Threat Intelligence & AI Ops Intern
Fuse threat intelligence with AI operations to detect, predict, and neutralize cyber threats in real time.
Role Overview & Operational Scope
You will sit at the intersection of offensive security and AI engineering — building intelligent threat detection pipelines that ingest, correlate, and act on adversarial signals before they impact our clients. Your work directly strengthens Cehpoint's AI-driven defense posture across SOC, IR, and vulnerability management engagements.
Key Responsibilities & Production Deliverables
- Ingest and normalize threat feeds (STIX/TAXII, OSINT, commercial TI) into SIEM and AI model pipelines for real-time correlation.
- Develop and maintain ML-based anomaly detection and classification models for threat data (phishing, malware IOC clustering, lateral movement prediction).
- Conduct structured adversary behavior mapping using MITRE ATT&CK and produce actionable threat briefs for client incident response teams.
- Design and automate TI enrichment workflows (Python, SOAR playbooks, API integrations with Virustotal, AlienVault OTX, Mandiant, etc.).
- Monitor AI model drift, retraining triggers, and performance degradation in production threat pipelines; implement MLOps observability dashboards.
- Collaborate with the Red Team and AI Engineering squads to stress-test detection models against live attack simulations and red-team exercises.
Mandatory Foundational Knowledge
- Deep understanding of the threat intelligence lifecycle — from requirement gathering through productionization and feedback loops.
- Solid grounding in adversarial tradecraft: how threat actors operate, TTPs, kill-chain dynamics, and evasion techniques.
- Foundational knowledge of supervised and unsupervised ML (classification, clustering, NLP for threat text) and their operational trade-offs in security contexts.
Mandatory Practical Skills & Architecture
- Python (pandas, scikit-learn, transformers/HuggingFace, LangChain or similar LLM orchestration frameworks)
- SIEM/SOAR platforms — Splunk, Elastic/SIEM, QRadar, or open-source equivalents; proven log-analysis expertise
- MITRE ATT&CK Framework (tactics, techniques, enterprise matrix navigation and custom mapping)
- Containerized deployment & MLOps tooling — Docker, Kubernetes, MLflow, or equivalent model-tracking systems
- TI data standards & feeds — STIX 2.x, TAXII, OpenCTI, MISP, and IOC parsing/extraction
Problem Solving, Execution Rigor & Curiosity
- Relentlessly follows emerging APT groups, ransomware strains, and zero-day disclosures — reads raw threat reports, not just summaries.
- Experimentally bridges offensive tradecraft with defensive ML: you enjoy building PoCs that simulate attacker behavior to harden detection logic.
- Proactively reverse-engineers threat data pipelines — questions every false positive, traces it back to source, and iterates on the model.
5-day live technical evaluation milestone
Over a 5-working-day evaluation period, you will be given a anonymized PCAP dataset and a raw threat feed (STIX bundle). Days 1–2: ingest, normalize, and enrich IOCs into a structured MISP-compatible format. Day 3: build a lightweight ML classifier (Python + scikit-learn or equivalent) to categorize IOCs as benign/malicious and rank severity. Day 4: map detected TTPs to MITRE ATT&CK and author a concise threat brief with recommended containment actions. Day 5: present findings in a 30-minute technical review before the AI Ops and Threat Intelligence leads. Evaluation is based on code quality, analytical depth, automation rigor, and clarity of communication — no prior relationship with Cehpoint is assumed.
Institutional hiring protocol: candidates who clear resume screening take a live practical milestone of strictly 5 working days. Verifiable completion and code audit by your assigned engineering mentor is the sole prerequisite for the official offer letter.
Compensation, Total Rewards & Advancement
- Competitive annual stipend (₹12L–₹20L) with performance-linked acceleration and early full-time conversion path
- Fully remote setup — budget allocation for workstation hardware and high-speed internet
- Generous GPU cloud credits (AWS/Azure) for personal projects, model training, and TI pipeline experimentation
- Direct mentorship from senior threat hunters and ML engineers who have operated at national CERTs and top-tier SIEM teams
- Access to private Cehpoint threat intel community, internal capture-the-flag events, and conference sponsorship for top performers
Dedicated inbox for this role
Questions, private repository links or portfolio references for this opening route straight to the engineering leads reviewing it.
threat-intelligence-ai-ops-intern-careers@cehpoint.co.in
Open mail client →