Cybersecurity Operations Intern
Job description
Cybersecurity Operations Team – created as part of the EY Cybersecurity practice in Poland, provides services in the field of security monitoring, threat detection and response, and vulnerability management, with particular focus on the SOC and Vulnerability Management space across on-premises, public and private cloud, and hybrid environments. The team is also responsible for the ongoing operation and optimization of security monitoring and vulnerability management processes for clients across various industries.
The team works on complex, international projects, helping organizations detect, investigate, and respond to threats while continuously identifying and reducing their exposure by embedding security operations capabilities into their environments and engineering workflows. Due to the dynamic growth of these services, we are looking for ambitious individuals to join the team as a CyberSecurity Operations Intern.
Opportunities that await you:
As a CyberSecurity Operations Intern, you will actively support internal security initiatives and client projects focused on monitoring, detecting, and responding to threats, as well as identifying and managing vulnerabilities across modern IT environments. You will gain hands-on experience with security operations tooling and learn how threats are detected, investigated, and remediated across SOC and Vulnerability Management functions.
You will work closely with SOC analysts, threat hunters, detection engineers, and vulnerability management specialists, learning how to translate security signals and intelligence into practical, automated, and scalable detection and response capabilities.
Your main tasks:
As a member of the Cybersecurity Operations team, you will take part in many different, interesting projects, mainly related to the design/implementation/operation of security monitoring, threat detection and response capabilities, with a focus on Vulnerability Management and SOC functions (Incident Handling, Threat Hunting, Threat Intelligence, Detection Engineering), including:
· Supporting the Vulnerability Management lifecycle (asset discovery, vulnerability scanning, prioritization, remediation tracking and reporting)
· Operating and maintaining vulnerability scanning tools and integrating them with asset inventory and CMDB data
· Building Vulnerability Management dashboards, metrics and reporting for technical teams and management
· Assisting in security incident handling and response, including triage, investigation, containment and post-incident activities
· Monitoring security alerts and events across SIEM, EDR and other security tooling as an L1/L2 analyst, performing initial triage, validation and prioritization
· Investigating and escalating confirmed incidents according to defined playbooks and SLAs, documenting findings and supporting containment and remediation actions
· Helping design, develop and tune detection content (e.g. SIEM/EDR rules, correlation logic, use cases) as part of Detection Engineering
· Working on end-to-end SOC use case development with field experts
· Helping integrate and automate security tooling via APIs and scripting (e.g. using Python, PowerShell, REST APIs, SOAR playbooks)
Moreover, you will take part in projects focused on the operationalization of CyberSecurity tools such as SIEM / SOAR / EDR and transformation initiatives, which will include tasks such as:
- SOC - daily monitoring, incident detection and response, reporting, and participation in continuous improvement of monitoring capabilities
- Engineering - performing regular updates, maintaining automation scripts, system health checks, supporting platform transformations, and maintaining documentation of security systems
- SOAR - developing and supporting automation workflows, optimizing routine processes, and contributing to incident response efficiency
- Vulnerability Management - conducting continuous scanning, tracking remediation progress, coordinating with system owners, and improving vulnerability management processes
- Cloud Security - performing compliance checks, monitoring security issues, implementing best practices, and cooperating closely with the cloud operations team
Skills you will use:
· Basic understanding of cybersecurity concepts, common attack types, and the CIA triad
· General knowledge of SIEM / SOAR / EDR tools
· General knowledge of Vulnerability Management tools and concepts (e.g. Tenable, Qualys, Rapid7) and CVSS-based risk scoring
· Analytical thinking and problem-solving mindset
· Knowledge of Linux (e.g. RedHat) and Windows including logs, processes and OS internals
· Understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, ports and protocols)
· Very good knowledge of English and Polish
Your previous experience:
Student/Graduate of Cybersecurity or related fields (IT profile)
We will also appreciate:
- Familiarity with alert triage, incident handling and escalation workflows (runbooks/playbooks)
- Basic familiarity with security tools such as CrowdStrike Falcon EDR, CrowdStrike NG-SIEM, LogScale, Splunk, Microsoft Sentinel
- Basic familiarity with VM or security tools such as Tenable, Qualys, Wiz, Rapid7, CrowdStrike, or ServiceNow VR
· Experience or interest in Python, PowerShell, Bash and REST APIs
- Possession of industry certificates in the field of IT security, e.g. CompTIA Security+, certification of leading IT/Security solution providers (also in the areas of security of cloud platforms, e.g. Microsoft AZ-900)
- Willingness to develop in the area of IT security
You are a good fit for us if:
You are a proactive, well-organized person who is genuinely passionate about cybersecurity, follows the latest threats, attack techniques, and industry trends, and wants to develop towards Security Operations, threat detection and response, and vulnerability management. You enjoy investigating how attacks work, are curious about technology and automation, and are ready to take on challenges in international, engineering-driven projects.
We offer:
Interesting work in an international consulting company,
- Locations:Warsaw, Poznań, Kraków, Wrocław and Gdańsk
- Flexible working hours to fit your university schedule
- Hybrid or remote work options, depending on project requirements
- Exposure to a wide range of technologies and projects, allowing you to explore different areas of cybersecurity and find your own career path
- Participation in complex, international projects in the field of implementation of cybersecurity solutions and thus enabling the acquisition of various experiences,
- Opportunity to gain hands-on experience with enterprise-level cybersecurity tools and technologies
- Personalized programs of courses and trainings,
- Participation in a professional development program
About EY Poland
We are a global consulting company – we help entrepreneurs, organizations and communities get the most out of their potential. We carry out projects in the field of: Audit, Tax, Transaction and Business Consulting (including IT).
We employ more than 240,000 exceptional people in more than 150 countries around the world. There are over 2800 of us in Poland, and we work in: Warsaw, Gdańsk, Katowice, Kraków, Łódź, Poznań and Wrocław.
We create amazing things together every day. We have people, a development path and training, thanks to which you can also handle the most prestigious projects.
EY is an equal opportunity employer, we appreciate the diversity of knowledge and experience of our employees.
EY provides all candidates with equal opportunities in the recruitment process, regardless of gender, age, race, religion, sexual orientation, national origin, disability or any other legally protected data, in accordance with applicable law.