Security Engineering Intern Blue Team
Summary
Intern on the Blue Team to monitor alerts, tune detection rules, hunt threats, and automate security workflows using cloud tools and AI/LLM assistance.
You will support defensive security operations by monitoring and triaging alerts, tuning detection rules, reviewing cloud misconfigurations, assisting with incident investigations, participating in threat hunting, operating security tools, developing automation, applying AI and LLM tools, and documenting procedures and reports.
Responsibilities
- Monitor and triage security alerts from SIEM tools
- Tune detection rules to improve alert fidelity
- Review and remediate cloud misconfigurations using CSPM tools
- Assist with security incident investigations and documentation
- Participate in threat hunting exercises
- Operate and maintain EDR, XDR, WAF, Email Security, and IDS/IPS technologies
- Write scripts that interface with cloud-based APIs
- Apply AI and LLM tools to improve detection and security workflows
- Document security procedures, runbooks, and reports
Requirements
- Currently pursuing a bachelor's or master's degree in Cybersecurity, Computer Science, IT, or a related field
- Basic understanding of cybersecurity concepts and network fundamentals
- Familiarity with Windows, Linux, and MacOS
- Basic scripting or programming knowledge
- Awareness of the MITRE ATT&CK framework
- Knowledge of SIEM tools and security monitoring concepts
- Familiarity with AWS, Azure, or GCP and their native security services
- Exposure to Infrastructure as Code solutions or systems automation platforms
- Experience with EDR, WAF, or DNS security tools
- Vietnamese and English communication skills
- Understanding or experience in Cryptocurrency, Blockchain, Fintech, or Finance Trading
Benefits
- Flexible schedule to accommodate academic commitments