×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Operations & Incident Response Intern

Job in 600001, Chennai, Tamil Nadu, India
Listing for: TECEZE
Apprenticeship/Internship position
Listed on 2026-09-29
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Job Description & How to Apply Below
Cybersecurity Operations & Incident Response Intern
About the Role
We are looking for a  Cybersecurity Operations & Incident Response Intern  to join our security team and gain hands-on experience in Security Operations Centre (SOC) activities, threat detection, alert investigation, incident response, and digital forensics.
This internship is designed for candidates who want to build practical cybersecurity skills by working with security telemetry, investigating alerts, analysing suspicious activity, developing detections, and supporting incident response activities.
The role provides exposure to industry-standard cybersecurity tools and methodologies, including  SIEM platforms, MITRE ATT&CK, Sigma, threat intelligence, endpoint telemetry, network monitoring, cloud security, and forensic investigation .

Key Responsibilities
Monitor and analyse security alerts from SIEM and security monitoring platforms.
Perform initial  alert triage  and determine whether activity is benign, suspicious, or malicious.
Investigate security events using endpoint, network, identity, and cloud telemetry.
Search and correlate security data using platforms such as  Splunk, Elastic, and Microsoft Sentinel .
Document investigation findings, evidence, severity, impact, and recommended actions.
Assist with incident response activities, including identification, containment, eradication, and recovery.
Map observed attacker behaviour to the  MITRE ATT&CK  framework.
Assist in creating, testing, and tuning security detection rules using  Sigma  and other detection technologies.
Participate in threat-hunting exercises based on defined hypotheses and available security telemetry.
Support digital forensic investigations involving Windows systems, disk evidence, memory evidence, and relevant system artefacts.
Assist with analysing cloud and identity security events, including Microsoft Entra  AWS Cloud Trail logs.
Contribute to incident timelines, investigation reports, shift handover notes, and executive-level summaries.
Participate in purple-team and simulated incident exercises.
Help identify opportunities to improve detection coverage, reduce false positives, and strengthen security monitoring.
Maintain accurate documentation of investigations and follow established security procedures.
Tools & Technologies
During the internship, you may work with technologies including:
SIEM:  Splunk, Elastic Stack/Kibana, Microsoft Sentinel
Endpoint & Network:  Sysmon, Windows Event Logs, Zeek, Suricata, Wireshark
Detection:  Sigma, MITRE ATT&CK, ATT&CK Navigator
Forensics:  Velociraptor, Volatility 3, KAPE, Plaso, Time sketch
Threat Intelligence:  MISP, STIX/TAXII
Incident Management:  The Hive, Cortex
Automation:  Shuffle / SOAR technologies
Cloud & Identity:  AWS Cloud Trail, Microsoft Entra
Security Testing:  Atomic Red Team
These technologies are aligned with the practical cybersecurity operations curriculum provided for the role.
What You Will Learn
By the end of the internship, the intern should be able to:
Understand how a SOC operates and how security events progress from  event → alert → investigation → incident → resolution .
Analyse and correlate security logs from multiple sources.
Conduct structured alert investigations using evidence rather than assumptions.
Write clear and defensible investigation notes.
Apply  MITRE ATT&CK  to real-world attack activity.
Develop and tune basic detection rules.
Understand the  NIST incident response lifecycle .
Support incident containment and investigation activities.
Perform introductory host, disk, and me
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary