PatientPoint®→
Application Security Analyst Intern at PatientPoint® in Remote
InternshipRemoteFull-timeRemote$52k–$54k/yr
Skills
application security testingsecure code reviewthreat modelingsast/dast toolsprogramming/scripting languageweb technologieswillingness to learnproblem-solving skillsattention to detail
Job Description
Summary: PatientPoint is a leading digital health company focused on improving patient behaviors and health outcomes. The Application Security Analyst Intern will support application security efforts through testing, secure code reviews, threat modeling, and vulnerability research while collaborating with engineers to promote secure coding practices.
Responsibilities:
- Assist in performing static (SAST) and dynamic (DAST) application security testing
- Help triage findings from automated scanners
- Participate in manual testing (under guidance) for common vulnerabilities such as SQL injection, XSS, or broken authentication
- Review code changes for security issues (often with senior mentorship)
- Learn to use tools like SonarQube, Checkmarx, Fortify, or GitHub Advanced Security
- Document findings and recommend secure coding practices
- Support threat modeling exercises by documenting potential attack paths
- Research emerging vulnerabilities, CVEs, and security advisories relevant to the tech stack
- Track security trends and update the team
- Help integrate security tools into the CI/CD pipeline
- Write scripts for automating repetitive tasks (e.g., log parsing, results consolidation)
- Support vulnerability management platforms (e.g., Jira, DefectDojo, Kenna)
- Draft and maintain internal documentation for secure coding guidelines
- Assist in preparing developer training materials (e.g., OWASP Top 10 examples)
- Work with engineers to clarify security requirements during development
- Exposure to OWASP Top 10 and CWE/SANS Top 25
- Mentorship in real-world vulnerability assessment and remediation
- Understanding how security integrates with agile/DevOps workflows
Required Qualifications:
- Currently pursuing a Bachelor's or Master's degree in Computer Science, Data Science, Cybersecurity, Information Technology, or a related field
- Basic understanding of application security concepts (OWASP Top 10, common web vulnerabilities)
- Familiarity with at least one programming or scripting language (Python, JavaScript, Java, or similar)
- Understanding of web technologies (HTTP/S, REST APIs, JSON, authentication mechanisms)
- Ability to analyze security findings and communicate risks clearly
- Strong problem-solving skills and attention to detail
- Willingness to learn secure coding practices and security testing tools
Preferred Qualifications:
- Exposure to SAST, DAST, or SCA tools (e.g., Checkmarx, ZAP, Burp Suite)
- Familiarity with Git, GitHub, or CI/CD pipelines
- Knowledge of secure SDLC principles
- Understanding of AI skills
Required Skills: Application Security Testing, Secure Code Review, Threat Modeling
Important Skills: SAST/DAST Tools, Programming/Scripting Language, Web Technologies
Nice-to-Have Skills: Willingness to Learn, Problem-Solving Skills, Attention to Detail
Benefits: Flexible time off to recharge, Hybrid work options, Mental and emotional wellness resources, A 401K plan, Competitive compensation
Benefits
Flexible time off to recharge
Hybrid work options
Mental and emotional wellness resources
A 401K plan
Competitive compensation