Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com

Security Engineer Internship

Metasys
๐Ÿ‡บ๐Ÿ‡ธ United States
Remote
Internship
10 months ago
  • AI
  • PCI DSS
  • GDPR
  • Next.js
  • NestJS
  • Threat Modeling
  • SAML
  • PostgreSQL
  • Vault
  • Traefik
  • WAF
  • Incident Response
  • Node.js
  • React.js
  • JWT
  • Docker
  • Terraform
  • SAST
  • DAST
  • LangChain
  • AutoGen
  • Devops
  • CI/CD
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

Security Engineer

Overview: Supply Chain Security and Compliance

The Security Engineer is a critical role responsible for implementing and enforcing robust security practices across our entire integrated supply chain e-commerce platform. You will safeguard e-commerce transactions, secure internal tool integrations, and establish the trust framework for our AI agent operations, ensuring compliance with global regulatory standards like PCI-DSS and GDPR.

Internship Details

  • Duration: 3 months (extendable based on performance and project scope)

  • Start Date: Immediate

  • Location: Remote

  • Stipend: Unpaid initially; may convert to a paid internship, full-time role, or even direct client absorption (FTE) based on your performance

Key Responsibilities & Core Projects

You will secure all layers of the application, from the Next.js frontend to the NestJS modular monolith and the cloud infrastructure.

  • Security Architecture & Threat Modeling: Perform vulnerability assessments, code reviews, and threat modeling for all new features and systems, focusing on the critical MES $\rightarrow$ WMS $\rightarrow$ OMS business process flow.

  • Compliance Enforcement: Lead the implementation and auditing of security controls necessary for PCI-DSS compliance (for Payment module) and GDPR compliance (for user/tenant data handling).

  • Access Control & Authentication: Implement and manage secure API authentication methods, including OAuth 2.0 and SAML, utilizing Authentik/Ory Kratos and leveraging PostgreSQL's Row-Level Security (RLS) for tenant isolation.

  • Secrets & Encryption: Manage secrets and key rotation using Vault, define and enforce encryption protocols for data both in transit and at rest, and manage certificates via Traefik.

  • Abuse Prevention: Implement and monitor controls for API rate limiting, Web Application Firewall (WAF) rules, and traffic monitoring to prevent abuse and denial-of-service attacks.

  • Incident Response: Develop and practice incident investigation and response protocols. Conduct security awareness training for development and operations teams.

Required Technologies & Tools

Candidates must possess hands-on security experience with our core stack and compliance tools:

  • Platform Security: Node.js/NestJS security best practices, Next.js/React security, PostgreSQL RLS.

  • Compliance Focus: Experience with PCI-DSS and GDPR controls and auditing.

  • Authentication & Access: OAuth 2.0, SAML, JWT, Authentik/Ory Kratos.

  • Secrets & Infrastructure: HashiCorp Vault, Docker, Terraform.

  • Monitoring & Assessment: Tools for Static/Dynamic Application Security Testing (SAST/DAST).

AI Agent Security

You will be responsible for securing the emerging AI ecosystem.

  • Agent Trust Framework: Establish security boundaries for the AI agent interfaces, ensuring agents (built with LangChain/AutoGen) operate within strict permissions when accessing supply chain data (WMS, OMS).

  • Prompt Injection Prevention: Implement validation and sanitization techniques to mitigate prompt injection and data exfiltration risks in user-facing LLM interactions.

Success Metrics & Career Path

Performance will be measured by:

  • Security Scorecard: Reduction in identified vulnerabilities from assessments and code reviews (SAST/DAST).

  • Compliance Audits: Successful passing of regular PCI-DSS and GDPR audits.

  • Incident Handling: Speed and effectiveness of security incident investigation and remediation.

Mentorship Structure: Reports to the Solution Architect or Head of Technology, working closely with the development and DevOps teams to embed security into the CI/CD pipeline.


Security Engineer Internship ยท Metasys

Auto apply with Likeremote