Cybersecurity Intern
Oteria·France
Internship2025
Second placement, focused on web application security: reviewing applications, reproducing findings and turning them into reports someone could act on.
What I worked on
- Assessed web applications for common classes of vulnerability, working from an agreed scope and a written methodology
- Reproduced and documented findings with a clear impact statement and a minimal proof of concept
- Wrote remediation guidance aimed at the developers who would implement it, not at other security people
- Retested fixes and closed findings only once the underlying cause was addressed
- Contributed to internal tooling and checklists used across engagements
What I took away
- A finding is only worth what its report communicates. Severity without a reproducible path and a concrete impact gets deprioritised, and rightly so.
- Scope discipline matters more than technique. Knowing exactly where the boundary is, and stopping at it, is part of the job.
- The best remediation advice is written for the person who has to ship it, in the terms of their codebase.
- Most real-world issues are not exotic. They are authorisation checks that were never written.
Tools
- Burp Suite
- Caido
- OWASP ZAP
- ffuf
- Nmap
- SQLMap
- Wireshark
- Linux
- Git
How the team worked
- Recon and mapping before testing — understanding the application's own model of itself first
- Methodology checklists per class of vulnerability, so coverage is repeatable rather than intuitive
- Peer review of findings before they reached the client
- Structured reporting: impact, reproduction, evidence, remediation, references
Skills
- Web application security
- Vulnerability assessment
- Technical reporting
- Remediation guidance

