LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
Forgot password?
Don't have an account?
or
Join Canary Wharfian
By signing up, you agree to our Terms & Conditions and Privacy Policy.
or

Cybersecurity Operations Intern

Other-InternNo visa sponsorship
Ernst & Young logo

at Ernst & Young

Big Four

Posted 12 days ago

No clicks

**Cybersecurity Operations Intern** Support internal security initiatives and client projects in threat detection, incident response, and vulnerability management. Gain hands-on experience with security operations tooling and learn detection and response capabilities. Key responsibilities include assisting in security incident handling, monitoring security alerts, and escalating confirmed incidents. Required skills include basic understanding of cybersecurity concepts, familiarity with SIEM/SOAR/EDR tools, and excellent English and Polish language skills.

Compensation
Not specified

Currency: Not specified

City
Warsaw
Country
Poland

Full Job Description

Cybersecurity Operations Team created as part of the EY Cybersecurity practice in Poland, provides services in the field of security monitoring, threat detection and response, and vulnerability management, with particular focus on the SOC and Vulnerability Management space across on-premises, public and private cloud, and hybrid environments. The team is also responsible for the ongoing operation and optimization of security monitoring and vulnerability management processes for clients across various industries.

The team works on complex, international projects, helping organizations detect, investigate, and respond to threats while continuously identifying and reducing their exposure by embedding security operations capabilities into their environments and engineering workflows. Due to the dynamic growth of these services, we are looking for ambitious individuals to join the team as a CyberSecurity Operations Intern.

 

Opportunities that await you:

As a CyberSecurity Operations Intern, you will actively support internal security initiatives and client projects focused on monitoring, detecting, and responding to threats, as well as identifying and managing vulnerabilities across modern IT environments. You will gain hands-on experience with security operations tooling and learn how threats are detected, investigated, and remediated across SOC and Vulnerability Management functions.

You will work closely with SOC analysts, threat hunters, detection engineers, and vulnerability management specialists, learning how to translate security signals and intelligence into practical, automated, and scalable detection and response capabilities.

 

Your main tasks:

As a member of the Cybersecurity Operations team, you will take part in many different, interesting projects, mainly related to the design/implementation/operation of security monitoring, threat detection and response capabilities, with a focus on Vulnerability Management and SOC functions (Incident Handling, Threat Hunting, Threat Intelligence, Detection Engineering), including:

 

       Supporting the Vulnerability Management lifecycle (asset discovery, vulnerability scanning, prioritization, remediation tracking and reporting)

       Operating and maintaining vulnerability scanning tools and integrating them with asset inventory and CMDB data

       Building Vulnerability Management dashboards, metrics and reporting for technical teams and management

       Assisting in security incident handling and response, including triage, investigation, containment and post-incident activities

       Monitoring security alerts and events across SIEM, EDR and other security tooling as an L1/L2 analyst, performing initial triage, validation and prioritization

       Investigating and escalating confirmed incidents according to defined playbooks and SLAs, documenting findings and supporting containment and remediation actions

       Helping design, develop and tune detection content (e.g. SIEM/EDR rules, correlation logic, use cases) as part of Detection Engineering

       Working on end-to-end SOC use case development with field experts

       Helping integrate and automate security tooling via APIs and scripting (e.g. using Python, PowerShell, REST APIs, SOAR playbooks)

 

Moreover, you will take part in projects focused on the operationalization of CyberSecurity tools such as SIEM / SOAR / EDR and transformation initiatives, which will include tasks such as:

 

  • SOC - daily monitoring, incident detection and response, reporting, and participation in continuous improvement of monitoring capabilities
  • Engineering - performing regular updates, maintaining automation scripts, system health checks, supporting platform transformations, and maintaining documentation of security systems
  • SOAR - developing and supporting automation workflows, optimizing routine processes, and contributing to incident response efficiency
  • Vulnerability Management - conducting continuous scanning, tracking remediation progress, coordinating with system owners, and improving vulnerability management processes
  • Cloud Security - performing compliance checks, monitoring security issues, implementing best practices, and cooperating closely with the cloud operations team

 

Skills you will use:

       Basic understanding of cybersecurity concepts, common attack types, and the CIA triad

       General knowledge of SIEM / SOAR / EDR tools

       General knowledge of Vulnerability Management tools and concepts (e.g. Tenable, Qualys, Rapid7) and CVSS-based risk scoring

       Analytical thinking and problem-solving mindset

       Knowledge of Linux (e.g. RedHat) and Windows including logs, processes and OS internals

       Understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, ports and protocols)

       Very good knowledge of English and Polish

 

Your previous experience:

 Student/Graduate of Cybersecurity or related fields (IT profile)

 

We will also appreciate:

  • Familiarity with alert triage, incident handling and escalation workflows (runbooks/playbooks)
  • Basic familiarity with  security tools such as CrowdStrike Falcon EDR, CrowdStrike NG-SIEM, LogScale, Splunk, Microsoft Sentinel
  • Basic familiarity with VM or security tools such as Tenable, Qualys, Wiz, Rapid7, CrowdStrike, or ServiceNow VR

       Experience or interest in Python, PowerShell, Bash and REST APIs

  • Possession of industry certificates in the field of IT security, e.g. CompTIA Security+, certification of leading IT/Security solution providers (also in the areas of security of cloud platforms, e.g. Microsoft AZ-900)
  • Willingness to develop in the area of IT security

 

You are a good fit for us if:

You are a proactive, well-organized person who is genuinely passionate about cybersecurity, follows the latest threats, attack techniques, and industry trends, and wants to develop towards Security Operations, threat detection and response, and vulnerability management. You enjoy investigating how attacks work, are curious about technology and automation, and are ready to take on challenges in international, engineering-driven projects.

 

We offer:

Interesting work in an international consulting company,

  • Locations:Warsaw, Pozna, Krakw, Wrocaw and Gdask
  • Flexible working hours to fit your university schedule
  • Hybrid or remote work options, depending on project requirements
  • Exposure to a wide range of technologies and projects, allowing you to explore different areas of cybersecurity and find your own career path
  • Participation in complex, international projects in the field of implementation of cybersecurity solutions and thus enabling the acquisition of various experiences,
  • Opportunity to gain hands-on experience with enterprise-level cybersecurity tools and technologies
  • Personalized programs of courses and trainings,
  • Participation in a professional development program

 

About EY Poland

We are a global consulting company we help entrepreneurs, organizations and communities get the most out of their potential. We carry out projects in the field of: Audit, Tax, Transaction and Business Consulting (including IT).

 

We employ more than 240,000 exceptional people in more than 150 countries around the world. There are over 2800 of us in Poland, and we work in: Warsaw, Gdask, Katowice, Krakw, d, Pozna and Wrocaw.

We create amazing things together every day. We have people, a development path and training, thanks to which you can also handle the most prestigious projects. 

EY is an equal opportunity employer, we appreciate the diversity of knowledge and experience of our employees.

EY provides all candidates with equal opportunities in the recruitment process, regardless of gender, age, race, religion, sexual orientation, national origin, disability or any other legally protected data, in accordance with applicable law.

Cybersecurity Operations Intern

Compensation

Not specified

City: Warsaw

Country: Poland

Ernst & Young logo
Big Four

12 days ago

No clicks

at Ernst & Young

Other-InternNo visa sponsorship

**Cybersecurity Operations Intern** Support internal security initiatives and client projects in threat detection, incident response, and vulnerability management. Gain hands-on experience with security operations tooling and learn detection and response capabilities. Key responsibilities include assisting in security incident handling, monitoring security alerts, and escalating confirmed incidents. Required skills include basic understanding of cybersecurity concepts, familiarity with SIEM/SOAR/EDR tools, and excellent English and Polish language skills.

Full Job Description

Cybersecurity Operations Team created as part of the EY Cybersecurity practice in Poland, provides services in the field of security monitoring, threat detection and response, and vulnerability management, with particular focus on the SOC and Vulnerability Management space across on-premises, public and private cloud, and hybrid environments. The team is also responsible for the ongoing operation and optimization of security monitoring and vulnerability management processes for clients across various industries.

The team works on complex, international projects, helping organizations detect, investigate, and respond to threats while continuously identifying and reducing their exposure by embedding security operations capabilities into their environments and engineering workflows. Due to the dynamic growth of these services, we are looking for ambitious individuals to join the team as a CyberSecurity Operations Intern.

 

Opportunities that await you:

As a CyberSecurity Operations Intern, you will actively support internal security initiatives and client projects focused on monitoring, detecting, and responding to threats, as well as identifying and managing vulnerabilities across modern IT environments. You will gain hands-on experience with security operations tooling and learn how threats are detected, investigated, and remediated across SOC and Vulnerability Management functions.

You will work closely with SOC analysts, threat hunters, detection engineers, and vulnerability management specialists, learning how to translate security signals and intelligence into practical, automated, and scalable detection and response capabilities.

 

Your main tasks:

As a member of the Cybersecurity Operations team, you will take part in many different, interesting projects, mainly related to the design/implementation/operation of security monitoring, threat detection and response capabilities, with a focus on Vulnerability Management and SOC functions (Incident Handling, Threat Hunting, Threat Intelligence, Detection Engineering), including:

 

       Supporting the Vulnerability Management lifecycle (asset discovery, vulnerability scanning, prioritization, remediation tracking and reporting)

       Operating and maintaining vulnerability scanning tools and integrating them with asset inventory and CMDB data

       Building Vulnerability Management dashboards, metrics and reporting for technical teams and management

       Assisting in security incident handling and response, including triage, investigation, containment and post-incident activities

       Monitoring security alerts and events across SIEM, EDR and other security tooling as an L1/L2 analyst, performing initial triage, validation and prioritization

       Investigating and escalating confirmed incidents according to defined playbooks and SLAs, documenting findings and supporting containment and remediation actions

       Helping design, develop and tune detection content (e.g. SIEM/EDR rules, correlation logic, use cases) as part of Detection Engineering

       Working on end-to-end SOC use case development with field experts

       Helping integrate and automate security tooling via APIs and scripting (e.g. using Python, PowerShell, REST APIs, SOAR playbooks)

 

Moreover, you will take part in projects focused on the operationalization of CyberSecurity tools such as SIEM / SOAR / EDR and transformation initiatives, which will include tasks such as:

 

  • SOC - daily monitoring, incident detection and response, reporting, and participation in continuous improvement of monitoring capabilities
  • Engineering - performing regular updates, maintaining automation scripts, system health checks, supporting platform transformations, and maintaining documentation of security systems
  • SOAR - developing and supporting automation workflows, optimizing routine processes, and contributing to incident response efficiency
  • Vulnerability Management - conducting continuous scanning, tracking remediation progress, coordinating with system owners, and improving vulnerability management processes
  • Cloud Security - performing compliance checks, monitoring security issues, implementing best practices, and cooperating closely with the cloud operations team

 

Skills you will use:

       Basic understanding of cybersecurity concepts, common attack types, and the CIA triad

       General knowledge of SIEM / SOAR / EDR tools

       General knowledge of Vulnerability Management tools and concepts (e.g. Tenable, Qualys, Rapid7) and CVSS-based risk scoring

       Analytical thinking and problem-solving mindset

       Knowledge of Linux (e.g. RedHat) and Windows including logs, processes and OS internals

       Understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, ports and protocols)

       Very good knowledge of English and Polish

 

Your previous experience:

 Student/Graduate of Cybersecurity or related fields (IT profile)

 

We will also appreciate:

  • Familiarity with alert triage, incident handling and escalation workflows (runbooks/playbooks)
  • Basic familiarity with  security tools such as CrowdStrike Falcon EDR, CrowdStrike NG-SIEM, LogScale, Splunk, Microsoft Sentinel
  • Basic familiarity with VM or security tools such as Tenable, Qualys, Wiz, Rapid7, CrowdStrike, or ServiceNow VR

       Experience or interest in Python, PowerShell, Bash and REST APIs

  • Possession of industry certificates in the field of IT security, e.g. CompTIA Security+, certification of leading IT/Security solution providers (also in the areas of security of cloud platforms, e.g. Microsoft AZ-900)
  • Willingness to develop in the area of IT security

 

You are a good fit for us if:

You are a proactive, well-organized person who is genuinely passionate about cybersecurity, follows the latest threats, attack techniques, and industry trends, and wants to develop towards Security Operations, threat detection and response, and vulnerability management. You enjoy investigating how attacks work, are curious about technology and automation, and are ready to take on challenges in international, engineering-driven projects.

 

We offer:

Interesting work in an international consulting company,

  • Locations:Warsaw, Pozna, Krakw, Wrocaw and Gdask
  • Flexible working hours to fit your university schedule
  • Hybrid or remote work options, depending on project requirements
  • Exposure to a wide range of technologies and projects, allowing you to explore different areas of cybersecurity and find your own career path
  • Participation in complex, international projects in the field of implementation of cybersecurity solutions and thus enabling the acquisition of various experiences,
  • Opportunity to gain hands-on experience with enterprise-level cybersecurity tools and technologies
  • Personalized programs of courses and trainings,
  • Participation in a professional development program

 

About EY Poland

We are a global consulting company we help entrepreneurs, organizations and communities get the most out of their potential. We carry out projects in the field of: Audit, Tax, Transaction and Business Consulting (including IT).

 

We employ more than 240,000 exceptional people in more than 150 countries around the world. There are over 2800 of us in Poland, and we work in: Warsaw, Gdask, Katowice, Krakw, d, Pozna and Wrocaw.

We create amazing things together every day. We have people, a development path and training, thanks to which you can also handle the most prestigious projects. 

EY is an equal opportunity employer, we appreciate the diversity of knowledge and experience of our employees.

EY provides all candidates with equal opportunities in the recruitment process, regardless of gender, age, race, religion, sexual orientation, national origin, disability or any other legally protected data, in accordance with applicable law.