Supports Cloudflare’s security compliance and risk programs through control evaluations, audits, risk assessments, and automation. The internship requires familiarity with security frameworks, risk management, Python, application development, and AI-enabled workflows.
Salary not listed
On-siteEntry levelSecurity Engineering
About the role
Responsibilities
Execute a specialized project that directly improves Cloudflare’s security posture over a 12–16 week internship.
Improve the maturity of the Security Compliance program by:
Evaluating the efficacy of security controls implemented across the organization.
Developing and implementing automated solutions to improve Governance, Risk, and Compliance processes and operations, integrating with existing security, engineering, and AI tools.
Supporting the security risk register by triaging and assessing potential risks, proposing mitigation strategies, and presenting key security insights to leadership.
Supporting security data center audits and assessments.
Work cross-functionally with Legal, People, Engineering, and Finance teams to integrate security into company operations.
Work closely with a mentor for hands-on guidance in a specific security domain.
Connect and learn from executives and leadership, including the co-founders.
Present the security project to the company at the end of the internship.
Write for the Cloudflare blog and participate in Cloudflare TV sessions.
Requirements
Working knowledge of industry-standard frameworks such as NIST 800-53, ISO 27001, or SOC 2 principles through coursework or personal study.
Understanding of risk management methodologies, including identifying threats, assessing impact and likelihood, and suggesting mitigation strategies.
Ability to write basic Python scripts to automate repetitive tasks, such as interacting with APIs or cleaning data.
Experience with workflow logic and orchestration, including “if-this-then-that” automation logic.
Understanding of how to instruct AI models effectively and leverage them for day-to-day tasks.
Ability to build and deploy a full application.
Technical writing and documentation skills.
Observability and metrics experience.
Prompt engineering or experience using LLM coding tools.
Familiarity with Cloudflare products such as Workers, Workers AI, R2, and D1.
Demonstrated critical thinking, curiosity, empathy, adaptability, and ability to get things done.
Ability to commit to a minimum 12-week summer internship.
Ability to work in the office 3–5 days per week at the internship location.
Nice-to-haves
Passion for security and software development demonstrated through personal projects, open-source contributions, or experience.
Experience building something with Cloudflare’s developer platform through Cloudflare for Students.
Entry-level cybersecurity analyst supporting clients, compliance, IT, and business operations while learning frameworks, tools, and industry certifications. The role requires strong communication, follow-through, curiosity, resilience, and willingness to work a demanding on-site schedule.
Hands-on tier-one IT Security Operations Analyst monitoring Microsoft Defender and Sentinel for threats, triaging alerts, investigating phishing and account compromises, performing access audits, and supporting SOC 2/ISO audits. Requires 1-2 years security or sysadmin experience and familiarity with Microsoft security tools.
Salary not listedOn-site2+ YOESecurity Engineering
Cyber Security Intern
LabelboxSan Francisco, CA
Security Engineering Intern at Labelbox supporting vulnerability management, IAM workflows, cloud access controls, SIEM optimization, and CI/CD security. Requires current pursuit of a CS/Cybersecurity degree, interest in cloud/data security, and basic cloud platform knowledge.
40 – 55/hrHybridEntry levelSecurity Engineering
Detection Engineer II
InstacartUnited States
Detection Engineer building and operating high-fidelity detection systems, threat hunting, and automated response across endpoint, cloud, container, and SaaS environments at Instacart. Requires 2+ years in detection/IR/offensive security, cloud experience, deep attacker TTP knowledge, macOS internals, and detection-as-code practices.
142k – 181k/yrRemote2+ YOESecurity Engineering
Security Guard
IdmeMcLean, VA
Unarmed Security Guard responsible for patrolling facilities, controlling access, responding to emergencies, and ensuring safety at ID.me offices. Requires 2+ years security experience, DCJS certification (or equivalent), physical fitness, and ability to obtain Public Trust clearance.