Skip to main content

Cybersecurity internship programme

Junior API Security Analyst

Learn to identify, test, and secure APIs using modern tools and techniques. Gain hands-on experience and industry-ready skills.

Review the programme structure, practical work, tools, eligibility, outcomes, and responsible-use expectations before applying.

Internship Highlights

Duration

8 Weeks

Mode

Remote & Flexible

Workload

20 Hours/Week

Projects

30 Tasks

Certificate

Guided Track Only

What is the Junior API Security Analyst Internship?

The Junior API Security Analyst Internship is a structured, practical programme. Learn to identify, test, and secure APIs using modern tools and techniques. Gain hands-on experience and industry-ready skills. The tasks cover API Fundamentals & OWASP Top 10, API Enumeration & Recon and Broken Auth & Access Control using Postman, Burp Suite, OWASP ZAP and Kiterunner. Participants complete work such as Capstone project and develop experience relevant to roles including API Security Tester, Web Application Pentester and Bug Bounty Hunter.

Programme at a glance

Delivery
Remote & Flexible
Duration
8 Weeks
Suitable for
Strong interest in web and API security
Practical outcome
Capstone project

What You'll Learn

API Fundamentals & OWASP Top 10

Understand API architectures and the most critical API security risks

API Enumeration & Recon

Discover hidden endpoints, parameter fuzzing, and undocumented APIs

Broken Auth & Access Control

Test for broken authentication, IDORs, and role-based access flaws

Input Validation & Injection Attacks

Identify and exploit injection flaws like SQLi and command injection in APIs

Testing REST & GraphQL APIs

Work with Postman, Burp Suite, and CLI tools to test RESTful and GraphQL APIs

Rate Limiting & DoS Protections

Analyze rate-limiting mechanisms and protections against abuse

API Security Testing Tools

Use tools like Burp Suite Pro, OWASP ZAP, Postman, and Kiterunner

Reporting & Mitigation Recommendations

Create professional vulnerability reports and provide remediation guidance

Internship Structure

  1. 1

    Week 1: API Security Introduction

    Overview of API architectures, protocols, and OWASP API Top 10

  2. 2

    Week 2: Enumeration & Recon

    Identifying endpoints, gathering metadata, using Postman and CLI tools

  3. 3

    Week 3: Authentication & Authorization Testing

    Testing for broken auth, IDORs, and role-based access flaws

  4. 4

    Week 4: Injection & Data Exposure

    Exploiting SQLi, NoSQLi, mass assignment, and data leaks

  5. 5

    Week 5: GraphQL & WebSocket Security

    Common GraphQL flaws, introspection, and WebSocket risks

  6. 6

    Week 6: Rate Limiting & Logic Flaws

    Testing rate limits, replay attacks, and business logic abuse

  7. 7

    Week 7: Reporting & Remediation

    Writing clear reports with CVSS scores and mitigation steps

  8. 8

    Week 8: Capstone Project

    Full end-to-end test of a vulnerable API environment and reporting

Capstone project

Review the supplied rules of engagement for a fictional partner API and record the authorised endpoints

  • Build an endpoint inventory and test authentication, object-level authorisation, input handling, and data exposure
  • Validate rate-limit and business-logic findings without accessing unrelated records or disrupting the lab
  • Map confirmed issues to OWASP API Security risks and create a severity-ranked remediation matrix
  • Submit reproducible request and response evidence, an executive summary, and a technical API assessment report
  • Retain only sanitised report extracts and diagrams; never publish tokens, credentials, raw datasets, or a vulnerable endpoint

Eligibility & Prerequisites

Eligibility

  • Strong interest in web and API security
  • Basic understanding of HTTP, JSON, and REST/GraphQL concepts
  • Willingness to learn through structured labs and independent research
  • Currently pursuing or completed a degree in Cybersecurity, Computer Science, or related field
  • Committed to completing the 8-week program
  • Strong attention to detail and analytical thinking
  • Comfort using API testing tools like Postman or Burp Suite
  • Reliable internet access and a computer with minimum 8GB RAM

Prerequisites

  • Understanding of HTTP request/response lifecycle
  • Experience using or testing web APIs (Postman, Curl, Insomnia, etc.)
  • Basic Linux command-line navigation
  • Familiarity with OWASP Top 10 or similar frameworks
  • Interest in API exploitation and bug bounty methodologies
  • Prior exposure to Burp Suite or OWASP ZAP (even beginner level)
  • Basic scripting knowledge in Python or JavaScript is helpful
  • Completed one beginner course in application security or web hacking

Why choose this internship?

Focuses on the service interfaces, identity controls, and business rules that connect modern applications

Differs from Application Security by concentrating on API contracts, object access, token handling, and abuse paths

Reflects junior work such as endpoint enumeration, authorisation checks, evidence capture, and remediation verification

Produces a sanitised endpoint map, test matrix, and report suitable for a controlled portfolio summary

All testing stays inside supplied APIs; related progression includes Application Security or DevSecOps

Internship Benefits

Remote Internship

Work from anywhere in the world with flexible hours that fit your schedule

Our fully remote program eliminates geographical barriers, allowing you to participate from anywhere with an internet connection. Set your own hours and balance the internship with your other commitments.

Hands-on Tasks

Real-world cybersecurity challenges and practical assignments

Tackle practical scenarios that reflect real-world cybersecurity threats. You'll use industry-standard tools and methodologies to solve problems professionals face every day.

Letter of Experience

Completion documentation for eligible participants

Documentation is considered after the Guided Track requirements have been successfully completed and the participant record has been verified.

Professional Profile Guidance

Present your completed work accurately on professional profiles

Learn how to describe your role, responsibilities, and sanitised portfolio evidence without exposing private information or overstating programme outcomes.

Letter of Recommendation

Performance-based recommendation eligibility

A recommendation may be considered only where current programme criteria are met. It is not automatic or guaranteed and remains subject to mentor review.

Internship Certificate

A completion credential for successful participants

Guided Track participants who satisfy the published completion requirements may receive a verifiable Certificate of Completion.

Expert Mentorship

Guidance from experienced cybersecurity professionals

Receive structured mentorship, feedback, and advice from seasoned experts who will guide you through your learning journey and career decisions.

Career Preparation

Develop clearer applications and interview evidence

Use sanitised reports, diagrams, scripts, and capstone evidence to explain your work. Participation does not guarantee employment, placement, or referral.

Enterprise Tool Mastery

Hands-on with tools like Wazuh, ELK, Zeek, Suricata, Frida, Burp Suite, and more

Gain practical experience in configuring and using powerful cybersecurity tools used in enterprise SOCs, red team labs, and cloud environments.

Report-Based Evaluation

Professional feedback on your security reports and documentation

Get evaluated on your ability to document findings clearly and professionally. We help you refine your reporting skills — critical in any cybersecurity role.

Resume-Ready Capstone

Complete a final project that showcases your technical ability

Create a substantial capstone project that demonstrates your applied skills. This is a great portfolio piece to show employers or attach to your job applications.

Practice with Realistic Scenarios

Engage with realistic simulations based on industry incidents

Work through case studies and attack scenarios inspired by real-world incidents. Whether you're investigating a breach or simulating an exploit, you'll gain authentic experience.

Forge Your Cyber Future

API Security Tester

Identify and exploit vulnerabilities in REST and GraphQL APIs.

Web Application Pentester

Focus on full-stack assessments with emphasis on API-level attack surfaces.

Bug Bounty Hunter

Study how authorised programmes on HackerOne and Bugcrowd handle API reports; perform all testing only in supplied environments.

AppSec Engineer (API Focus)

Secure APIs during SDLC, integrate API testing into CI/CD.

API Gateway & Access Control Analyst

Implement and audit API gateway configurations and OAuth flows.

Threat Hunter (App Layer)

Hunt for abuse and anomalies in web and API traffic logs.

Ready to Review the Application Route?

Review the joining requirements, current availability, and official application route for this cybersecurity internship programme.

Frequently Asked Questions

Track-specific and programme-wide answers for prospective interns.

Yes. The internship starts with API-security fundamentals before progressing to more advanced testing techniques. Basic internet skills and a willingness to learn are sufficient to begin.

Programme provider

About EncryptEdge Labs

EncryptEdge Labs is a cybersecurity-focused organisation that provides practical training and mentorship through remote internship programmes. Participants work through structured challenges, capstone projects, and the tools specified for their chosen track. EncryptEdge Labs also provides professional cybersecurity services to organisations seeking to strengthen their digital defences.

Success Stories

Elizabeth Akoth

Elizabeth Akoth

Network Security Engineer Intern

March 2025 Cohort

I chose EncryptEdge Lab for its strong focus on practical security and innovation. Conducting a social engineering test and realizing how easily people could be tricked was eye‑opening. I gained real-world exposure to security monitoring, incident response, vulnerability assessment, and honed my skills with tools like Wireshark, Nmap, and SIEM platforms.