Security Engineering Intern, Blue Team
Job description
About the role
Join our cyber defense unit to protect digital assets through active monitoring, cloud defense, and threat hunting. You will work alongside our security engineers to manage daily operations while building technical expertise in a high-speed environment. This internship provides a structured path to deepen your understanding of enterprise security operations and incident response. You will be immersed in real-world scenarios that require quick thinking and precise execution under pressure. The role emphasizes collaboration, clear communication, and a proactive approach to identifying risks before they escalate. You will gain hands-on experience with modern security tooling and learn how to translate technical findings into actionable insights. This position is ideal for individuals who are passionate about defending systems and eager to contribute to a resilient security posture. Success in this role will be measured by your ability to support the team in improving detection accuracy and strengthening overall infrastructure security.
Key facts
What you'll do
- Triage security alerts from SIEM platforms like ELK or DataDog and refine detection rules to reduce false positives and improve accuracy.
- Review cloud configurations using CSPM tools to address security gaps and ensure adherence to best practices and compliance standards.
- Observe CSIRT incident investigations and help with initial analysis and reporting to understand the full lifecycle of response activities.
- Conduct threat hunting to uncover activity that bypasses automated systems and identify indicators of compromise that require further investigation.
- Maintain defensive infrastructure including EDR, XDR, WAF, email security, and IDS/IPS to ensure they operate effectively and are properly tuned.
- Build scripts to interact with cloud APIs and automate security tasks, reducing manual effort and increasing operational efficiency.
- Integrate AI and LLM tools to improve detection workflows and explore innovative methods for enhancing security analytics.
- Create and update security documentation, runbooks, and internal reports to capture procedures, decisions, and lessons learned for future reference.
- Collaborate with cross-functional teams to align security initiatives with business objectives and ensure that controls are appropriately scaled.
- Analyze security trends and emerging threats to support the development of more robust defense strategies over time.
- Validate security configurations across environments to confirm that they meet organizational standards and regulatory expectations.
- Support the implementation of new security tools and processes by assisting with testing, deployment, and optimization activities.
- Monitor security performance metrics and provide insights that help drive continuous improvement across the security program.
- Assist in preparing status updates and summaries for internal stakeholders to maintain visibility into security operations.
Requirements
- Current enrollment in a bachelor or master degree program in Cybersecurity, Computer Science, IT, or a related field.
- Foundational knowledge of network security and cybersecurity principles including core concepts and common attack vectors.
- Proficiency with Windows, Linux, and MacOS environments for performing investigations and managing security tools.
- Ability to write basic scripts for task automation using languages such as Python or Bash to streamline repetitive activities.
- Familiarity with the MITRE ATT&CK framework to understand adversary tactics, techniques, and procedures.
- Strong analytical capabilities and problem-solving skills to interpret complex data and draw meaningful conclusions.
- Professional proficiency in both Vietnamese and English to communicate effectively with team members and stakeholders.
- Interest in applying AI tools to security operations to explore how emerging technologies can enhance detection and response.
- Willingness to follow established procedures while also contributing ideas for improving security workflows and efficiency.
- Commitment to maintaining confidentiality and handling sensitive information in accordance with organizational policies.
- Ability to work independently and as part of a team in a fast-paced environment with shifting priorities.
- Readiness to learn new technologies and adapt quickly to changes in the security landscape and tooling.
Nice to have
- Experience in Cryptocurrency, Blockchain, Fintech, or Finance Trading sectors to better understand relevant threat landscapes.
- Knowledge of SIEM monitoring concepts and how to leverage log data for effective detection and analysis.
- Experience with AWS, Azure, or GCP security services to support cloud security initiatives and configuration reviews.
- Exposure to Infrastructure as Code or systems automation to streamline deployment and ensure consistency.
- Hands-on experience with EDR, WAF, or DNS security tools to assist in maintaining and tuning security controls.
- Progress toward certifications like CompTIA Security+, AWS SAA, or CEH to demonstrate foundational security knowledge.
- Interest in AI security research to explore how machine learning can be applied to detect and respond to threats.
Practical notes
- We offer mentorship from senior staff and exposure to enterprise-level security technologies to support your professional growth.
- Performance may lead to a full-time employment offer based on demonstrated skills and team fit.
- Schedules are flexible to fit your academic requirements, allowing you to balance work and study commitments effectively.
- By applying, you agree to the data processing terms outlined in our privacy policy at https://www.coinhako.com/legal/sg-1/privacy_policy.