What are the responsibilities and job description for the Fall 2026 - Cybersecurity Engineering Internship position at Medlaunch Concepts?
We're building a transformative healthcare accreditation platform that is revolutionizing how hospitals manage compliance, quality improvement, and regulatory processes. Our platform combines cutting-edge technology with deep healthcare domain expertise to solve real problems for healthcare organizations nationwide. We are SOC 2 Type 2 certified and HIPAA compliant, and are actively pursuing ISO 27001 certification and GDPR readiness.
The OpportunityThe goal is to have interns turn into full-time employees; therefore, you will be given full-time responsibilities from day one. You will be working in a high-velocity growth startup and will be required to move fast. You'll work directly with our engineering and security teams on production healthcare systems, gaining hands-on experience with penetration testing, cloud security, and compliance operations while making real contributions that impact our product and customers.
Compensation StructureBase position is unpaid; however, qualified candidates may receive upfront equity compensation based on their experience level and demonstrated capabilities. We evaluate each applicant individually and offer equity packages commensurate with their potential contribution.
About the RoleWe're hiring a Cybersecurity Intern focused on Penetration Testing & Cloud Security. This role is split between offensive security — finding and exploiting vulnerabilities across our web applications, APIs, and cloud infrastructure — and defensive hardening of our AWS environment. As we transition into production, you will also assist with blue teaming initiatives, focusing on detection engineering and active threat monitoring. You'll also contribute to our compliance posture as we maintain SOC 2 and HIPAA while working toward ISO 27001 and GDPR readiness.
Requirements- Penetration testing & API security: Solid understanding of web application and API security testing frameworks, testing security features, and familiarity with OWASP standards for both traditional applications and AI.
- Threat Monitoring & Blue Teaming: Familiarity with blue teaming concepts, with a strong interest in actively monitoring infrastructure in real-time to detect threats, prevent compromises, and maintain company SLAs.
- Cloud security: Experience with AWS security concepts — identity and access management, network segmentation, encryption, and logging.
- Networking & infrastructure security: Understanding of firewalls, VPNs, TLS/SSL, DNS security, and least-privilege network design.
- Compliance frameworks: Working knowledge of at least one: SOC 2, HIPAA, ISO 27001, or GDPR — and willingness to learn the others.
- Scripting & automation: Python or Bash for security automation, exploit development, log parsing, and vulnerability scanning workflows.
- Version control: Git for code and configuration versioning.
- Collaborative mindset: Ability to work within a specialized team structure and move fast in a startup environment.
- Hands-on experience with pen testing tools (Burp Suite, OWASP ZAP, Metasploit, Nmap, Nikto).
- Experience with SIEM tools (Splunk, Datadog Security, or AWS-native equivalents) and detection engineering principles.
- Exposure to infrastructure-as-code security scanning (Terraform, CloudFormation, Checkov, tfsec).
- Knowledge of container security (Docker image scanning, runtime security).
- Bug bounty participation or CTF competition experience.
- Healthcare or regulated industry experience.
- Relevant certifications or coursework: CompTIA Security , OSCP, CEH, AWS Security Specialty, or similar.
- Web & AI application testing: Conduct structured penetration tests against our platform — identifying injection flaws, broken authentication, access control bypasses, and vulnerabilities aligned with the OWASP Top 10 and OWASP Top 10 for LLM/AI.
- API security assessments: Test REST API endpoints using API security frameworks, specifically focusing on testing core security features, authentication weaknesses, improper authorization, rate limiting gaps, mass assignment, and data exposure risks.
- Cloud infrastructure testing: Assess our AWS environment for misconfigurations, privilege escalation paths, exposed services, and insecure default settings.
- Vulnerability discovery and reporting: Document findings with clear severity ratings, reproducible proof-of-concept exploits, and actionable remediation guidance for engineering teams.
- Red team exercises: Participate in simulated attack scenarios to test organizational security awareness and incident response readiness.
- Threat detection, monitoring, & SLAs: Configure, tune, and actively monitor cloud-native logging services in real-time to detect threats, prevent platform compromises, and safeguard our production SLAs.
- Detection engineering: Help build and refine detection rules and alerts for infrastructure monitoring as our production environment scales.
- Identity and access management: Audit and enforce least-privilege access policies across AWS services — eliminating over-permissioned roles and implementing conditional access controls.
- Network security: Review and harden network segmentation, security groups, and perimeter controls to isolate sensitive healthcare data workloads.
- Encryption and secrets management: Verify and improve encryption-at-rest and in-transit across all platform services, and enforce secrets rotation and key management best practices.
- Secure configuration baselines: Develop and enforce security benchmarks (CIS, AWS Well-Architected) across cloud resources, with automated drift detection.
- ISO 27001 readiness: Assist in developing and documenting Information Security Management System (ISMS) policies, controls, and evidence aligned to Annex A requirements.
- GDPR data protection: Help implement data subject access request (DSAR) workflows, consent management mechanisms, data processing inventories, and cross-border data transfer controls.
- SOC 2 continuous compliance: Maintain and improve existing SOC 2 Type 2 controls — gathering evidence, monitoring control effectiveness, and remediating gaps identified in audits.
- HIPAA security rule alignment: Support ongoing HIPAA compliance by reviewing technical safeguards, access controls, and audit trail requirements across the platform.
- Policy and procedure documentation: Draft and maintain security policies, incident response playbooks, and risk assessment documentation for internal use and auditor review.
- Conduct penetration tests against web applications, APIs (using security frameworks), and cloud infrastructure — documenting findings with severity ratings and remediation steps.
- Actively monitor production infrastructure for real-time threats as a security analyst, escalating and responding to alerts to protect SLAs.
- Contribute to detection engineering and help build out the telemetry and rules needed for robust infrastructure defense.
- Audit and harden identity and access management policies, network configurations, and encryption settings across AWS.
- Perform vulnerability assessments, validate core security features, and work with engineering teams on prioritized remediation.
- Participate in red team exercises and help refine incident response, detection, and escalation procedures.
- Automate security workflows using Python and Bash — vulnerability scanning, compliance checks, and reporting.
Candidates must meet all Core Qualifications plus demonstrate depth in the Penetration Testing & Cloud/Blue Team focus area.
Core Qualifications- Intermediate to advanced Python or Bash scripting skills (1 years).
- Git for version control and collaborative development workflows.
- Understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, TLS).
- Familiarity with AWS or equivalent cloud platforms.
- Understanding of web application and API security testing methodologies (OWASP Top 10, OWASP for AI/LLMs, PTES, OSSTMM).
- Familiarity with API security frameworks and testing core security features.
- Familiarity with blue teaming concepts, detection engineering, and real-time threat monitoring.
- Hands-on experience with at least one pen testing tool (Burp Suite, OWASP ZAP, Metasploit, Nmap).
- Familiarity with AWS security concepts — IAM, VPC networking, encryption services, and logging.
- Familiarity with at least one compliance framework: SOC 2, HIPAA, ISO 27001, or GDPR.
- Knowledge of encryption standards and key management (AES-256, TLS 1.2 ).
- Understanding of SIEM or centralized logging concepts.
- Security-related coursework, certifications, CTF participation, or bug bounty experience.
- OSCP, CEH, CompTIA Security , or AWS Security Specialty certification (or in progress).
- Bug bounty hall of fame entries or published vulnerability disclosures.
- Healthcare or regulated industry experience.
- Experience writing incident response playbooks or security documentation.
- Familiarity with infrastructure-as-code security scanning (Checkov, tfsec, Prowler).
- Knowledge of container and serverless security hardening.
- SOC 2 audit evidence gathering or ISO 27001 ISMS development.
- Familiarity with zero-trust architecture principles.
We believe in a transparent and thorough selection process that respects your time while ensuring mutual fit:
- Initial Screening Call — We'll discuss your background, experience, and career goals, while providing an overview of the role and our team culture.
- Technical Challenge (issued on a case-by-case basis) — You'll receive a real-world security challenge to complete within a specified timeframe.
Technical Interview — We'll have an in-depth discussion about your solution and explore related security concepts.