Skip to main content

Cybersecurity internship programme

Junior Security Automation Engineer

Automate routine security tasks with scripting, SOAR tools, and workflows that enhance detection and response efficiency.

Review the programme structure, practical work, tools, eligibility, outcomes, and responsible-use expectations before applying.

Internship Highlights

Duration

8 Weeks

Mode

Remote & Flexible

Workload

20 Hours/Week

Projects

30 Tasks

Certificate

Guided Track Only

What is the Junior Security Automation Engineer Internship?

The Junior Security Automation Engineer Internship is a structured, practical programme. Automate routine security tasks with scripting, SOAR tools, and workflows that enhance detection and response efficiency. The tasks cover Master Automation Scripting, SOAR Platform Proficiency and Automated Playbook Design using Python, Shuffle, Cortex XSOAR Demo and REST APIs. Participants complete work such as Capstone project and develop experience relevant to roles including Security Automation Engineer, SOAR Analyst / Developer and Security Engineer (Automation Focus).

Programme at a glance

Delivery
Remote & Flexible
Duration
8 Weeks
Suitable for
Basic understanding of cybersecurity concepts (networking, common threats, vulnerabilities).
Practical outcome
Capstone project

What You'll Learn

Master Automation Scripting

Develop Python, Bash, or PowerShell scripts to streamline detection, response, and repetitive SOC tasks.

SOAR Platform Proficiency

Build familiarity with Security Orchestration, Automation, and Response (SOAR) platforms such as Cortex XSOAR and Splunk SOAR.

Automated Playbook Design

Design and test security playbooks for threat triage, alert enrichment, and scoped remediation recommendations.

API & Systems Integration

Connect security tools and controlled data sources through REST APIs, webhooks, and Syslog, then validate how information moves between them.

MITRE ATT&CK Automation

Map controlled detection and response workflows to the MITRE ATT&CK framework, with human review retained for consequential actions.

Alert Enrichment & Auto-Triage

Automate contextual enrichment of alerts using threat intelligence feeds, geolocation, and sandboxing data to reduce analyst fatigue.

Security Toolchain Automation

Automate approved interactions between SIEM, EDR, firewall, and ticketing systems while validating outputs before response decisions are made.

Incident Response Workflow Automation

Build scripts and SOAR playbooks for ticketing, escalation, reporting, and scoped containment recommendations, with approval gates for consequential actions.

Internship Structure

  1. 1

    Week 1: Introduction to Security Automation & SOAR Platforms

    Understanding core concepts, benefits, and the role of automation in modern SOCs. Overview of leading SOAR tools.

  2. 2

    Week 2: Python for Security Automation

    Fundamentals of Python scripting, relevant libraries (requests, json, re), and best practices for security tasks.

  3. 3

    Week 3: API Integration & Data Handling

    Working with REST APIs, parsing JSON/XML, data normalization, and regular expressions for log analysis.

  4. 4

    Week 4: Deep Dive into Cortex XSOAR / Splunk SOAR

    Exploring platform architecture, incident types, indicators, playbook components, and basic automation.

  5. 5

    Week 5: Playbook Development Fundamentals

    Designing logical flows, using conditions, loops, and tasks to build initial alert triage and enrichment playbooks.

  6. 6

    Week 6: Advanced Playbook Logic & MITRE ATT&CK Integration

    Implementing complex decision trees, error handling, and mapping playbook actions to MITRE ATT&CK tactics and techniques.

  7. 7

    Week 7: Capstone Project: Automated Alert Triage & Response Workflow

    Building an end-to-end automation for a specific use case, integrating multiple tools and data sources.

  8. 8

    Week 8: Capstone Presentation, Optimization, and Career Prep

    Presenting the capstone project, refining playbooks, and preparing for interviews in security automation roles.

Capstone project

Build a controlled alert-triage workflow for a fictional SOC using supplied alerts and enrichment APIs

  • Normalise incoming data, enrich indicators, score confidence, and route cases without exposing secrets
  • Add approval gates for containment recommendations and handle timeouts, malformed data, and provider failures
  • Write unit-style test cases, logging, rollback guidance, and measurable success criteria
  • Deliver version-controlled scripts, a playbook diagram, test evidence, runbook, and optimisation brief
  • Use mock APIs and sample indicators only; never automate destructive action or submit sensitive data to public services

Eligibility & Prerequisites

Eligibility

  • Basic understanding of cybersecurity concepts (networking, common threats, vulnerabilities).
  • Familiarity with at least one scripting language (Python highly preferred, Bash, PowerShell accepted).
  • Strong analytical thinking and problem-solving abilities.
  • A proactive and enthusiastic approach to learning new technologies and automation techniques.
  • Currently enrolled in or a recent graduate of a relevant degree program (e.g., Computer Science, Cybersecurity, Information Technology) or possess equivalent practical experience.
  • Interest in optimizing SOC workflows through scripting and automation.
  • Good written communication skills for documenting automation playbooks and logic flows.
  • Motivation to contribute to detection engineering, response tuning, and toolchain integration.

Prerequisites

  • Completed introductory coursework or self-study in computer networking and operating systems (Linux/Windows).
  • Demonstrable interest in cybersecurity automation, evidenced by personal projects, relevant coursework, or participation in CTFs/security communities.
  • Ability to work effectively both independently and as part of a collaborative remote team.
  • Access to a stable internet connection and a personal computer capable of running virtualization software or connecting to cloud lab environments.
  • Familiarity with REST APIs, JSON, and how services communicate in modern security environments.
  • Basic knowledge of SIEM platforms, EDR tools, or log collection pipelines (e.g., Splunk, Wazuh, Sysmon).
  • Comfort using the command line for file manipulation, scripting, or environment configuration.
  • Willingness to learn SOAR platforms, automation logic builders, and script orchestration systems.

Why choose this internship?

Turns repetitive analyst decisions into testable, observable workflows while preserving human control for consequential actions

Differs from DevSecOps by automating security operations and case handling rather than software build and release gates

Reflects junior automation work in scripting, API integration, data normalisation, error handling, and documentation

Produces portfolio-safe scripts, workflow diagrams, tests, and a sanitised runbook

Related progression includes SOC Analyst, DevSecOps, or Cybersecurity Analyst

Internship Benefits

Remote Internship

Work from anywhere in the world with flexible hours that fit your schedule

Our fully remote program eliminates geographical barriers, allowing you to participate from anywhere with an internet connection. Set your own hours and balance the internship with your other commitments.

Hands-on Tasks

Real-world cybersecurity challenges and practical assignments

Use supplied alerts and mock APIs to automate enrichment, routing, and reporting. Each workflow is tested against malformed input and provider failures before its output is reviewed.

Letter of Experience

Completion documentation for eligible participants

Documentation is considered after the Guided Track requirements have been successfully completed and the participant record has been verified.

Professional Profile Guidance

Present your completed work accurately on professional profiles

Learn how to describe your role, responsibilities, and sanitised portfolio evidence without exposing private information or overstating programme outcomes.

Letter of Recommendation

Performance-based recommendation eligibility

A recommendation may be considered only where current programme criteria are met. It is not automatic or guaranteed and remains subject to mentor review.

Internship Certificate

A completion credential for successful participants

Guided Track participants who satisfy the published completion requirements may receive a verifiable Certificate of Completion.

Expert Mentorship

Guidance from experienced cybersecurity professionals

Receive structured mentorship, feedback, and advice from seasoned experts who will guide you through your learning journey and career decisions.

Career Preparation

Develop clearer applications and interview evidence

Use sanitised reports, diagrams, scripts, and capstone evidence to explain your work. Participation does not guarantee employment, placement, or referral.

Enterprise Tool Mastery

Hands-on with tools like Wazuh, ELK, Zeek, Suricata, Frida, Burp Suite, and more

Use the listed scripting, SOAR, API, version-control, and security-data tools to build and test bounded automation workflows.

Report-Based Evaluation

Professional feedback on your security reports and documentation

Get evaluated on your ability to document findings clearly and professionally. We help you refine your reporting skills — critical in any cybersecurity role.

Resume-Ready Capstone

Complete a final project that showcases your technical ability

The capstone produces sanitised scripts, a playbook diagram, test evidence, and a runbook that can be retained as portfolio material.

Practice with Realistic Scenarios

Engage with realistic simulations based on industry incidents

Work through alert-triage and enrichment scenarios using controlled test data, then verify the workflow output before documenting its limitations.

Forge Your Cyber Future

Security Automation Engineer

Design, implement, and maintain sophisticated automation solutions to enhance security operations and incident response capabilities.

SOAR Analyst / Developer

Specialize in the development, management, and optimization of security playbooks and workflows on SOAR platforms.

Security Engineer (Automation Focus)

Integrate and manage automation tools and processes within the broader security infrastructure to improve efficiency and effectiveness.

DevSecOps Engineer

Embed security automation practices and tools throughout the software development lifecycle (SDLC) to build more secure applications.

SOC Automation Specialist

Automate SOC processes such as alert triage, enrichment, escalation, and response using scripting and playbooks.

Threat Detection Engineer

Use scripting and automation to improve detection logic, reduce false positives, and deploy automated responses based on threat behavior.

Automate Your Cybersecurity Career Path

Review the joining requirements and programme pathways before continuing through the official application route for the Security Automation internship.

Frequently Asked Questions

Track-specific and programme-wide answers for prospective interns.

Yes. The programme introduces automation through SIEM, SOAR, and Python-based workflows. A basic understanding of cybersecurity or scripting is useful, but the published prerequisites do not require prior automation experience.

Programme provider

About EncryptEdge Labs

EncryptEdge Labs is a cybersecurity-focused organisation that provides practical training and mentorship through remote internship programmes. Participants work through structured challenges, capstone projects, and the tools specified for their chosen track. EncryptEdge Labs also provides professional cybersecurity services to organisations seeking to strengthen their digital defences.

Success Stories

Elizabeth Akoth

Elizabeth Akoth

Network Security Engineer Intern

March 2025 Cohort

I chose EncryptEdge Lab for its strong focus on practical security and innovation. Conducting a social engineering test and realizing how easily people could be tricked was eye‑opening. I gained real-world exposure to security monitoring, incident response, vulnerability assessment, and honed my skills with tools like Wireshark, Nmap, and SIEM platforms.