Security Internship Program

A hands-on internship for students and early-career learners β€” real research work, structured learning, and mentorship from a working security researcher.

Why this matters: Hmmnm was built by learners, for learners β€” the learning paths, career guides, and weekly research exist because someone needed them. This internship is the direct continuation: not coffee runs and shadowing, but real research tasks with your name on them, guided by the researcher who publishes this site’s work every week.

What we cover

  • Real research work: CVE analysis, tool testing, and checklist development
  • Structured track built on the public learning paths
  • One-on-one mentorship from a working security researcher
  • Participation in weekly threat-intelligence research
  • Writing and communication skills for security careers
  • Certificate and letter of recommendation on successful completion

How we test

1Apply

A short conversation about your background and goals β€” no gatekeeping on prestige, focus on curiosity and consistency.

2Structured track

A learning plan built from the public paths: web security, threat intel, or research skills, matched to your level.

3Guided real work

You produce real outputs β€” analysis drafts, scanner test results, documentation β€” reviewed like a colleague, not graded like homework.

4Complete & launch

Successful completions earn a certificate, a recommendation, and portfolio work you can show employers.

What you get

  • Portfolio-worthy published or co-created work
  • Mentorship and career direction from a practitioner
  • A completed structured track through core security skills
  • Certificate and recommendation letter

The engagement at a glance

πŸ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote β€” no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

πŸ” Retest included

A verification pass over everything you fix β€” included in the price, not an add-on.

See the full engagement process β†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

Who can apply?

Students, recent graduates, and career-switchers. We care about curiosity, consistency, and willingness to learn β€” not your institution’s ranking.

Is it remote?

Yes β€” the program runs fully remote, so location is not a barrier.

How long is the program?

Typically 8 to 12 weeks, structured around the learning-path track and the research work in progress at the time.

What will I actually do?

Real work: drafting CVE analyses, testing in-house scanner output, developing checklists and documentation, and joining the weekly research cycle. Your contributions are reviewed the way a colleague’s would be.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement β€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation β€” a researcher replies.

Start the conversation β†’