CloudSEK Security Consultant Intern 2026 hiring in Bengaluru
CloudSEK is hiring a Security Consultant Intern in Bengaluru, and this one is for the students who already tinker with security in their spare time. The role sits at the intersection of threat intelligence, security consulting and product strategy, and the work is hands-on from day one: VAPT, dark web monitoring, and turning findings into reports that reach real clients. This post breaks down what the intern actually does, who CloudSEK will consider, and the skills the listing names. It is all taken from the official CloudSEK listing on its Greenhouse board, with nothing added.
Context on the company, since it shapes the work. CloudSEK is an Indian cybersecurity product company that builds AI-driven threat detection, with products like XVigil, BeVigil, SVigil and AIVigil. As an intern you would work directly on findings that flow out of those platforms.
What a Security Consultant Intern does here
The listing is unusually specific about the day to day, and it spans testing, intelligence and client work.
- Perform VAPT across web, API, mobile and cloud, and triage findings from BeVigil and SVigil into concrete, prioritized issues.
- Track how the threat scene is shifting and monitor underground and dark web feeds, flagging relevant chatter, leaks or actor activity.
- Run OSINT and HUMINT collection, infrastructure hunting and C2 mapping.
- Research exposed credentials, misconfigurations and leaked assets, then judge whether each is a real risk or a harmless placeholder.
- Help build client-facing deliverables: trial summaries, responsible disclosure reports and CISO-ready impact summaries.
- Present findings on calls with prospects, turning technical detail into business impact.
Read that mix and one thing stands out. This is not a pure testing seat. You would test, but you would also write up findings and talk about them on live calls, so communication carries as much weight as the hacking.
Who CloudSEK will consider
The requirements are skills-first, with one education line.
- Currently pursuing or recently completed a degree in Computer Science, Information Security or a related field.
- A strong interest in cybersecurity, threat intelligence or security research.
- Working knowledge of VAPT methodology across at least two of web, API, mobile or cloud.
- Familiarity with core concepts: CVEs, IOCs, TTPs, exposed credentials, attack surface management, OSINT and HUMINT.
A BCA, B.Sc IT, B.Tech or MCA student fits the degree line. The pursuing or recently completed wording means both final-year students and fresh graduates are in scope. What CloudSEK clearly wants is someone who can already run a basic VAPT and reason about findings, not learn it from scratch.
The nice-to-haves that help
CloudSEK lists extras that would strengthen an application. If you have any of these, put them on your resume for this role.
- Prior CTF, bug bounty or independent security research experience.
- Experience with dark web or underground forum monitoring, C2 infrastructure mapping or threat actor tracking.
- Exposure to digital risk protection or supply chain risk concepts.
- An interest in how security products get positioned and sold, not just built.
The CTF and bug bounty line is the one to note. If you have a profile on a bug bounty platform or CTF wins, that is direct evidence of exactly what this role wants.
What you would gain
The listing is upfront about the return, and it reads as more than a certificate.
- Direct mentorship from CloudSEK's security consulting and research team.
- Real client and prospect exposure, not simulated exercises.
- An end-to-end view of how a research finding becomes a report, a sales conversation or a product feature.
What the listing does not say
Some practical fields are missing, and guessing them would not be fair.
- No stipend figure. The page carries no pay or stipend line, so the salary reads as not disclosed by the company.
- No internship duration. The page does not say how many months it runs.
- No batch year and no seat count. Nothing on the page rules a graduation year in or out.
Where CloudSEK sits, in numbers
The listing carries a fair amount about the company, and it is worth reading because it tells you what your work would support. CloudSEK was founded in 2015 and is headquartered in Singapore, with operations across India, Southeast Asia and the Americas. On the page it lists a $7M Series A in 2021 led by MassMutual Ventures and $19M raised in 2025 led by Tenacity Ventures and Commvault, alongside a NASSCOM-DSCI Security Product Company of the Year award and a place in the NVIDIA Inception programme.
The takeaway for an intern is that the threat intelligence you would work on feeds live, funded products with real customers. One detail to flag from the responsibilities: the role tracks threats across the Americas, so expect exposure to global threat feeds, not only India-based activity.
How to apply for the CloudSEK internship 2026
The application runs on CloudSEK's own Greenhouse board. Since the role is skills-led, the strongest thing you can bring is proof of hands-on security work: a CTF profile, a bug bounty report, or a write-up of something you found and disclosed. Line those up before you apply, and use the official link below.
Source: the responsibilities and skills above come from CloudSEK's official Security Consultant Intern listing. Apply on the official CloudSEK careers board.