01 Oct
|
TECEZE
|
Tamil Nadu
Job Description
Cybersecurity Operations & Incident Response Intern
n
About the Role
n
We are looking for a Cybersecurity Operations & Incident Response Intern to join our security team and gain hands-on experience in Security Operations Centre (SOC) activities, threat detection, alert investigation, incident response, and digital forensics.
n
This internship is designed for candidates who want to build practical cybersecurity skills by working with security telemetry, investigating alerts, analysing suspicious activity, developing detections, and supporting incident response activities.
n
The role provides exposure to industry-standard cybersecurity tools and methodologies, including SIEM platforms, MITRE ATT&CK;, Sigma, threat intelligence, endpoint telemetry, network monitoring, cloud security, and forensic investigation.
n
Key Responsibilities
n
n
- Monitor and analyse security alerts from SIEM and security monitoring platforms.
n
- Perform initial alert triage and determine whether activity is benign, suspicious, or malicious.
n
- Investigate security events using endpoint, network, identity, and cloud telemetry.
n
- Search and correlate security data using platforms such as Splunk, Elastic, and Microsoft Sentinel.
n
- Document investigation findings, evidence, severity, impact, and recommended actions.
n
- Assist with incident response activities, including identification, containment, eradication, and recovery.
n
- Map observed attacker behaviour to the MITRE ATT&CK; framework.
n
- Assist in creating, testing, and tuning security detection rules using Sigma and other detection technologies.
n
- Participate in threat-hunting exercises based on defined hypotheses and available security telemetry.
n
- Support digital forensic investigations involving Windows systems, disk evidence, memory evidence, and relevant system artefacts.
n
- Assist with analysing cloud and identity security events, including Microsoft Entra ID and AWS CloudTrail logs.
n
- Contribute to incident timelines, investigation reports, shift handover notes, and executive-level summaries.
n
- Participate in purple-team and simulated incident exercises.
n
- Help identify opportunities to improve detection coverage, reduce false positives, and strengthen security monitoring.
n
- Maintain accurate documentation of investigations and follow established security procedures.
n
n
Tools & Technologies
n
During the internship, you may work with technologies including:
n
n
- SIEM: Splunk, Elastic Stack/Kibana, Microsoft Sentinel
n
- Endpoint & Network: Sysmon, Windows Event Logs, Zeek, Suricata, Wireshark
n
- Detection: Sigma, MITRE ATT&CK;, ATT&CK; Navigator
n
- Forensics: Velociraptor, Volatility 3, KAPE, Plaso, Timesketch
n
- Threat Intelligence: MISP, STIX/TAXII
n
- Incident Management: TheHive, Cortex
n
- Automation: Shuffle / SOAR technologies
n
- Cloud & Identity: AWS CloudTrail, Microsoft Entra ID
n
- Security Testing: Atomic Red Team
n
n
These technologies are aligned with the practical cybersecurity operations curriculum provided for the role.
n
What You Will Learn
n
By the end of the internship, the intern should be able to:
n
n
- Understand how a SOC operates and how security events progress from event → alert → investigation → incident → resolution.
n
- Analyse and correlate security logs from multiple sources.
n
- Conduct structured alert investigations using evidence rather than assumptions.
n
- Write transparent and defensible investigation notes.
n
- Apply MITRE ATT&CK; to real-world attack activity.
n
- Develop and tune basic detection rules.
n
- Understand the NIST incident response lifecycle.
n
- Support incident containment and investigation activities.
n
- Perform introductory host, disk, and me
n
📌 Cybersecurity Operations & Incident Response Intern (Tamil Nadu)
🏢 TECEZE
📍 Tamil Nadu