Cybersecurity Operations Intern
EY
- Location
- Warszawa, PL, 00-124
- Employment
- Internship
- Work model
- On-Site
- Level
- Intern
Skills
About this role
Cybersecurity Operations Team – created as part of the EY Cybersecurity practice in Poland, provides services in the field of security monitoring, threat detection and response, and vulnerability management, with particular focus on the SOC and Vulnerability Management space across on-premises, public and private cloud, and hybrid environments. The team is also responsible for the ongoing operation and optimization of security monitoring and vulnerability management processes for clients across various industries. The team works on complex, international projects, helping organizations detect, investigate, and respond to threats while continuously identifying and reducing their exposure by embedding security operations capabilities into their environments and engineering workflows. Due to the dynamic growth of these services, we are looking for ambitious individuals to join the team as a CyberSecurity Operations Intern. Opportunities that await you: As a CyberSecurity Operations Intern, you will actively support internal security initiatives and client projects focused on monitoring, detecting, and responding to threats, as well as identifying and managing vulnerabilities across modern IT environments. You will gain hands-on experience with security operations tooling and learn how threats are detected, investigated, and remediated across SOC and Vulnerability Management functions. You will work closely with SOC analysts, threat hunters, detection engineers, and vulnerability management specialists, learning how to translate security signals and intelligence into practical, automated, and scalable detection and response capabilities. Your main tasks: As a member of the Cybersecurity Operations team, you will take part in many different, interesting projects, mainly related to the design/implementation/operation of security monitoring, threat detection and response capabilities, with a focus on Vulnerability Management and SOC functions (Incident Handling, Threat Hunting, Threat Intelligence, Detection Engineering), including: · Supporting the Vulnerability Management lifecycle (asset discovery, vulnerability scanning, prioritization, remediation tracking and reporting) · Operating and maintaining vulnerability scanning tools and integrating them with asset inventory and CMDB data · Building Vulnerability Management dashboards, metrics and reporting for technical teams and management · Assisting in security incident handling and response, including triage, investigation, containment and post-incident activities · Monitoring security alerts and events across SIEM, EDR and other security tooling as an L1/L2 analyst, performing initial triage, validation and prioritization · Investigating and escalating confirmed incidents according to defined playbooks and SLAs, documenting findings and supporting containment and remediation actions · Helping design, develop and tune detection content (e.g. SIEM/EDR rules, correlation logic, use cases) as part of Detection Engineering · Working on end-to-end SOC use case development with field experts · Helping integrate and automate security tooling via APIs and scripting (e.g. using Python, PowerShell, REST APIs, SOAR playbooks) Moreover, you will take part in projects focused on the operationalization of CyberSecurity tools such as SIEM / SOAR / EDR and transformation initiatives, which will include tasks such as:
SOC - daily monitoring, incident detection and response, reporting, and participation in continuous improvement of monitoring capabilities Engineering - performing regular updates, maintaining automation scripts, system health checks, supporting platform transformations, and maintaining documentation of security systems SOAR - developing and supporting automation workflows, optimizing routine