Security Operations Intern
1 нед. назад
VietnamWorldwideTraineeOnsite
security operationssecurity awareness trainingsoftware deliveryai-assisted development
Internship focusing on running and developing an in-house security awareness training platform within the gaming and blockchain company .
Обязанности
- We are replacing our commercial third-party security awareness training vendor with an in-house platform. This internship sits at the intersection of security operations and software delivery . You will own the security awareness training program end-to-end: designing the training content and quiz bank, building and deploying the platform that delivers it (the architecture and specifications are already fully documented, and you'll work with AI-assisted development tooling under senior guidance), and then running it as an operational security program — enrollments, completion tracking, and audit-ready reporting.
- You'll leave with something few interns get: hands-on experience running a real security awareness program for a whole company, plus the platform you shipped to production to run it on.
Будет плюсом
- Security research/hand-on or Blue CTF experience.
- Prior exposure to an awareness training or phishing-simulation platform (e.g., KnowBe4, GoPhish) as an admin or content author.
- Experience with SOC/security operations tooling, or contributing to audit evidence collection.
- Exposure to Solidity, Hardhat, ethers.js, or any EVM chain (Ronin is a plus).
- Experience creating instructional content (slides, videos, quizzes) or running internal campaigns.
Другое
- is building the future of gaming. We’re the creators of Axie Infinity, the most successful Web3 game ever, and Ronin, a purpose-built blockchain that ranked as the 4th most-used chain in 2024, behind Ethereum, Bitcoin, and Solana.
- We’ve processed over $4.3 billion in on-chain volume and are backed by more than $170 million from top-tier investors, including a16z, Accel, Libertus Capital, and Paradigm.
- Our team moves fast, builds with intention, and believes in a world where players truly own what they earn. If you’re excited by open economies, massive scale, and shaping new digital frontiers, join us.
- Design and author the security awareness training curriculum: modules and quiz banks covering phishing and social engineering, password and MFA hygiene, data handling and classification, secure remote work, and Web3-specific threats (wallet security, seed phrase protection, approval scams, fake dApps).
- Map each training module to the compliance requirements it satisfies (SOC 2 CC1/CC2, ISO 27001 A.6.3 awareness controls) so auditors can trace evidence to controls.
- Operate the training program day-to-day: enroll employees, configure module deadlines and renewal cycles, monitor completion rates, and chase stragglers with the People team.
- Produce audit-ready reporting: completion evidence exports, on-chain verification links for auditors, and periodic metrics for the security team (completion %, average scores, weakest topics).
- Use quiz analytics to find knowledge gaps and iterate on content — treat awareness as a measurable security control, not a checkbox.
- Document program runbooks (onboarding a new hire, adding a module, annual renewal campaign, audit evidence collection) so the program survives beyond the internship.
- Implement the platform from the existing specification under senior review: Solidity contracts (completion tracker + soulbound certificate NFT), Express/TypeScript/PostgreSQL backend with server-side quiz scoring and signed attestations, and the React frontend (module player, quiz flow, dashboards, admin analytics, public certificate verification).
- Test and harden it: contract tests (100% must pass), backend integration tests, and the project's mandatory security-audit and business-logic checks before every PR — zero Critical/High findings before deploy.
- Deploy, then support.
- Final-year student or recent graduate in Information Security, Computer Science, or a related field (or equivalent practical experience).
- Solid security fundamentals: common attack vectors (phishing, social engineering, credential theft, malware delivery), basic OWASP Top 10 awareness, and why the human layer is a primary attack surface.
- Genuine interest in security awareness and security operations: you can explain what makes training effective versus checkbox compliance, and you care about measuring behavior change, not just completions.
- Familiarity with a compliance or control framework (SOC 2, ISO 27001, NIST CSF)
- Working programming ability in TypeScript/JavaScript (Node.js, REST APIs, basic SQL, basic React) — enough to implement from a detailed specification with senior review and AI-assisted tooling. This is a build-and-operate role, not a research role.
- Strong written communication: you will author training content and audit documentation that non-technical employees and external auditors will read.
- Interest in Web3 security — wallet threats, on-chain verification — with motivation to learn Solidity basics quickly (prior experience not required).
- Understanding of Git workflows (branching, pull requests, code review).