Currently pursuing a degree in Computer Science, Cybersecurity, or a related field., Familiarity with security testing tools such as Burp Suite, Fiddler, or Wireshark., Understanding of cloud networking concepts including VPC, IP, TCP, DNS, and HTTP., Experience with DevSecOps tools and CI/CD pipelines is a plus..
Key responsibilities:
Participate in securing web applications and APIs by identifying vulnerabilities.
Deploy and maintain DevSecOps tools within CI/CD pipelines.
Implement least-privileged access policies using Hashicorp Vault.
Investigate automated security alerts and maintain audit log pipelines.
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
Super.com is a technology company at the intersection of fintech and commerce that empowers users to spend less, save more, and build credit - so they can make the most of life. Super.com is home to the best prices on everything - from discounted everyday items to great hotel deals - and it’s the hub that enables rich cashback and credit building on every transaction.
The company is trusted by over 7 million customers, helping them save over $150M to date. Super.com is backed by Steph Curry and has raised over $100MM USD and surpassed $1B in sales.
We started Super.com to help maximize lives–both the lives of our customers and the lives of our employees– so that everyone can experience all that life has to offer. For our employees, our promise is that Super.com is more than just a job; it’s an opportunity to unlock one’s potential, where learning is celebrated and impact is realized.
We are looking for a Security Engineering Intern to join our team. Duties and responsibilities include:
- Participate in securing our product by catching application-level vulnerabilities in our web apps and APIs
- Deploy and maintain DevSecOps tools such as Trivy, Bandit, or GitLeaks as part of our CI/CD pipelines
- Implement least-privileged access policies for our secrets using Hashicorp Vault
- Help investigate automated security alerts
- Implement and maintain audit log pipelines from our internal tools and external vendors
- Work with cutting edge infrastructure tools like AWS, Docker, Kubernetes, Terraform, and Helm
About You
You’ve seen how to take advantage of vulnerable web apps and APIs, and you would like to patch them
You’ve performed testing with some variation of security tooling (whether it be Burp Suite, Fiddler, Wireshark, etc.)
You have excellent knowledge of how networked services in the cloud work: VPC, IP, TCP, DNS, HTTP, etc.
You can use critical thinking skills to determine the impact and severity of the identified vulnerability to our organization
Terraform and Helm
Datadog for logging, monitoring, and alerting
Postgres for storage and Redis for caching
Gitlab for version control and CI/CD
Python, Bash, and Docker for local development workflows and CI/CD jobs
Our Stack
Amazon Web Services
Tens of containerized microservices written in Python and/or JS processing a total of 15k+ requests per second
Kubernetes for deploying services
Infrastructure as Code in Terraform and Helm
Datadog for logging, monitoring, and alerting
Postgres for storage and Redis for caching
Gitlab for version control and CI/CD
Python, Bash, and Docker for local development workflows and CI/CD jobs
We've got you covered
Compensation: we pay our Interns top-of-market
$300 One-time home office set up allowance
$25/Week UberEats allowance on Fridays
$300/Term Learning and Development allowance
$120/Term Fitness/Wellness allowance
Top Talent: work with the best in the world, including Engineers and Leadership from Google, Uber, and more.
Build Something Great: most importantly, build a product used by millions around the world - have ownership, have impact, and do great work.
We Believe in Equal Opportunity
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Accommodations are available on request for candidates taking part in all aspects of the selection process. If needed, please notify our Talent Acquisition Partner.
Required profile
Experience
Industry :
Information Technology & Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.