About the job
CONTEXT
The Cybersecurity (CYB) practice at Wavestone collaborates with leading enterprises to identify the real risks they encounter: loss of sensitive information, disruption or interruption of operations due to an attack, damage to brand reputation, etc. The security audits conducted aim to develop pragmatic action plans to enhance the security level of these companies' information systems in the short and medium term.
These audits can take various forms, including penetration testing, architecture reviews, configuration or code assessments, as well as organizational audits. We also employ less conventional approaches such as social engineering simulations, physical on-site intrusions, and Red and Purple Team audits.
The scope and technologies covered within the practice are diverse and require specific expertise and appropriate tools, some of which are developed in-house. All aspects of the information system are addressed by the audits conducted by CYB: desktop and mobile applications, virtual or containerized environments, wireless communication protocols (Bluetooth, Wi-Fi, NFC...), embedded systems and IoT, Big Data technologies (Hadoop...), etc.
INTERNSHIP OBJECTIVE
The objective of this internship is to advance and expand Wavestone's expertise in security audits by developing new skills, techniques, and attack methodologies.
ASSIGNED TASKS
Under the guidance of a consultant and the management of a team lead, the intern or apprentice may be tasked with executing part or all of the following:
- Development of exploit code (reverse engineering of patches, vulnerability POCs, etc.);
- Creation of attack tools and vulnerability research tools (plugins and modules for public and private tools);
- Updating methodologies to account for the latest threats and attack vectors;
- Enhancing technical expertise and approaches to address new topics and components (container escape, data exfiltration, etc.).

