Intern (Cyber Security)
Accops
Job Description & Responsibilities
Detection and Security Monitoring Platforms
Department Cybersecurity
Primary focus Design, build, implementation and validation
Internship Type: Paid
Position Overview
The Cybersecurity Engineering Intern will support the evaluation, design, proof-of-concept development, implementation and validation of open-source technologies used for security monitoring, incident detection and response enablement. The work will cover a hybrid environment comprising cloud infrastructure, on-premises systems, endpoints, network devices, applications, identity services and SaaS platforms.
This is a hands-on security engineering role. The intern will work with the Cybersecurity Manager and collaborate with IT, cloud, infrastructure, DevOps and product engineering teams to establish reliable, secure and supportable security-operations technology capabilities.
Role Scope
The internship focuses on designing, building, integrating, testing and documenting security-monitoring capabilities. It is not a SOC analyst role. The intern will not be responsible for continuous monitoring, managing production alert queues, owning incidents or independently executing containment or response actions. Any access to production systems or data will be supervised, approved and governed by least-privilege and change-management requirements.
Key Responsibilities
Requirements and Tool Evaluation
- Translate agreed security-monitoring and incident-response use cases into functional, technical and operational requirements.
- Research and compare open-source tools for security information and event management, log management, endpoint visibility, network detection, case management, threat intelligence and security orchestration.
- Assess shortlisted tools for integration coverage, detection capability, scalability, performance, access control, deployment complexity, licensing, community health, release cadence and ongoing maintenance effort.
- Document evaluation results using a consistent assessment matrix and recommend tools for controlled proof-of-concept testing.
Solution Design and Proof of Concept
- Develop solution architecture, component, data-flow and integration diagrams for the proposed security-monitoring platform.
- Deploy and configure approved tools in a segregated lab or proof-of-concept environment.
- Implement secure authentication, role-based access, encryption, administrative logging, retention, backup and health-monitoring configurations.
- Record configuration decisions, dependencies, assumptions, issues and risks so that the build can be reproduced and reviewed.
Data Source Integration
- Integrate representative telemetry from Windows and Linux systems, endpoints, network devices, firewalls, cloud platforms, identity services, applications, SaaS platforms and existing security tools.
- Configure and test collection, parsing, normalization, enrichment, indexing, retention, search and dashboard functions.
- Validate that log sources are complete, time-synchronized, correctly classified and traceable to their originating systems.
- Troubleshoot collection, connector, parsing and ingestion issues and document repeatable resolutions.
Detection Engineering and Validation
- Develop and tune detection rules for agreed scenarios such as suspicious authentication, privileged-account misuse, endpoint compromise, unauthorized configuration changes, anomalous network activity and cloud-account misuse.
- Map relevant detection rules and test scenarios to MITRE ATT&CK techniques where appropriate.
- Generate approved test events or simulated activity and verify that telemetry is collected, correlated, enriched, alerted and displayed as designed.
- Assess detection coverage, accuracy, completeness, timeliness, false-positive behavior and the investigative context presented to an eventual SOC or incident-response team.
- Document test cases, expected results, actual results, defects and remediation recommendations.
Automation and Documentation
- Develop basic Python, PowerShell or Bash scripts for log parsing, data transformation, alert enrichment, integration testing and validation reporting.
- Create and maintain technical documentation, including architecture, installation, configuration, integration, administration, testing and troubleshooting guides.
- Design and validate dashboards and reporting templates for operational and management use.
- Present findings, implementation risks and recommendations to cybersecurity and technology stakeholders.
Expected Deliverables
- A documented set of security-monitoring requirements, use cases and acceptance criteria.
- A comparative assessment of shortlisted open-source technologies.
- One or more securely configured and reproducible proofs of concept.
- Validated integrations for agreed cloud, on-premises, endpoint, network, identity and SaaS data sources.
- A baseline library of tested detection rules and corresponding validation results.
- Architecture, build, administration, troubleshooting and handover documentation.
- A final recommendation covering technical fit, limitations, operational effort, infrastructure requirements, risks and an implementation roadmap.
Required Qualifications
- Currently pursuing or recently completed a degree or diploma in cybersecurity, computer science, information technology, electronics or a related discipline.
- Good understanding of cybersecurity, networking, operating systems, system and application logs, authentication and incident-detection concepts.
- Working familiarity with Linux and Windows environments and comfort using command-line tools.
- Basic scripting ability in Python, PowerShell, Bash or a similar language.
- Ability to install, configure, test and troubleshoot software in a lab environment.
- Strong analytical, problem-solving, documentation and written communication skills.
- Ability to learn unfamiliar technologies, test assumptions systematically and raise technical issues promptly.
Preferred Qualifications
- Exposure to a cloud platform such as AWS, Microsoft Azure or Google Cloud.
- Familiarity with common telemetry sources and formats, including Syslog, Windows Event Logs, JSON, API-based telemetry and cloud audit logs.
- Exposure to SIEM, log-management, endpoint-monitoring, network-detection, SOAR or threat-intelligence concepts and tools.
- Experience with Docker, virtual machines, APIs, Git or basic system administration.
- Awareness of tools such as Wazuh, Security Onion, OpenSearch, Suricata, Zeek, osquery, Velociraptor, TheHive, MISP or comparable platforms.
- Academic, personal, lab or project experience implementing or integrating an open-source security tool.
Prior production SOC experience is not required.
Success Measures
- Quality, consistency and evidence base of tool evaluations and recommendations.
- Security, reproducibility and reliability of proof-of-concept implementations.
- Accuracy and completeness of data-source integrations and detection validation.
- Identification and clear communication of technical, licensing, scalability and operational risks.
- Quality of test evidence, technical documentation and implementation handover materials.
- Compliance with confidentiality, data-handling, access-control and change-management requirements.
About Accops
Required Skills
Job Details
Posted by
N/A
Posted on:
17 Sept 2026
About Accops
More open roles
- Lead, Tech (Python Infra)D. E. Shaw India · Hyderabad, Telangana, India
- Lead, Tech (Python Infra)D. E. Shaw India · Hyderabad, Telangana, India
- Python Automation Engineer – TelecomTechnoShrine InfoSolutions · Bengaluru, Karnataka, India
- Python Backend Developer (remote)Hire Feed · India
- Python Backend Developer|57 Years| Gurugram | Hyderabad | Noida| ImmediateInnova ESI · India
- Python Backend Developer- AI/ML Backend Developer (API, Agentic AI & RAG) (4-7CGI Group · India