CloudSEK is looking for an intern to join a team that sits at the intersection of threat intelligence, security consulting, and product strategy. You'll get hands-on exposure to our core platform, XVigil (external threat intelligence, dark web monitoring, EASM), BeVigil, SVigil, GTI, and AIVigil (AI attack surface monitoring), and to how findings from that platform turn into client-facing deliverables and product decisions.
What You'll Do
Perform VAPT across web, API, mobile, and cloud; triage findings surfaced by BeVigil/SVigil and turn them into concrete, prioritized issues
Feed VAPT and triage experience back into product: flag gaps, false positives, and missed detection classes based on hands-on testing and industry-wide understanding of the product line
Track the threat landscape across the Americas; closely monitor underground/dark web feeds and proactively flag relevant chatter, leaks, or actor activity
Run HUMINT/OSINT collection, infrastructure hunting, and C2 mapping, and map resulting intel to specific prospects, customers, or lead-gen angles
Build or use automation (scripts, workflows) to cut down redundant manual steps in research, triage, and reporting
Research exposed credentials, misconfigurations, leaked assets, and attack surface findings across client and prospect footprints - Validate and assess the impact of findings (e.g. determine if a leaked token or exposed API is a real risk vs. a placeholder/example value)
Help build client-facing deliverables: trial summaries, responsible disclosure reports, CISO-ready security impact summaries
Communicate findings directly on calls with prospects, clearly and confidently, translating technical detail into business impact
Assist with competitive and market research on the threat intel and cybersecurity vendor landscape
Contribute to product strategy discussions around new detection use cases and roadmap prioritization
What We're Looking For
Strong interest in cybersecurity, threat intelligence, or security research
Working knowledge of VAPT methodology across at least two of: web, API, mobile, cloud
Familiarity with core concepts: CVEs, IOCs, TTPs, exposed credentials, attack surface management, OSINT, HUMINT
Comfortable reading technical documentation (APIs, specs, security reports) and writing clearly about what it means
Strong written and verbal communication; comfortable presenting findings on live prospect/client calls
Currently pursuing or recently completed a degree in Computer Science, Information Security, or related field
Nice to Have
Prior CTF, bug bounty, or independent security research experience
Experience with dark web/underground forum monitoring, C2 infrastructure mapping, or threat actor tracking
Exposure to digital risk protection or supply chain risk concepts
Interest in how security products get positioned and sold, not just built
What You'll Gain
Direct mentorship from CloudSEK's security consulting and research team
Real client and prospect exposure, not simulated exercises
End-to-end view of how a research finding becomes a report, a sales conversation, or a product feature