VGS
VGS

Application Security Intern

$20 per hour

TLDR

Contribute to application security by partnering with engineers to evaluate application risks and improve secure development practices within a flexible work environment.

What you will be doing at VGS…
  • Support application security reviews for services, APIs, and new product features across the VGS platform.

  • Help identify, validate, and track security findings from static analysis, dependency scanning, container scanning, and other security testing tools.

  • Participate in threat modeling and secure design discussions with engineering teams during feature development.

  • Help evaluate the security of AI-enabled development workflows, including internal AI systems integrated into the SDLC, by thinking like both an attacker and a defender to identify risks and improve guardrails.

  • Assist with manual testing and validation of web application and API security issues, including access control, authentication, input validation, and secrets handling.

  • Help improve secure SDLC processes by contributing to developer guidance, secure coding resources, and repeatable review checklists.

  • Work with engineers to understand remediation options and clearly document security risks and recommendations.

  • Contribute to improving security tooling and guardrails in CI/CD and development workflows.

  • Be proactive and innovative; we rely on your feedback to help build a world-class product securely.

  • Be a part of a team that believes in transparency, collaboration, grit, and humility, and in doing the right thing for our customers and the company.

  • What we are looking for from you (Requirements)…
  • Currently pursuing a degree in Computer Science, Cybersecurity, Software Engineering, or a related field, or have equivalent practical experience.

  • Foundational understanding of application security concepts such as the OWASP Top 10, API security, authentication and authorization, secure coding, and common software vulnerabilities.

  • Ability to read and reason about code in one or more programming languages such as Java, Python, JavaScript, or Go.

  • Familiarity with Git, the software development lifecycle, and basic testing or debugging workflows.

  • Strong interest in secure software design, cloud-native architectures, and automation.

  • Strong written and verbal communication skills, with the ability to explain technical issues clearly to both security and engineering stakeholders.

  • Curious, collaborative, and excited to learn how security can enable developers rather than slow them down.

  • Bonus points if you have exposure to LLMs, threat modeling, Burp Suite, SAST/DAST tools, CI/CD pipelines, Docker/Kubernetes, or cloud environments.

  • At VGS, we have a remote-first philosophy because we believe flexibility leads to great work and a healthy work-life balance. That said, if you live within 30 miles of one of our office locations, you’ll be on a hybrid schedule with some in-person time, because we know there’s real value in coming together.
     
    We’re not about being in the office every day, but we are about connection, collaboration, and the energy that comes from a great brainstorm, a team lunch, or celebrating a big win in person.
     
    We consider applicants without regard to race, color, national origin, sex, age, religion, sexual orientation, gender identity, veteran status, marital status, physical or mental disability, or other protected classes under all local, state, and federal laws and ordinances (AA/EOE/W/M/Vet/Disabled).
     
    Qualified applicants with arrest and conviction records will be considered for the position in accordance with the San Francisco Fair Chance Ordinance.
     
    Visa Sponsorship. The Company does not provide visa sponsorship for this role. Candidates must be legally authorized to work in the United States at the time of hire and throughout their employment. Individuals with temporary visas such as E, F-1 (including those with OPT or CPT), H-1, H-2, L-1, B, J, or TN, or who need sponsorship for work authorization now or in the future, are not eligible.
     
    Please note we are currently only hiring in the following states...
     
    California, Colorado, Connecticut, Florida, Illinois, New York, North Carolina, Oregon, Texas, Virginia, and Washington

    VGS provides payment tokenization solutions that simplify how businesses handle sensitive payment data. By offering processor-agnostic services and universal token vaults, we empower banks and merchants to efficiently manage complexities and ensure compliance in their payment processes.

    View company profile
    Report this job
    Apply for this job