AI Security Intern
Sennovate Inc. · Coimbatore, Tamil Nadu, India
قدّم وتابع مع أبلاي إيدجJob Title: AI Security InternLocation: Coimbatore — on-site (preferred)/hybrid/remoteType: 3-months paid internship (full-time)Conversion: Strong performers convert to full-timeRole PurposeWe're hiring someone who builds AI systems for security. You'll design and ship accelerators, turnkey solutions, and standalone capabilities that go into production for enterprise clients across energy, financial services, healthcare, and technology. The ceiling on this role is high: we're working toward a security-domain LLM that generalizes across industries, and the person in this seat will be part of making that real.That takes two things at once. You must engineer — Python, ML, agent frameworks, retrieval, evaluation, deployment. And you must understand security at the fundamentals level.Key ResponsibilitiesWhat you'll buildDelivery accelerators — AI-assisted alert triage, evidence summarization, automated assessment and reporting that compresses weeks of consulting into daysTurnkey solutions — packaged, repeatable, deployable capabilities with documentation and handoverAgentic systems — multi-step workflows with tool use, retrieval, memory, and guardrails, integrated into SenOptic, our TechFinSecOps platformDomain LLM work — dataset curation, synthetic data generation, fine-tuning, grounding, and evaluationEvaluation harnesses — because "it looked right in the demo" is not a standard we accept for anything touching client security decisionsRequired Qualifications1. Engineering — you ship, not prototype-and-abandonPython and software craft — clean, typed, testable code; Git, Docker, CI/CD, Linux, REST/API development (FastAPI or similar), data pipelinesLLM and agent engineering — orchestration frameworks (LangGraph, LangChain, LlamaIndex, CrewAI, or equivalent); RAG in practice — chunking, embeddings, vector stores, hybrid and re-ranked retrieval; tool calling, structured output, context management, MCP; prompt engineering as a versioned, tested disciplineML foundations — PyTorch or scikit-learn, anomaly detection and clustering; fine-tuning and adaptation (LoRA/QLoRA, PEFT); evaluation and observability (eval sets, hallucination and regression measurement, tracing); the judgment to know when a rule or small classifier beats an LLMNice to have — cloud AI platforms (Azure OpenAI, Bedrock, Vertex), local inference (vLLM, Ollama), Kubernetes, entity extraction from unstructured security text2. Security domain depth — fundamentals, not product certificationsYou should understand how security actually works — attack paths, controls, identity, trust boundaries, risk. We care that you can reason from first principles, not that you've clicked through a particular vendor console. Products change; fundamentals don't.Genuine depth in at least two of the following:Offensive security — VAPT, web and API testing (OWASP Top 10), AD attack paths, privilege escalation, cloud misconfigurationExternal attack surface management — asset discovery, shadow IT, DNS and certificate recon, exposure prioritizationDetection & response / SOC — detection engineering, Sigma rules, KQL/SPL, MITRE ATT&CK, threat hunting, incident response, SOARIdentity & access management — OAuth 2.0, OIDC, SAML, SCIM, RBAC/ABAC, privileged access, lifecycle, Zero Trust, non-human identityThreat intelligence — collection and analysis, IOCs vs. TTPs, STIX/TAXII, MISP, operationalizing intel into detectionsGRC — NIST CSF 2.0, ISO 27001, SOC 2, PCI-DSS, HIPAA; control mapping, risk assessment, evidence collectionNetworking, OS internals, cryptography basics, and cloud architecture are assumed groundwork across all of these.3. Securing AI itselfAnything you build will handle sensitive client data, so this matters as much as building it: OWASP Top 10 for LLM Applications and MITRE ATLAS; prompt injection, data leakage, insecure output handling, excessive agency; guardrails and human-in-the-loop design for consequential actions. Familiarity with NIST AI RMF, ISO 42001, or the EU AI Act is a plus.4. The personB.E./B.Tech/M.Tech/MCA in CS, Cybersecurity, IT, or related — final year or recently completed. Equivalent self-taught capability is fully acceptable if you can show the work.Evidence of building. GitHub, CTF profiles, home lab, published research, open-source contributions, deployed side projects. This is the single strongest signal in your application.Clear technical writing — you'll produce documentation and client-facing material, and explain findings to non-technical readersSelf-direction. You'll get problems and context, not step-by-step tickets.Certifications — Security and AI certs are welcome but are not a substitute for demonstrated capability.