Internship focusing on evaluating a Security-as-Code tool for Microsoft 365 environments. Collaborate on technical aspects and improve security assessment methodologies.
Responsibilities
The project focuses on evaluating a Security-as-Code tool designed for assessing Microsoft 365 environments and Entra ID.
The primary objective is to understand the deployment process, including its configuration and integration within existing systems.
The project involves: conducting a comprehensive analysis of the tool's functionalities; identifying its strengths and potential areas for improvement; performing a gap analysis by comparing the tool with another security assessment script, and determining areas where it excels and where enhancements might be necessary.
Additionally, the project explores the implementation of custom controls within the Security-as-Code framework.
This involves delving into the technical aspects of the tool to understand how custom policies and controls can be developed and integrated into the existing framework.
Collaboration with team members is essential to design and test these custom controls, ensuring they meet the teams specific security needs.
Through this project, participants will gain experience in security assessment methodologies, Microsoft 365 and Entra ID features and architecture, and the customization of security solutions, contributing to the enhancement of the organization's security posture through automation.
Requirements
Pursuing or recently completed a degree in Information Technology, Cybersecurity, Computer Science, or a related field.
Familiarity with Microsoft 365 and Software-as-a-Service concepts.
Understanding of security assessment methodologies and tools.
Basic knowledge of scripting languages (e.g., PowerShell, Python) for understanding code.
Ability to conduct comprehensive analysis and gap assessments of tools.
Strong problem-solving skills to identify strengths and areas for improvement in security solutions.
Effective communication skills to collaborate with team members and articulate findings and recommendations.
Ability to work in a team-oriented environment.
Keen interest in cybersecurity and security automation.
Nice to have: Coding skills in PowerShell to improve and add custom controls.
Knowledge of Entra ID in particular.
Experience with administration of SaaS tools, provisioning of access, and IT/Security operations.
Experience or knowledge about CI/CD best practices.
Job title
Cloud Security Intern – MS 365 Security-as-Code Analysis
Personal Security Advisor responsible for securing the CEO and other Senior Officers at PG&E. Conducting threat assessments, providing protection, and coordinating travel security.
IAM Info Security Controls Specialist at Bank of America analyzing and securing identity access systems. Collaborating with teams to enhance compliance and governance across IAM practices.
Director of Information Security overseeing LATAM operations for BCD Travel. Leading cybersecurity strategy, risk management and collaboration with regional leadership teams.
Trainee in Offensive Security with a focus on hands - on training and real projects. Develop skills in vulnerability detection, cybersecurity, and offensive tools within a specialized team.
Physical Security Shift Supervisor ensuring safety and administering security measures at Broadridge's Edgewood location. Overseeing a team and coordinating security operations during scheduled shifts.
Connected Vehicle Cybersecurity Manager securing automotive products against cyber threats. Lead engineering team to ensure compliance and drive security strategies in connected vehicle ecosystem.
Senior Information Security Engineer supporting advanced cybersecurity operations in AWS environment. Leading security measures and risk assessments to protect organizations from cyber threats.
Senior SAP Security IAM Consultant at Wavestone shaping digital security for clients in Switzerland. Engaging in holistic security architecture and innovative solutions with a strong team spirit.
Senior Principal Security Software Engineer developing common security software for Dell's server and storage products. Implementing encryption, collaborating on design and test strategies across international teams.
Drive simplification and standardisation of operational processes in Manufacturing Security. Focus on defining KPIs, facilitating meetings, and aligning stakeholders for improved efficiency.