false positives, and write up findings clearly
  • Reproduce and verify reported vulnerabilities (web app issues: auth flaws, injection, misconfiguration, exposed services)
  • Write small scripts to automate repetitive checks and parse assessment output
  • Help harden our own stack: secrets handling, container and cloud configuration, access control
  • Keep notes and reports that a non-security reader can actually understand

What we're looking for

  • Working knowledge of how the web works: HTTP, DNS, TLS, cookies, sessions
  • Familiarity with the OWASP Top 10 and what each item looks like in practice
  • Comfort in Linux and the command line
  • Python: you can read and write it well enough to automate a task end to end
  • Have completed hands-on security labs involving vulnerability assessment, network tracing, or web application testing
  • AI tools are welcome, but you must learn, explain, test, and take responsibility for any code you submit. Do not use generated code you do not understand

Nice to have

  • Go: used across modern security engineering; being able to read and patch Go is a strong plus
  • Bash scripting beyond one-liners
  • JavaScript: useful for understanding client-side bugs (XSS, CSP, DOM issues)
  • SQL: enough to understand injection and query behaviour
  • Security lab participation or a public writeup/blog that demonstrates how you investigated a finding
  • Exposure to Docker, cloud (GCP/AWS/DigitalOcean), or CI pipelines
  • Any bug bounty reports, even low-severity ones

You don't need every language on this list. Python plus a genuine willingness to pick up Go is enough.

What you'll get

  • Direct mentorship and real ownership of a piece of the platform
  • Exposure to how security automation and AI-assisted workflows are built end to end