Cybersecurity internship programme
Junior API Security Analyst
Learn to identify, test, and secure APIs using modern tools and techniques. Gain hands-on experience and industry-ready skills.
Review the programme structure, practical work, tools, eligibility, outcomes, and responsible-use expectations before applying.
Internship Highlights
Duration
8 Weeks
Mode
Remote & Flexible
Workload
20 Hours/Week
Projects
30 Tasks
Certificate
Guided Track Only
What is the Junior API Security Analyst Internship?
The Junior API Security Analyst Internship is a structured, practical programme. Learn to identify, test, and secure APIs using modern tools and techniques. Gain hands-on experience and industry-ready skills. The tasks cover API Fundamentals & OWASP Top 10, API Enumeration & Recon and Broken Auth & Access Control using Postman, Burp Suite, OWASP ZAP and Kiterunner. Participants complete work such as Capstone project and develop experience relevant to roles including API Security Tester, Web Application Pentester and Bug Bounty Hunter.
Programme at a glance
- Delivery
- Remote & Flexible
- Duration
- 8 Weeks
- Suitable for
- Strong interest in web and API security
- Practical outcome
- Capstone project
What You'll Learn
API Fundamentals & OWASP Top 10
Understand API architectures and the most critical API security risks
API Enumeration & Recon
Discover hidden endpoints, parameter fuzzing, and undocumented APIs
Broken Auth & Access Control
Test for broken authentication, IDORs, and role-based access flaws
Input Validation & Injection Attacks
Identify and exploit injection flaws like SQLi and command injection in APIs
Testing REST & GraphQL APIs
Work with Postman, Burp Suite, and CLI tools to test RESTful and GraphQL APIs
Rate Limiting & DoS Protections
Analyze rate-limiting mechanisms and protections against abuse
API Security Testing Tools
Use tools like Burp Suite Pro, OWASP ZAP, Postman, and Kiterunner
Reporting & Mitigation Recommendations
Create professional vulnerability reports and provide remediation guidance
Internship Structure
- 1
Week 1: API Security Introduction
Overview of API architectures, protocols, and OWASP API Top 10
- 2
Week 2: Enumeration & Recon
Identifying endpoints, gathering metadata, using Postman and CLI tools
- 3
Week 3: Authentication & Authorization Testing
Testing for broken auth, IDORs, and role-based access flaws
- 4
Week 4: Injection & Data Exposure
Exploiting SQLi, NoSQLi, mass assignment, and data leaks
- 5
Week 5: GraphQL & WebSocket Security
Common GraphQL flaws, introspection, and WebSocket risks
- 6
Week 6: Rate Limiting & Logic Flaws
Testing rate limits, replay attacks, and business logic abuse
- 7
Week 7: Reporting & Remediation
Writing clear reports with CVSS scores and mitigation steps
- 8
Week 8: Capstone Project
Full end-to-end test of a vulnerable API environment and reporting
Capstone project
Review the supplied rules of engagement for a fictional partner API and record the authorised endpoints
- Build an endpoint inventory and test authentication, object-level authorisation, input handling, and data exposure
- Validate rate-limit and business-logic findings without accessing unrelated records or disrupting the lab
- Map confirmed issues to OWASP API Security risks and create a severity-ranked remediation matrix
- Submit reproducible request and response evidence, an executive summary, and a technical API assessment report
- Retain only sanitised report extracts and diagrams; never publish tokens, credentials, raw datasets, or a vulnerable endpoint
Eligibility & Prerequisites
Eligibility
- Strong interest in web and API security
- Basic understanding of HTTP, JSON, and REST/GraphQL concepts
- Willingness to learn through structured labs and independent research
- Currently pursuing or completed a degree in Cybersecurity, Computer Science, or related field
- Committed to completing the 8-week program
- Strong attention to detail and analytical thinking
- Comfort using API testing tools like Postman or Burp Suite
- Reliable internet access and a computer with minimum 8GB RAM
Prerequisites
- Understanding of HTTP request/response lifecycle
- Experience using or testing web APIs (Postman, Curl, Insomnia, etc.)
- Basic Linux command-line navigation
- Familiarity with OWASP Top 10 or similar frameworks
- Interest in API exploitation and bug bounty methodologies
- Prior exposure to Burp Suite or OWASP ZAP (even beginner level)
- Basic scripting knowledge in Python or JavaScript is helpful
- Completed one beginner course in application security or web hacking
Why choose this internship?
Focuses on the service interfaces, identity controls, and business rules that connect modern applications
Differs from Application Security by concentrating on API contracts, object access, token handling, and abuse paths
Reflects junior work such as endpoint enumeration, authorisation checks, evidence capture, and remediation verification
Produces a sanitised endpoint map, test matrix, and report suitable for a controlled portfolio summary
All testing stays inside supplied APIs; related progression includes Application Security or DevSecOps
Internship Benefits
Remote Internship
Work from anywhere in the world with flexible hours that fit your schedule
Our fully remote program eliminates geographical barriers, allowing you to participate from anywhere with an internet connection. Set your own hours and balance the internship with your other commitments.
Hands-on Tasks
Real-world cybersecurity challenges and practical assignments
Tackle practical scenarios that reflect real-world cybersecurity threats. You'll use industry-standard tools and methodologies to solve problems professionals face every day.
Letter of Experience
Completion documentation for eligible participants
Documentation is considered after the Guided Track requirements have been successfully completed and the participant record has been verified.
Professional Profile Guidance
Present your completed work accurately on professional profiles
Learn how to describe your role, responsibilities, and sanitised portfolio evidence without exposing private information or overstating programme outcomes.
Letter of Recommendation
Performance-based recommendation eligibility
A recommendation may be considered only where current programme criteria are met. It is not automatic or guaranteed and remains subject to mentor review.
Internship Certificate
A completion credential for successful participants
Guided Track participants who satisfy the published completion requirements may receive a verifiable Certificate of Completion.
Expert Mentorship
Guidance from experienced cybersecurity professionals
Receive structured mentorship, feedback, and advice from seasoned experts who will guide you through your learning journey and career decisions.
Career Preparation
Develop clearer applications and interview evidence
Use sanitised reports, diagrams, scripts, and capstone evidence to explain your work. Participation does not guarantee employment, placement, or referral.
Enterprise Tool Mastery
Hands-on with tools like Wazuh, ELK, Zeek, Suricata, Frida, Burp Suite, and more
Gain practical experience in configuring and using powerful cybersecurity tools used in enterprise SOCs, red team labs, and cloud environments.
Report-Based Evaluation
Professional feedback on your security reports and documentation
Get evaluated on your ability to document findings clearly and professionally. We help you refine your reporting skills — critical in any cybersecurity role.
Resume-Ready Capstone
Complete a final project that showcases your technical ability
Create a substantial capstone project that demonstrates your applied skills. This is a great portfolio piece to show employers or attach to your job applications.
Practice with Realistic Scenarios
Engage with realistic simulations based on industry incidents
Work through case studies and attack scenarios inspired by real-world incidents. Whether you're investigating a breach or simulating an exploit, you'll gain authentic experience.
Forge Your Cyber Future
API Security Tester
Identify and exploit vulnerabilities in REST and GraphQL APIs.
Web Application Pentester
Focus on full-stack assessments with emphasis on API-level attack surfaces.
Bug Bounty Hunter
Study how authorised programmes on HackerOne and Bugcrowd handle API reports; perform all testing only in supplied environments.
AppSec Engineer (API Focus)
Secure APIs during SDLC, integrate API testing into CI/CD.
API Gateway & Access Control Analyst
Implement and audit API gateway configurations and OAuth flows.
Threat Hunter (App Layer)
Hunt for abuse and anomalies in web and API traffic logs.
Ready to Review the Application Route?
Review the joining requirements, current availability, and official application route for this cybersecurity internship programme.
Frequently Asked Questions
Track-specific and programme-wide answers for prospective interns.
Programme provider
About EncryptEdge Labs
EncryptEdge Labs is a cybersecurity-focused organisation that provides practical training and mentorship through remote internship programmes. Participants work through structured challenges, capstone projects, and the tools specified for their chosen track. EncryptEdge Labs also provides professional cybersecurity services to organisations seeking to strengthen their digital defences.
Success Stories

Elizabeth Akoth
Network Security Engineer Intern
“I chose EncryptEdge Lab for its strong focus on practical security and innovation. Conducting a social engineering test and realizing how easily people could be tricked was eye‑opening. I gained real-world exposure to security monitoring, incident response, vulnerability assessment, and honed my skills with tools like Wireshark, Nmap, and SIEM platforms.”

