Applications are expected to open on June 1, 2027.
The selected intern will assist the team in researching and developing an intelligent security operations solution that combines SIEM capabilities, threat detection, event correlation, automation and analyst-focused decision support.
Expected responsibilities
- Research SIEM technologies, architectures and security operations workflows.
- Collect, parse and normalise security logs from different sources.
- Develop and test detection rules and alert-generation logic.
- Support event-correlation and alert-prioritisation experiments.
- Work with technologies such as Splunk, Elastic Stack, Wazuh or similar platforms.
- Analyse false positives and identify ways to improve alert quality.
- Assist with dashboards, incident summaries and analyst-oriented interfaces.
- Test the solution in controlled lab environments.
- Document experiments, findings, configurations and technical decisions.
Preferred knowledge
Applicants should have basic knowledge of some of the following areas:
- SIEM and SOC workflows
- Windows and Linux security logs
- Log analysis and threat detection
- Networking fundamentals
- Python or another scripting language
- Splunk SPL, Elastic KQL, Wazuh or Sigma
- Git and GitHub
Applicants are not expected to be experts in every area. A strong willingness to learn, experiment and document work is more important.
Work arrangement
This will be an onsite internship in Karachi, Pakistan. The exact location, schedule, duration and working hours will be announced before applications open.
Current status
Coming soon. The application process and complete eligibility requirements will be published closer to June 1, 2027.