Security Internship Program
A hands-on internship for students and early-career learners β real research work, structured learning, and mentorship from a working security researcher.
What we cover
- Real research work: CVE analysis, tool testing, and checklist development
- Structured track built on the public learning paths
- One-on-one mentorship from a working security researcher
- Participation in weekly threat-intelligence research
- Writing and communication skills for security careers
- Certificate and letter of recommendation on successful completion
How we test
A short conversation about your background and goals β no gatekeeping on prestige, focus on curiosity and consistency.
A learning plan built from the public paths: web security, threat intel, or research skills, matched to your level.
You produce real outputs β analysis drafts, scanner test results, documentation β reviewed like a colleague, not graded like homework.
Successful completions earn a certificate, a recommendation, and portfolio work you can show employers.
What you get
- Portfolio-worthy published or co-created work
- Mentorship and career direction from a practitioner
- A completed structured track through core security skills
- Certificate and recommendation letter
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote β no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix β included in the price, not an add-on.
See the full engagement process β and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
Who can apply?
Students, recent graduates, and career-switchers. We care about curiosity, consistency, and willingness to learn β not your institutionβs ranking.
Is it remote?
Yes β the program runs fully remote, so location is not a barrier.
How long is the program?
Typically 8 to 12 weeks, structured around the learning-path track and the research work in progress at the time.
What will I actually do?
Real work: drafting CVE analyses, testing in-house scanner output, developing checklists and documentation, and joining the weekly research cycle. Your contributions are reviewed the way a colleagueβs would be.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation β a researcher replies.
Start the conversation β