Endpoint Troubleshooting & Log-Analysis (EPP) Intern (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Endpoint Troubleshooting & Log-Analysis (EPP) Intern (Cybersecurity): Own end-to-end log-analysis pipelines for EPP telemetry, transforming heterogeneous endpoint logs into structured events with an accent on parsing, normalization, and correlation across Windows, Linux, macOS. Focus on building investigator workflows (CLI/UI), search capabilities, and prototype detection aids like anomaly detectors for root-cause analysis.
Location: Hybrid with visits to Kraków office, Poland (1 July 2026 – 11 September 2026)
Company
revolutionizes data security with identity-centric solutions, serving 13,500+ organizations in 100+ countries through innovation and global presence.
What you will do
- Design and implement log-analysis pipelines ingesting endpoint telemetry (agent logs, Sysmon/ETW, syslog, process/network snapshots, registry/fs metadata) and emitting structured events.
- Create parsers/normalizers and schemas for heterogeneous logs across Windows, Linux, macOS, with timestamp normalization and enrichment.
- Implement correlation/aggregation logic to link events into investigation artifacts like process chains and network flows.
- Build search/query capabilities and investigator tooling (CLI/web UI) for triage, timeline building, and evidence packaging.
- Prototype detection aids using rule-based correlation, heuristics, or simple anomaly detectors.
- Develop test harnesses, ensure observability, optimize performance, and produce documentation/runbooks/demo.
Requirements
- Hybrid role with required visits to Kraków office, Poland during program dates (1 July – 11 September 2026)
- Hands-on experience with data processing, scripting, or programming for log parsing and analysis.
- Familiarity with endpoint telemetry sources (Sysmon, ETW, syslog) and OS logs (Windows/Linux/macOS).
- Ability to build CLI tools or simple UIs for investigation workflows.
- Skills in correlation logic, search/querying, and basic anomaly detection.
- Strong problem-solving for reproducible failure scenarios and pipeline validation.
Culture & Benefits
- Remote-first environment with frequent face-to-face interactions encouraged.
- Competitive health benefits and continuous learning opportunities.
- Team-oriented, collaborative, innovative culture valuing customer focus, excellence, and ownership.
- Regular town halls, career growth, and emphasis on integrity, respect, hard work.
- Paid internship with measurable project ownership from day one.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →