Skip to main content

Cybersecurity internship programme

Junior DevSecOps Engineer

Integrate security into CI/CD pipelines, ensuring secure development practices across infrastructure and code deployments.

Review the programme structure, practical work, tools, eligibility, outcomes, and responsible-use expectations before applying.

Internship Highlights

Duration

8 Weeks

Mode

Remote & Flexible

Workload

20 Hours/Week

Projects

30 Tasks

Certificate

Guided Track Only

What is the Junior DevSecOps Engineer Internship?

The Junior DevSecOps Engineer Internship is a structured, practical programme. Integrate security into CI/CD pipelines, ensuring secure development practices across infrastructure and code deployments. The tasks cover Master Shift-Left Security Principles, CI/CD Pipeline Security Automation and Infrastructure as Code (IaC) Security using GitHub Actions, Jenkins, SonarQube and Trivy. Participants complete work such as Capstone project and develop experience relevant to roles including DevSecOps Engineer, CI/CD Security Specialist and Cloud Security DevOps Engineer.

Programme at a glance

Delivery
Remote & Flexible
Duration
8 Weeks
Suitable for
Basic understanding of the Software Development Lifecycle (SDLC), CI/CD concepts, and version control systems like Git.
Practical outcome
Capstone project

What You'll Learn

Master Shift-Left Security Principles

Learn to integrate security controls early in the development lifecycle, implementing SAST, DAST, and dependency scanning in CI/CD pipelines.

CI/CD Pipeline Security Automation

Configure security gates and compliance checks in GitHub Actions, GitLab CI/CD, Jenkins, and CircleCI workflows.

Infrastructure as Code (IaC) Security

Review Terraform and Ansible configurations, including policy-as-code checks and configuration drift detection.

Secrets Management & Compliance

Implement robust secrets management strategies using HashiCorp Vault, AWS Secrets Manager, and automated compliance scanning.

Container & Cloud Security

Secure Docker containers, Kubernetes deployments, and multi-cloud environments with automated vulnerability scanning and policy enforcement.

Security Testing Integration in Dev Workflows

Embed tools like Trivy, Snyk, and Bandit into developer workflows to catch security issues pre-deployment.

Policy-as-Code & Compliance-as-Code

Define and enforce security and compliance policies using tools like OPA, Checkov, and Conftest across cloud-native stacks.

DevSecOps Monitoring & Alerting

Set up real-time security monitoring and alerting in DevOps environments using Prometheus, Grafana, and cloud-native solutions.

Internship Structure

  1. 1

    Week 1: DevSecOps Fundamentals & Shift-Left Security

    Introduction to DevSecOps principles, security integration strategies, and the importance of shifting security left in the development lifecycle.

  2. 2

    Week 2: CI/CD Pipeline Basics & Security Integration

    Understanding CI/CD concepts, setting up basic pipelines in GitHub Actions and GitLab CI/CD, and integrating initial security checks.

  3. 3

    Week 3: Static Application Security Testing (SAST) & Code Analysis

    Implementing SAST tools like SonarQube and CodeQL, understanding code quality metrics, and automating security code reviews.

  4. 4

    Week 4: Dynamic Testing & Dependency Scanning

    Deploying DAST tools like OWASP ZAP, implementing Software Composition Analysis (SCA) with Snyk and Trivy, and SBOM generation.

  5. 5

    Week 5: Infrastructure as Code (IaC) Security

    Securing Terraform and Ansible configurations, implementing policy-as-code with Open Policy Agent (OPA), and IaC scanning automation.

  6. 6

    Week 6: Secrets Management & Container Security

    Implementing HashiCorp Vault, securing Docker containers, Kubernetes security best practices, and automated secrets scanning.

  7. 7

    Week 7: Capstone Project: End-to-End Secure CI/CD Pipeline

    Building a secure CI/CD pipeline that incorporates the programme controls from code commit through a controlled deployment stage.

  8. 8

    Week 8: Advanced Topics, Monitoring & Career Preparation

    Security monitoring, incident response automation, compliance reporting, and preparing for DevSecOps career opportunities.

Capstone project

Secure a controlled delivery pipeline for a fictional containerised application

  • Add source, dependency, container, dynamic, and infrastructure-as-code checks at appropriate pipeline stages
  • Define severity gates, exceptions, and developer feedback without leaking secrets into logs or artefacts
  • Harden the sample container and Terraform configuration, then document before-and-after findings
  • Deliver pipeline configuration, a security-gate diagram, remediation notes, and an operational runbook
  • Retain only sanitised YAML, scripts, and diagrams; use test credentials and isolated repositories only

Eligibility & Prerequisites

Eligibility

  • Basic understanding of the Software Development Lifecycle (SDLC), CI/CD concepts, and version control systems like Git.
  • Familiarity with at least one programming language such as Python, JavaScript, Go, or Bash.
  • Awareness of cloud computing principles and containerization (Docker, Kubernetes).
  • Interest in secure coding practices, infrastructure automation, and pipeline security.
  • Strong problem-solving mindset with attention to detail in automation and integration tasks.
  • Currently enrolled in or recently graduated from a Computer Science, Cybersecurity, IT, or related technical degree program.
  • Willingness to learn modern DevSecOps tools and frameworks such as Terraform, Trivy, and GitHub Actions.
  • Ability to commit to a structured 8-week remote internship with weekly deliverables and practical labs.

Prerequisites

  • Completed coursework or self-study in Linux command line, basic scripting, and system administration.
  • Foundational understanding of networking protocols, HTTP, firewalls, and access control models.
  • Exposure to cloud service providers like AWS, Azure, or GCP (basic console or CLI use is acceptable).
  • Ability to troubleshoot build pipelines, container images, or code deployment processes.
  • Familiarity with security concepts like secrets management, static/dynamic analysis, or vulnerability scanning.
  • Access to a modern computer capable of running virtualization tools (e.g., Docker, Vagrant, or a VM) with a reliable internet connection.
  • Experience with or willingness to learn YAML, JSON, or Terraform configuration files.
  • Self-discipline to follow remote instructions, complete assignments independently, and collaborate virtually using Git and productivity tools.

Why choose this internship?

Shows how security feedback becomes part of repeatable software delivery rather than a final manual checkpoint

Differs from Cloud Security by focusing on build, test, release, secrets, and infrastructure automation workflows

Reflects junior work integrating scanners, reviewing failures, tuning gates, and documenting secure release paths

Produces portfolio evidence through sanitised pipeline code, architecture diagrams, and check results

Related progression includes Application Security, Cloud Security, or Security Automation

Internship Benefits

Remote Internship

Work from anywhere in the world with flexible hours that fit your schedule

Our fully remote program eliminates geographical barriers, allowing you to participate from anywhere with an internet connection. Set your own hours and balance the internship with your other commitments.

Hands-on Tasks

Real-world cybersecurity challenges and practical assignments

Work with isolated repositories and sample applications to integrate scanning, review failed checks, and document secure release decisions.

Letter of Experience

Completion documentation for eligible participants

Documentation is considered after the Guided Track requirements have been successfully completed and the participant record has been verified.

Professional Profile Guidance

Present your completed work accurately on professional profiles

Learn how to describe your role, responsibilities, and sanitised portfolio evidence without exposing private information or overstating programme outcomes.

Letter of Recommendation

Performance-based recommendation eligibility

A recommendation may be considered only where current programme criteria are met. It is not automatic or guaranteed and remains subject to mentor review.

Internship Certificate

A completion credential for successful participants

Guided Track participants who satisfy the published completion requirements may receive a verifiable Certificate of Completion.

Expert Mentorship

Guidance from experienced cybersecurity professionals

Receive structured mentorship, feedback, and advice from seasoned experts who will guide you through your learning journey and career decisions.

Career Preparation

Develop clearer applications and interview evidence

Use sanitised reports, diagrams, scripts, and capstone evidence to explain your work. Participation does not guarantee employment, placement, or referral.

Enterprise Tool Mastery

Hands-on with tools like Wazuh, ELK, Zeek, Suricata, Frida, Burp Suite, and more

Configure the listed pipeline, container, infrastructure-as-code, and secrets-management tools within isolated programme environments.

Report-Based Evaluation

Professional feedback on your security reports and documentation

Get evaluated on your ability to document findings clearly and professionally. We help you refine your reporting skills — critical in any cybersecurity role.

Resume-Ready Capstone

Complete a final project that showcases your technical ability

The capstone combines sanitised pipeline configuration, security-gate evidence, remediation notes, and an operational runbook for portfolio use.

Practice with Realistic Scenarios

Engage with realistic simulations based on industry incidents

Work through delivery-pipeline failures involving vulnerable dependencies, container findings, exposed test secrets, and infrastructure configuration.

Forge Your Cyber Future

DevSecOps Engineer

Design and implement secure CI/CD pipelines, automate security testing, and ensure compliance across development workflows.

CI/CD Security Specialist

Focus specifically on securing continuous integration and deployment processes, implementing security gates and automated testing.

Cloud Security DevOps Engineer

Specialize in securing cloud infrastructure deployments, implementing Infrastructure as Code security, and cloud compliance automation.

Security Automation Engineer

Develop automated security solutions, integrate security tools into development workflows, and build security-focused automation platforms.

Infrastructure as Code (IaC) Security Analyst

Audit, analyze, and enforce secure configurations in IaC tools like Terraform, CloudFormation, and Ansible.

Compliance-as-Code Specialist

Automate compliance validation across cloud-native infrastructure using policy-as-code frameworks like OPA and Conftest.

Secure Your Development Pipeline Career

Review the joining requirements and programme pathways before continuing through the official application route for the DevSecOps internship.

Frequently Asked Questions

Track-specific and programme-wide answers for prospective interns.

Yes. The programme starts with foundational DevSecOps principles, then introduces automation, CI/CD controls, and the listed cloud-security tools. It is suitable for developers, IT students, and early-career professionals who meet the published requirements.

Programme provider

About EncryptEdge Labs

EncryptEdge Labs is a cybersecurity-focused organisation that provides practical training and mentorship through remote internship programmes. Participants work through structured challenges, capstone projects, and the tools specified for their chosen track. EncryptEdge Labs also provides professional cybersecurity services to organisations seeking to strengthen their digital defences.

Success Stories

Elizabeth Akoth

Elizabeth Akoth

Network Security Engineer Intern

March 2025 Cohort

I chose EncryptEdge Lab for its strong focus on practical security and innovation. Conducting a social engineering test and realizing how easily people could be tricked was eye‑opening. I gained real-world exposure to security monitoring, incident response, vulnerability assessment, and honed my skills with tools like Wireshark, Nmap, and SIEM platforms.