Hardening work on live estates that cannot be taken offline.
What you will do Assist on threat modelling, identity and entitlement reviews, secrets rotation and pipeline attestation under senior guidance. Every control you close is one you helped verify, not just described. What we expect Studying Security, CS or equivalent, or captured-the-flag / bug-bounty experience. Basic IAM, OWASP familiarity and the ability to explain a risk in one paragraph and in one diff. No audit-only work — if you raise a finding, you help fix it.