Skip to main content

Cybersecurity internship programme

Junior Cloud Security Engineer

Understand AWS cloud architectures, identify misconfigurations, and implement security controls on the AWS platform.

Review the programme structure, practical work, tools, eligibility, outcomes, and responsible-use expectations before applying.

Internship Highlights

Duration

8 Weeks

Mode

Remote & Flexible

Workload

20 Hours/Week

Projects

30 Tasks

Certificate

Guided Track Only

What is the Junior Cloud Security Engineer Internship?

The Junior Cloud Security Engineer Internship is a structured, practical programme. Understand AWS cloud architectures, identify misconfigurations, and implement security controls on the AWS platform. The tasks cover Advanced Identity & Access Management (IAM), Resilient Secure Cloud Storage Solutions and Comprehensive Cloud Logging & Monitoring using AWS IAM Access Analyzer, Amazon GuardDuty, AWS Security Hub and Prowler. Participants complete work such as Capstone project and develop experience relevant to roles including Cloud Security Engineer / Analyst, Cloud Security Architect and DevSecOps Engineer (Cloud Focus).

Programme at a glance

Delivery
Remote & Flexible
Duration
8 Weeks
Suitable for
Enrolled in or recent graduate of a Cybersecurity, Computer Science, or IT-related degree program.
Practical outcome
Capstone project

What You'll Learn

Advanced Identity & Access Management (IAM)

Configure granular IAM controls, apply the principle of least privilege, and review federated identity patterns within AWS.

Resilient Secure Cloud Storage Solutions

Configure storage controls in Amazon S3 and related AWS storage services, with attention to encryption, access management, and data protection.

Comprehensive Cloud Logging & Monitoring

Configure logging, monitoring, and alerting with CloudTrail, GuardDuty, and AWS Security Hub to build a comprehensive detection capability.

Enterprise Encryption & Key Management

Apply encryption and key-management controls with AWS KMS and Secrets Manager for data at rest and in transit.

Proactive Cloud Threat Detection & Response

Learn to identify, analyze, and respond effectively to cloud-specific threats, misconfigurations, and Indicators of Compromise (IOCs).

Secure Infrastructure as Code (IaC)

Review Terraform and CloudFormation deployments, then incorporate security scanning and policy-as-code controls.

Cloud Compliance & Governance Automation

Understand and implement major cloud compliance frameworks (e.g., CIS, NIST, ISO 27001) and automate governance using native cloud tools.

Cloud Security Posture & Architecture Review

Assess AWS security architecture patterns and examine how foundational controls contribute to a coherent cloud security posture.

Internship Structure

  1. 1

    Week 1: Cloud Security Foundations & AWS Architecture

    Deep dive into cloud computing models, the AWS shared responsibility model, and foundational AWS security services. Introduction to secure AWS architecture design.

  2. 2

    Week 2: Mastering AWS IAM

    Intensive hands-on labs on AWS Identity and Access Management, covering policies, roles, service accounts, and federated identities within AWS.

  3. 3

    Week 3: Securing Cloud Storage & Advanced Data Protection

    Learn to configure and secure Amazon S3 and AWS storage controls. Implement advanced data protection strategies including encryption at rest and in transit and data loss prevention (DLP).

  4. 4

    Week 4: Cloud Network Security & Zero Trust Principles

    Master VPC/VNet design, security groups, NACLs, cloud firewalls, and implement Zero Trust network access (ZTNA) principles in cloud environments.

  5. 5

    Week 5: Advanced Logging, Monitoring & Threat Intelligence

    Implement comprehensive security logging with CloudTrail and AWS Config. Configure GuardDuty and AWS Security Hub and integrate threat intelligence feeds.

  6. 6

    Week 6: Infrastructure as Code (IaC) Security & DevSecOps

    Secure cloud infrastructure deployments using Terraform and CloudFormation. Integrate security scanning (e.g., Checkov, TFSec) into CI/CD pipelines.

  7. 7

    Week 7: Cloud Compliance Frameworks & Automated Governance

    Understand CIS Benchmarks, NIST CSF, ISO 27001 in cloud contexts. Automate compliance checks using AWS Config and AWS Security Hub.

  8. 8

    Week 8: Capstone: AWS Security Audit & Hardening

    Audit the assigned AWS environment, document vulnerabilities, apply scoped hardening measures, and present a security posture report.

Capstone project

Audit a controlled AWS account for a fictional company migrating a service to the cloud

  • Review identity, storage, networking, logging, encryption, and infrastructure-as-code configuration
  • Validate findings with read-only or low-impact checks and avoid changing resources outside the assigned accounts
  • Design least-privilege and segmented target-state diagrams with a prioritised hardening backlog
  • Deliver a cloud security assessment, evidence register, architecture diagram, and remediation roadmap
  • Remove account identifiers, keys, and tenant details from retained evidence; related progression includes DevSecOps or Privacy and Compliance

Eligibility & Prerequisites

Eligibility

  • Enrolled in or recent graduate of a Cybersecurity, Computer Science, or IT-related degree program.
  • Solid understanding of networking fundamentals (TCP/IP, DNS, HTTP/S) and operating systems.
  • Demonstrable passion for cloud computing and a strong desire to specialize in cloud security.
  • Excellent analytical, problem-solving, and critical thinking skills.
  • Ability to learn complex technologies rapidly and adapt to new cloud services.
  • Commitment to an intensive 8-week program requiring active participation and hands-on lab work.

Prerequisites

  • Completion of foundational courses in cybersecurity and cloud computing (e.g., AWS CCP, AZ-900 equivalent knowledge).
  • Basic experience with command-line interfaces (Linux Bash, PowerShell, Cloud Shells).
  • Awareness of fundamental security principles (CIA triad, defense-in-depth, least privilege).
  • Familiarity with virtualization concepts and API interactions.
  • Basic scripting knowledge (Python, Bash, or PowerShell) is highly advantageous for automation tasks.
  • Eagerness to explore and master AWS security services, IAM controls, and cloud-native security tooling.

Why choose this internship?

Secures identity, data, network boundaries, logging, and configuration across shared-responsibility cloud services

Differs from DevSecOps by reviewing deployed cloud controls and architecture rather than primarily the delivery pipeline

Reflects junior cloud-security work in posture review, evidence validation, access analysis, and hardening support

Creates portfolio-safe architecture diagrams, risk registers, assessment extracts, and remediation roadmaps

Use only assigned controlled accounts; related progression includes DevSecOps or Privacy and Compliance

Internship Benefits

Remote Internship

Work from anywhere in the world with flexible hours that fit your schedule

Our fully remote program eliminates geographical barriers, allowing you to participate from anywhere with an internet connection. Set your own hours and balance the internship with your other commitments.

Hands-on Tasks

Real-world cybersecurity challenges and practical assignments

Work through controlled cloud scenarios involving identity, storage, network controls, logging, and configuration review. Each task requires evidence and a clear explanation of the recommended remediation.

Letter of Experience

Completion documentation for eligible participants

Documentation is considered after the Guided Track requirements have been successfully completed and the participant record has been verified.

Professional Profile Guidance

Present your completed work accurately on professional profiles

Learn how to describe your role, responsibilities, and sanitised portfolio evidence without exposing private information or overstating programme outcomes.

Letter of Recommendation

Performance-based recommendation eligibility

A recommendation may be considered only where current programme criteria are met. It is not automatic or guaranteed and remains subject to mentor review.

Internship Certificate

A completion credential for successful participants

Guided Track participants who satisfy the published completion requirements may receive a verifiable Certificate of Completion.

Expert Mentorship

Guidance from experienced cybersecurity professionals

Receive structured mentorship, feedback, and advice from seasoned experts who will guide you through your learning journey and career decisions.

Career Preparation

Develop clearer applications and interview evidence

Use sanitised reports, diagrams, scripts, and capstone evidence to explain your work. Participation does not guarantee employment, placement, or referral.

Enterprise Tool Mastery

Hands-on with tools like Wazuh, ELK, Zeek, Suricata, Frida, Burp Suite, and more

Use the listed cloud-native and infrastructure-as-code tools to inspect configuration, validate findings, and document remediation within assigned lab accounts.

Report-Based Evaluation

Professional feedback on your security reports and documentation

Get evaluated on your ability to document findings clearly and professionally. We help you refine your reporting skills — critical in any cybersecurity role.

Resume-Ready Capstone

Complete a final project that showcases your technical ability

The capstone brings the assessment evidence, architecture diagram, risk register, and remediation roadmap into one sanitised portfolio project.

Practice with Realistic Scenarios

Engage with realistic simulations based on industry incidents

Review cloud misconfiguration and incident scenarios in controlled accounts, then record the evidence, impact, and recommended response.

Forge Your Cyber Future

Cloud Security Engineer / Analyst

Design, implement, and manage robust security controls for enterprise cloud infrastructure and applications, with a focus on AWS.

Cloud Security Architect

Lead the design and development of secure, resilient, and compliant cloud architectures for complex enterprise environments.

DevSecOps Engineer (Cloud Focus)

Integrate and automate security best practices throughout the cloud-native software development lifecycle (SDLC) and CI/CD pipelines.

Cloud Compliance & Governance Specialist

Ensure cloud environments adhere to industry regulations (e.g., PCI DSS, HIPAA, GDPR) and internal governance policies.

Cloud Security Consultant / Advisor

Provide expert advisory services to organizations, guiding them in developing and implementing effective cloud security strategies and roadmaps.

Cloud Security Operations Manager

Oversee and optimise security operations across cloud and hybrid infrastructure environments, leading threat detection and response efforts.

Ready to Architect the Future of Secure Cloud?

Review the joining requirements and compare the available programme pathways before continuing through the official application route for the Cloud Security programme.

Frequently Asked Questions

Track-specific and programme-wide answers for prospective interns.

No prior cloud certification is required. The programme introduces the relevant AWS foundations before moving into configuration reviews; existing AWS CCP or equivalent experience may still be useful.

Programme provider

About EncryptEdge Labs

EncryptEdge Labs is a cybersecurity-focused organisation that provides practical training and mentorship through remote internship programmes. Participants work through structured challenges, capstone projects, and the tools specified for their chosen track. EncryptEdge Labs also provides professional cybersecurity services to organisations seeking to strengthen their digital defences.

Success Stories

Elizabeth Akoth

Elizabeth Akoth

Network Security Engineer Intern

March 2025 Cohort

I chose EncryptEdge Lab for its strong focus on practical security and innovation. Conducting a social engineering test and realizing how easily people could be tricked was eye‑opening. I gained real-world exposure to security monitoring, incident response, vulnerability assessment, and honed my skills with tools like Wireshark, Nmap, and SIEM platforms.