Skip to main content

Cybersecurity internship programme

Junior Threat Intelligence Analyst

Develop skills in OSINT, APT profiling, and intelligence reporting to proactively understand and counter emerging cyber threats.

Review the programme structure, practical work, tools, eligibility, outcomes, and responsible-use expectations before applying.

Internship Highlights

Duration

8 Weeks

Mode

Remote & Flexible

Workload

20 Hours/Week

Projects

30 Tasks

Certificate

Guided Track Only

What is the Junior Threat Intelligence Analyst Internship?

The Junior Threat Intelligence Analyst Internship is a structured, practical programme. Develop skills in OSINT, APT profiling, and intelligence reporting to proactively understand and counter emerging cyber threats. The tasks cover CTI Lifecycle (Collection to Dissemination), Threat Actor Profiling and MITRE ATT&CK & APT Group Mapping using VirusTotal, MISP, Shodan and ThreatFox. Participants complete work such as Capstone project and develop experience relevant to roles including Threat Intelligence Analyst, OSINT Specialist and APT Research Analyst.

Programme at a glance

Delivery
Remote & Flexible
Duration
8 Weeks
Suitable for
Currently enrolled in or graduated from Cybersecurity, International Relations, Intelligence Studies, or a related field.
Practical outcome
Capstone project

What You'll Learn

CTI Lifecycle (Collection to Dissemination)

Apply the threat-intelligence lifecycle from defined collection requirements through analysis and dissemination

Threat Actor Profiling

Assess reported threat-actor activity, TTPs, and possible motivations while recording source reliability and confidence

MITRE ATT&CK & APT Group Mapping

Map reported techniques to MITRE ATT&CK and analyse supplied campaign evidence without treating attribution as certain

IOC Hunting & Threat Feed Analysis

Develop skills in hunting for indicators of compromise and analyzing threat intelligence feeds

OSINT Tools (Recon-ng, Spiderfoot)

Collect and evaluate information from approved public sources using the listed OSINT tools

PDF & Document Metadata Analysis

Analyze document metadata and extract intelligence from various file formats

Geopolitical Threat Landscape Analysis

Understand geopolitical factors influencing cyber threats and nation-state activities

Threat Intelligence Report Writing

Develop clear and concise intelligence reports for stakeholders and decision-makers

Internship Structure

  1. 1

    Week 1: Introduction to Cyber Threat Intelligence

    CTI fundamentals, intelligence cycle, and threat landscape overview

  2. 2

    Week 2: OSINT Fundamentals & Tool Mastery

    Hands-on training with Maltego, Spiderfoot, and advanced OSINT techniques

  3. 3

    Week 3: Threat Actor Profiling & Attribution

    Assessing reported threat-actor activity and applying cautious attribution methodologies

  4. 4

    Week 4: MITRE ATT&CK Framework & APT Mapping

    Deep dive into ATT&CK framework and mapping APT group techniques

  5. 5

    Week 5: IOC Analysis & Threat Feed Integration

    Working with indicators of compromise and integrating threat intelligence feeds

  6. 6

    Week 6: Advanced OSINT & Digital Forensics

    Advanced OSINT techniques and document metadata analysis

  7. 7

    Week 7: Geopolitical Analysis & Campaign Tracking

    Understanding geopolitical context and tracking long-term threat campaigns

  8. 8

    Week 8: Capstone: Nation-State APT Threat Report

    Produce a confidence-rated intelligence assessment of a supplied campaign and its reported associations

Capstone project

Produce a threat-intelligence assessment for a fictional organisation concerned about a supplied campaign

  • Define intelligence requirements and collect from approved public sources and provided datasets
  • Validate indicators, assess source reliability, and separate confirmed facts from analytical judgements
  • Profile the actor or cluster, map techniques to MITRE ATT&CK, and evaluate relevance to the fictional organisation
  • Deliver an IOC package, source log, ATT&CK map, confidence-rated intelligence brief, and collection-gap note
  • Use passive, lawful research only; do not access illicit services, contact actors, buy data, or publish personal information

Eligibility & Prerequisites

Eligibility

  • Currently enrolled in or graduated from Cybersecurity, International Relations, Intelligence Studies, or a related field.
  • Strong analytical and research skills with an interest in threat actor behavior and tactics.
  • Curiosity about global cyber conflicts, APT groups, and geopolitical threats.
  • Committed to completing the 8-week internship with high-quality research deliverables.
  • Ability to synthesize large volumes of data into actionable intelligence.
  • Interest in cybersecurity journalism, cybercrime tracking, or national security.
  • Capable of working independently while engaging in team-based intelligence collaboration.
  • Access to a computer with a reliable internet connection and basic OSINT tools.

Prerequisites

  • Basic understanding of cybersecurity principles, threat actors, and attack vectors.
  • Familiarity with open-source intelligence (OSINT) collection techniques.
  • Strong written communication skills for creating professional intelligence reports.
  • Critical thinking and attention to detail when analyzing data or news sources.
  • Understanding of research methodologies (academic or investigative).
  • Basic knowledge of tools like VirusTotal, Shodan, Maltego, or SpiderFoot (preferred but not required).
  • Awareness of the MITRE ATT&CK framework and common adversary tactics (optional).
  • Interest in cybercrime trends, malware campaigns, or global threat intelligence reports.

Why choose this internship?

Teaches how scattered indicators and reporting become decision-focused intelligence with confidence and sourcing

Distinct from SOC Analyst because it prioritises external context, actor behaviour, and intelligence requirements over live alert handling

Reflects junior CTI work in collection, source evaluation, IOC validation, ATT&CK mapping, and concise briefing

Produces portfolio-safe intelligence briefs, source matrices, and anonymised ATT&CK maps

Related progression includes SOC Analyst, Incident Response, or Malware Analysis

Internship Benefits

Remote Internship

Work from anywhere in the world with flexible hours that fit your schedule

Our fully remote program eliminates geographical barriers, allowing you to participate from anywhere with an internet connection. Set your own hours and balance the internship with your other commitments.

Hands-on Tasks

Real-world cybersecurity challenges and practical assignments

Define collection requirements, evaluate approved sources, enrich indicators, and record confidence levels before preparing an intelligence brief.

Letter of Experience

Completion documentation for eligible participants

Documentation is considered after the Guided Track requirements have been successfully completed and the participant record has been verified.

Professional Profile Guidance

Present your completed work accurately on professional profiles

Learn how to describe your role, responsibilities, and sanitised portfolio evidence without exposing private information or overstating programme outcomes.

Letter of Recommendation

Performance-based recommendation eligibility

A recommendation may be considered only where current programme criteria are met. It is not automatic or guaranteed and remains subject to mentor review.

Internship Certificate

A completion credential for successful participants

Guided Track participants who satisfy the published completion requirements may receive a verifiable Certificate of Completion.

Expert Mentorship

Guidance from experienced cybersecurity professionals

Receive structured mentorship, feedback, and advice from seasoned experts who will guide you through your learning journey and career decisions.

Career Preparation

Develop clearer applications and interview evidence

Use sanitised reports, diagrams, scripts, and capstone evidence to explain your work. Participation does not guarantee employment, placement, or referral.

Enterprise Tool Mastery

Hands-on with tools like Wazuh, ELK, Zeek, Suricata, Frida, Burp Suite, and more

Use the listed intelligence, indicator-research, sharing, and link-analysis tools with approved public sources and supplied datasets.

Report-Based Evaluation

Professional feedback on your security reports and documentation

Get evaluated on your ability to document findings clearly and professionally. We help you refine your reporting skills — critical in any cybersecurity role.

Resume-Ready Capstone

Complete a final project that showcases your technical ability

The capstone produces a sanitised IOC package, source log, ATT&CK map, confidence-rated brief, and collection-gap note for portfolio use.

Practice with Realistic Scenarios

Engage with realistic simulations based on industry incidents

Assess supplied campaigns and public reporting while distinguishing verified facts, reported associations, and analytical judgements.

Forge Your Cyber Future

Threat Intelligence Analyst

Analyze cyber threats and produce actionable intelligence for organizational security

OSINT Specialist

Focus on open-source intelligence gathering and analysis for security operations

APT Research Analyst

Assess reporting on advanced persistent threat groups and document confidence, evidence gaps, and observed techniques

Cyber Threat Researcher

Conduct in-depth research on emerging threats and attack methodologies

Geopolitical Cyber Analyst

Analyze the intersection of geopolitics and cyber warfare for strategic intelligence

CTI Program Manager

Lead threat intelligence programs and coordinate intelligence sharing initiatives

Ready to Master Threat Intelligence?

Review the joining requirements and programme pathways before continuing through the official application route for the Threat Intelligence internship.

Frequently Asked Questions

Track-specific and programme-wide answers for prospective interns.

Yes. No prior threat-intelligence experience is required. The programme begins with collection requirements, source evaluation, and confidence before moving into IOC enrichment, ATT&CK mapping, and reporting.

Programme provider

About EncryptEdge Labs

EncryptEdge Labs is a cybersecurity-focused organisation that provides practical training and mentorship through remote internship programmes. Participants work through structured challenges, capstone projects, and the tools specified for their chosen track. EncryptEdge Labs also provides professional cybersecurity services to organisations seeking to strengthen their digital defences.

Success Stories

Elizabeth Akoth

Elizabeth Akoth

Network Security Engineer Intern

March 2025 Cohort

I chose EncryptEdge Lab for its strong focus on practical security and innovation. Conducting a social engineering test and realizing how easily people could be tricked was eye‑opening. I gained real-world exposure to security monitoring, incident response, vulnerability assessment, and honed my skills with tools like Wireshark, Nmap, and SIEM platforms.