Offensive Application Security Intern

Information Security

Confirmed live in the last 24 hours

Tesla

Tesla

No salary listed

Austin, TX, USA

In Person

Full-time on-site work is required; the internship is expected to run through the Spring 2027 term.

CategoryEngineering & Information TechnologyLocationAUSTIN, TexasRequisition ID281483TypeIntern/Apprentice

Job Description

Consider before submitting an application:  

This position is expected to start around January 2027 and continue through the entire Spring term (ending approximately May 2027 or later, if available). We ask for a minimum of 12 weeks, Full - Time (40 hours/week) and on-site, for most internships. Our internship program is for students who are actively enrolled in an academic program. Recent graduates seeking employment after graduation and not returning to school should apply for full-time positions, not internships.

International Students: If your work authorization is through CPT, please consult your school on your ability to work 40 hours per week before applying. You must be able to work 40 hours per week on-site. Many students will be limited to part-time during the academic year.   

About the Team

We are looking for an enthusiastic Offensive Application Security Intern to join our team, where you'll conduct simulated attacks on web and mobile applications to identify vulnerabilities, exploit weaknesses, and recommend robust defenses. Responsibilities include performing penetration testing, code reviews, and threat modeling; developing custom tools and scripts for exploit automation; collaborating with development teams to remediate issues; and staying abreast of emerging threats like OWASP Top 10 risks. The ideal candidate loves to play CTFs, possesses strong programming skills in languages like Python or JavaScript, and has interest in ethical hacking, with a passion for proactive security in fast-paced environments.

Job Responsibilities

  • Hands-on penetration testing and simulated attacks on web, mobile, and API apps in a collaborative, fast-paced setting
  • Regular code reviews and threat modeling with dev and DevOps teams to embed security in the SDLC
  • Building and maintaining custom exploit tools/scripts in Python, Bash, or JavaScript for automated testing
  • Researching emerging threats via conferences, CTF challenges, and bug bounty programs
  • Blend of solo and team projects, including shaping security policies

Job Requirements

  • Currently pursuing a degree in Computer Science or a related field of study with a graduation date between 2027-2028
  • Experience with secure architecture design
  • Participation in Capture the Flag (CTF) events is ideal
  • Security experience in one or more of: C, C++, PHP, Go,x86, ARM, CAN, cryptography, reverse engineering, wireless networks
  • Strong understanding of common web vulnerabilities with SQLi, XSS, CSRF and exploit development
  • Strong penetration testing experience
  • Experience auditing code and features