Security Analyst Intern
Role: GRC and new OffSec/Pentesting Internships!
Location: Remote
About Rhymetec:
Rhymetec was founded in New York City in 2015, growing steadily in the areas of compliance, cybersecurity, and data privacy. Our mission is to ensure our clients are compliant faster, so they can focus on their core business and less on the complexities of building effective and compliant infosec programs.
Job Title and Description: Security Analyst Intern and Offensive Security Analyst Intern
Rhymetec’s GRC internship program is aimed at teaching aspiring cybersecurity professionals the fundamentals of cybersecurity best practices and gain real-world experience in the cybersecurity industry. Rhymetec interns will work with various cloud-based technologies to aid in industry understanding and skill advancement within GRC. W
This is a paid internship at 25 hours per week, intended to last three months. Typical work hours will be approximately 10:00 a.m. to 3:00 p.m. (about 5-6 hours per day), with flexibility for time off as needed.
Rhymetec’s offsec internship program is seeking an Offensive Security Analyst Intern to support our Offensive Security team with managed vulnerability disclosure bug bounty operations, internal tooling, security research, and supervised penetration testing support. This role focuses on triaging and validating vulnerability submissions, contributing to internal automation, and learning professional penetration testing methodology and reporting.
This is a structured internship and training pipeline designed to prepare students who are eager to earn a full time role as a Penetration Tester with Rhymetec’s Offensive Security team. This is an unpaid internship at 20 hours per week, intended to last four months. Typical work hours will be approximately 8:00 a.m. to 12:00 p.m. (about 4-5 hours per day), with flexibility for time off as needed. Conversion to a full time position may be considered for high performers based on department needs.
*Rhymetec's Offensive Security Internship and GRC Security Internship are paid opportunities.
Qualifications GRC:
- Bachelor's Degree in Information Technology, Cybersecurity or Computer Science
- Reliable internet, with video conference ability (camera/microphone, etc).
- Professional approach to assigned tasks, ability to meet deadlines and communicate with mentor and upper management.
- Basic knowledge of Google Workspace
- Basic understanding of macOS
- Must be able to pass a state and federal background check
Qualifications OffSec:
- Upperclassman or recently graduated in 2025 or 2026 with a Bachelor’s or Master’s in Cybersecurity, Computer Science, IT, or related field.
- Strong understanding of web fundamentals: HTTP/S, sessions/cookies, authentication patterns, APIs, JSON.
- Working knowledge of Macbook or Linux command line.
- Ability to write and maintain scripts in Python and Bash for practical automation tasks.
- Foundational knowledge of vulnerability concepts (OWASP Top 10-level understanding).
- Strong written communication skills with the ability to document steps and explain findings clearly.
- Professional judgment with sensitive data, scope boundaries, and ethical handling of security information.
Competitive Qualifications - Prior experience with bug bounty hunting (HackerOne, Bugcrowd, Intigriti, etc.).
- GitHub portfolio, code samples, or security writeups (CTFs, labs, research).
- Intro-level cloud security familiarity (e.g., basic AWS concepts such as IAM, S3, security groups).
- Exposure to vulnerability scoring and prioritization or published CVE submissions.
Skills Needed for Success:
- Posses technical competency to understand Rhymetec’s services
- Motivated to gain industry experience
- Commitment to the program from start to finish
- Willingness to learn and adapt in a fast-paced environment and with autonomy
Rhymetec is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetic, disability, age, or veteran status.