We are seeking a motivated and detail-oriented Security Intern to join our Blue Team (Cyber Defense). This position offers a unique opportunity to gain hands-on experience in defending our organization's digital assets across Security Monitoring, Cloud Security, Threat Hunting, and AI-driven security automation. The ideal candidate will support our engineers in day-to-day defensive operations while developing practical skills in a fast-paced security environment.
What you'll be doing:
- Assist in monitoring and triaging security alerts from our SIEM (e.g., ELK, DataDog), and help tune detection rules to reduce noise and improve alert fidelity
- Support cloud security monitoring and help review/remediate cloud misconfigurations using Cloud Security Posture Management (CSPM) tools
- Shadow CSIRT members during security incident investigations and assist with preliminary analysis and documentation
- Participate in threat hunting exercises to identify suspicious activity that automated tools might miss
- Help operate and maintain defensive technologies such as EDR/XDR, WAF, Email Security, and IDS/IPS
- Contribute to security tooling and automation projects, including writing scripts that interface with cloud-based APIs
- Explore and apply AI/LLM tools to enhance detection accuracy and streamline security workflows
- Help document security procedures, runbooks and reports.
What we're looking for:
- Currently pursuing a bachelor's or master's degree in Cybersecurity, Computer Science, IT, or related field
- Basic understanding of cybersecurity concepts and network fundamentals
- Familiarity with common operating systems (Windows, Linux, MacOS)
- Basic scripting or programming knowledge with willingness to automate repetitive tasks
- Awareness of the MITRE ATT&CK framework
- Strong analytical and problem-solving skills
- Effectively communicate technical issues to diverse audiences, both in writing and verbally (Vietnamese and English)
- Curiosity and eagerness to learn about cyber defense and to use AI tools in daily workflows
Preferred Qualifications:
- Knowledge of SIEM tools and security monitoring concepts
- Familiarity with cloud platforms (AWS, Azure, or GCP) and their native security services
- Exposure to IaC (Infrastructure as Code) solutions or systems automation platforms
- Experience with security tools (EDR, WAF, DNS security, etc.)
- Interest in pursuing cybersecurity certifications (e.g., CompTIA Security+, AWS SAA, CEH)
What’s in it for you:
- Hands-on experience across multiple cybersecurity domains
- Mentorship from experienced security professionals
- Exposure to enterprise-grade security tools and technologies
- Opportunity to participate in real security operations and projects
- Potential pathway to full-time employment based on performance
- Flexible schedule to accommodate academic commitments
Duration 3-6 months, with possibility of extension based on performance and mutual agreement.
Find out more about Coinhako here https://www.coinhako.com/ and don't forget to visit our Careers Page https://www.coinhako.com/join-us
By submitting your application to us, you consent to the collection, use, disclosure and processing of your personal data in accordance with our privacy policy, which is accessible at https://www.coinhako.com/legal/sg-1/privacy_policy.