ePayPolicy→
SOC Analyst Intern at ePayPolicy in Austin, TX
InternshipHybridFull-timeAustin, TX
Skills
cybersecurityincident responsethreat huntingedr toolssiem logiccloud securitynetworking protocolsanalytical mindsettechnical curiositypassioncommunicationdocumentation
Job Description
Summary: ePayPolicy is a company that helps insurance companies streamline payment processes through modern tools. They are seeking a SOC Analyst Intern to support the defense of their environments by monitoring security threats, assisting in incident response, and participating in threat hunting activities.
Responsibilities:
- Monitor & Triage: Learn to actively monitor security alerts from our SIEM, EDR (CrowdStrike), and cloud environments (Azure) to identify potential threats
- Incident Response Support: Assist the team in the initial investigation of security incidents, including phishing attempts and malware alerts, following the Incident Response Lifecycle
- Defense Optimization: Participate in purple team exercises to validate endpoint configurations (CrowdStrike) and help verify that our detection logic effectively catches simulated attacks
- Threat Hunting: Learn proactive threat hunting techniques to search for undetected threats or indicators of compromise (IoCs) within our network
- Vulnerability Management: Assist in analyzing vulnerability scan results and coordinating with the IT Ops team to track remediation efforts
- Email Security: Help analyze suspicious emails reported by employees, review anti-phishing controls, and provide feedback to users
- Rule Tuning: Assist senior team members in tuning SIEM rules and EDR policies to reduce noise and filter out false positives
- Documentation: Maintain accurate records of investigations and incident response actions within our ticketing system, helping to build out our internal knowledge base (Playbooks)
Required Qualifications:
- A background in Computer Science, Cybersecurity, or Information Systems—whether you are currently pursuing a degree, possess equivalent self-taught skills, or are an IT professional looking to transition into security
- Basic familiarity with EDR concepts or tools (CrowdStrike, SentinelOne) and SIEM logic
- Understanding of Cloud Security basics (Microsoft Azure, Azure AD/Entra ID)
- Solid foundation in Networking protocols (TCP/IP, DNS, HTTP/S) and an interest in learning how to analyze packet captures or logs
- Ability to look at data and spot patterns or anomalies that don't look right
- Ability to communicate clearly and ask questions when you don't understand a concept—we value curiosity over knowing everything on day one
- A genuine interest in the cybersecurity landscape, staying current with the latest threat intelligence, CVEs, and attack vectors
Preferred Qualifications:
- Current pursuit of certifications such as CompTIA Security+, CySA+, or Azure Security Engineer Associate is a plus
Required Skills: Cybersecurity, Incident Response, Threat Hunting
Important Skills: EDR tools, SIEM logic, Cloud Security, Networking protocols
Nice-to-Have Skills: Analytical Mindset, Technical Curiosity, Passion, Communication, Documentation
Benefits: Company Holidays, In-office perks (Daily lunch stipend, access to the onsite gym, and two fully-stocked kitchens), Company provided laptop, Open invite to company-events, Company swag, Comprehensive benefits package with employer-paid basic life and disability premiums, 401K, Unlimited PTO, Company-sponsored quarterly “ePayItForward” initiatives, Fully-stocked kitchen, Lunch stipend when working onsite
Benefits
Company Holidays
In-office perks (Daily lunch stipend, access to the onsite gym, and two fully-stocked kitchens)
Company provided laptop
Open invite to company-events
Company swag
Comprehensive benefits package with employer-paid basic life and disability premiums
401K
Unlimited PTO
Company-sponsored quarterly “ePayItForward” initiatives
Fully-stocked kitchen
Lunch stipend when working onsite