- Location
- Indonesia
- Type
- Internship
- Department
- Engineering
- Seniority
- Internship
- Source
- Workday
Description
Ensign is hiring !
Key Responsibilities
- Log Source Onboarding: Assist in integrating new log sources (servers, firewalls, endpoints, cloud services, applications) into the SIEM platform.
- Use Case / Detection Rule Development: Help build, test, and tune correlation rules, alerts, and detection use cases to identify suspicious or malicious activity.
- Dashboard & Report Creation: Create and maintain dashboards, visualizations, and reports for security monitoring and compliance purposes.
- Alert Triage & Tuning: Support the SOC team in reviewing alerts, reducing false positives, and improving signal-to-noise ratio.
- Log Parsing & Normalization: Assist with parsing, normalizing, and enriching raw log data so it's usable for analysis.
- Documentation: Document SIEM configurations, standard operating procedures (SOPs), playbooks, and detection logic.
- Incident Support: Assist analysts during security incident investigations by pulling relevant logs/queries from the SIEM.
- Health Monitoring: Help monitor SIEM system health, data ingestion rates, and license/storage usage.
- Research: Stay current on emerging threats, MITRE ATT&CK techniques, and translate them into new detection content.
- Compliance Support: Assist with audit and compliance log retention/reporting requirements (e.g., PCI-DSS, ISO 27001, SOC 2).
Required / Preferred Skills
- Basic understanding of networking (TCP/IP, DNS, firewalls) and operating systems (Windows/Linux).
- Familiarity with security concepts: threat detection, incident response, log analysis.
- Exposure to at least one SIEM tool (Splunk, QRadar, Sentinel, ELK/Elastic) — coursework, labs, or certs count.
- Basic scripting/query language skills (SPL, KQL, Python, or regex).
- Understanding of common attack techniques (phishing, malware, lateral movement) — MITRE ATT&CK familiarity is a plus.
- Analytical thinking, attention to detail, and good documentation habits.
- Currently pursuing a degree in Cybersecurity, Computer Science, IT, or related field.
Nice-to-Have
- Certifications: Security+, CySA+, Splunk Fundamentals, or similar.
- Experience with cloud security (AWS/Azure/GCP logging).
- Prior CTF, home lab, or SOC simulation experience.
Learning Outcomes for the Intern
- Hands-on SIEM administration and content development experience.
- Real-world exposure to SOC workflows and incident response.
- Understanding of enterprise logging architecture and detection engineering lifecycle.
Skills
PythonAWSAzureGCPLinuxCybersecuritySIEMSOCSplunkTCP/IPComplianceSOC 2ISO 27001