We are seeking a motivated and detail-oriented Security Intern to join our Blue Team (Cyber Defense). This position offers a unique opportunity to gain hands-on experience in defending our organization's digital assets across Security Monitoring, Cloud Security, Threat Hunting, and AI-driven security automation.
The ideal candidate will support our engineers in
day-to-day
defensive operations while developing practical skills in a fast-paced security environment.
What you'll be doing
- Assist in monitoring and triaging security alerts from our SIEM (e.g., ELK, DataDog), and help tune detection rules to reduce noise and improve alert fidelity
- Support cloud security monitoring and help review/remediate cloud misconfigurations using Cloud Security Posture Management (CSPM) tools
- Shadow CSIRT members during security incident investigations and assist with preliminary analysis and documentation
- Participate in threat hunting exercises to identify suspicious activity that automated tools might miss
- Help operate and maintain defensive technologies such as EDR/XDR, WAF, Email Security, and IDS/IPS
- Contribute to security tooling and automation projects, including writing scripts that interface with cloud-based APIs
- Explore and apply AI/LLM tools to enhance detection accuracy and streamline security workflows
- Help document security procedures, runbooks and reports.
What we're looking for
- Currently pursuing a bachelor's or master's degree in Cybersecurity, Computer Science, IT, or related field
- Basic understanding of cybersecurity concepts and network fundamentals
- Familiarity with common operating systems (Windows, Linux, MacOS)
- Basic scripting or programming knowledge with willingness to automate repetitive tasks
- Awareness of the MITRE ATT&CK framework
- Strong analytical and problem-solving skills
- Effectively communicate technical issues to diverse audiences, both in writing and verbally (Vietnamese and English)
- Curiosity and eagerness to learn about cyber defense and to use AI tools in daily workflows
- Understanding and/or experience working in a Cryptocurrency/Blockchain/Fintech/Finance Trading domain
preferred
.
Preferred Qualifications
- Knowledge of SIEM tools and security monitoring concepts
- Familiarity with cloud platforms (AWS, Azure, or GCP) and their native security services
- Exposure to IaC (Infrastructure as Code) solutions or systems automation platforms
- Experience with security tools (EDR, WAF, DNS security, etc.)
- Interest in pursuing cybersecurity certifications (e.g., CompTIA Security+, AWS SAA, CEH)
- Interest in AI Security topics.
What’s in it for you: