Cyber Security Intern

ASSA ABLOYAustin, TX
1dOnsite

About The Position

This internship provides hands‑on experience performing security assessments and penetration testing across HID’s multi‑layered product ecosystem, including hardware devices, embedded firmware, cloud backend systems, API integrations, web portals, and mobile applications for iOS and Android. The intern will support the Product Security team by contributing to vulnerability analysis, secure code review, and validation of secure authentication modules that protect identity workflows across devices and cloud services. This role is ideal for a cybersecurity student eager to explore offensive security methodologies in a real engineering environment. Working closely with security architects, the intern will evaluate system‑wide attack surfaces and help strengthen HID’s trusted identity ecosystem. HID powers the trusted identities of the world’s people, places, and things, allowing people to transact safely, work productively and travel freely. We are a high-tech software company headquartered in Austin, TX, with over 4,500 worldwide employees. Check us out here: www.hidglobal.com and https://youtu.be/23km5H4K9Eo HID Physical Access Control Solutions (PACS) is at the forefront of securing spaces with advanced, reliable access control solutions. From cutting-edge readers, credentials and controllers, to mobile and biometric technologies, HID PACS empowers organizations worldwide to protect their people, property and assets with scalable, high-quality solutions. This is more than just a job – it’s your chance to join an industry leader to drive innovation in access control and make a real impact on global security solutions.

Requirements

  • Currently enrolled in a Cybersecurity, Computer Science, or Information Security degree.
  • Foundational understanding of cybersecurity concepts including encryption, authentication, cloud identity, and common attack vectors.
  • Basic familiarity with APIs, mobile apps, or cloud platforms (even conceptual).
  • Exposure to Linux, command‑line tools, and scripting (e.g., Python, Bash).
  • Strong curiosity about penetration testing across hardware, cloud, web, and mobile environments.
  • Good communication skills and willingness to collaborate with a multidisciplinary engineering team.
  • Introductory knowledge of: API security or OWASP API Top 10 Cloud security fundamentals (Azure, AWS, GCP) Mobile platform security models (iOS Keychain, Android Keystore, permissions systems)

Nice To Haves

  • Familiarity with penetration testing tools such as Burp Suite, OWASP ZAP, Postman, Nmap, Ghidra, or mobile security toolkits.
  • Understanding of embedded systems or firmware architectures.
  • Awareness of cryptographic modules (Secure Elements, TPMs, HSMs).
  • Experience writing simple automation scripts.

Responsibilities

  • Assisting with penetration testing on hardware, firmware, cloud services, mobile apps, and web portal front‑ends.
  • Supporting the execution of API security testing, including authentication/authorization validation and fuzzing.
  • Helping evaluate mobile application security using static and dynamic analysis tools for both iOS and Android platforms.
  • Participating in cloud security assessments, reviewing IAM configurations, API gateways, secrets management, and data‑flow protections.
  • Documenting findings, reproduction steps, and remediation recommendations clearly and accurately.
  • Collaborating in threat‑modeling sessions that span device, cloud, and mobile ecosystems.
  • Contributing to hands‑on testing of embedded systems, custom firmware, cloud microservices, and mobile applications.
  • Assisting in performing API endpoint discovery, input validation testing, and token‑based auth analysis (OAuth2, JWT, etc.).
  • Supporting web portal assessments including session‑management testing, OWASP Top 10 analysis, and role‑based access control reviews.
  • Participating in mobile application reverse‑engineering, local data‑storage evaluation, and API‑interaction security testing.
  • Executing lab testing using hardware security tools as well as cloud‑security and mobile‑security toolchains.
  • Maintaining vulnerability logs, mitigation tracking, and regression‑testing documentation across all platform types.
  • Assisting in ensuring HID’s Secure Development Lifecycle (SDL) is followed for cloud, web, mobile, and device components.

Benefits

  • Competitive salary and rewards package
  • Competitive benefits and annual leave offering, allowing for work-life balance
  • A vibrant, welcoming & inclusive culture
  • Extensive career development opportunities and resources to maximize your potential
  • To be a part of a global organization that is pioneering the hardware, software and services that allow people to confidently navigate the physical and digital worlds
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service