HobbyFi
Website:
hobbyfi.in
Job details:
Position: Cybersecurity Intern (VAPT & Pentesting)
Location: Remote / Hybrid
Duration: 3–6 Months
Type: Internship (with potential full-time conversion)
About the RoleWe are building a security-first product focused on VAPT (Vulnerability Assessment & Penetration Testing) for modern vibe-coded applications—fast-built, AI-assisted, and often security-neglected products.
As a Cybersecurity Intern, you will work directly on identifying, exploiting, and documenting vulnerabilities across web and mobile applications, helping us build scalable security tooling and frameworks.
What You’ll Do- Perform Vulnerability Assessments and Penetration Testing (VAPT) on web and mobile apps
- Assist in building automated VAPT workflows for modern app stacks
- Identify vulnerabilities such as:
- OWASP Top 10 issues (XSS, SQLi, CSRF, etc.)
- Authentication & session flaws
- API security gaps
- Write clear, structured security reports with PoCs and remediation steps
- Work on real-world applications built using no-code, low-code, and AI-assisted tools
- Collaborate with product and engineering teams to fix vulnerabilities
- Contribute to internal tools/scripts for scanning and testing
What We’re Looking For- Basic understanding of web security fundamentals
- Familiarity with OWASP Top 10
- Hands-on exposure (even beginner level) with tools like:
- Burp Suite / OWASP ZAP
- Nmap, Nikto, etc.
- Understanding of:
- HTTP/HTTPS protocols
- APIs (REST/GraphQL)
- Curiosity to break systems and think like an attacker
- Ability to document findings clearly
Bonus (Good to Have)- Experience with bug bounty platforms (HackerOne, Bugcrowd, etc.)
- Knowledge of mobile app pentesting (Android/iOS)
- Basic scripting (Python, Bash, JS)
- Exposure to cloud security (AWS/GCP basics)
What You’ll Gain- Hands-on experience in real VAPT engagements
- Exposure to modern app architectures (AI + vibe coding stacks)
- Mentorship from experienced security engineers
- Opportunity to convert into a full-time cybersecurity role
- Build a strong portfolio with real vulnerability reports
How to ApplyShare:
- Your resume
- Any past projects / write-ups / bug bounty reports
- A short note on why you’re interested in cybersecurity
Ideal CandidateSomeone who:
- Loves breaking things (ethically)
- Thinks like an attacker, communicates like a consultant
- Is obsessed with finding “what can go wrong”
Join us in securing the next generation of rapidly built apps.
Click on Apply to know more.