Skip to content
Z3tra

Experience

Where I have worked

Two internships, both at Oteria. Written as what I actually did rather than what the job description said.

Cybersecurity Intern

Oteria·France

Internship2025

Second placement, focused on web application security: reviewing applications, reproducing findings and turning them into reports someone could act on.

What I worked on

  • Assessed web applications for common classes of vulnerability, working from an agreed scope and a written methodology
  • Reproduced and documented findings with a clear impact statement and a minimal proof of concept
  • Wrote remediation guidance aimed at the developers who would implement it, not at other security people
  • Retested fixes and closed findings only once the underlying cause was addressed
  • Contributed to internal tooling and checklists used across engagements

What I took away

  • A finding is only worth what its report communicates. Severity without a reproducible path and a concrete impact gets deprioritised, and rightly so.
  • Scope discipline matters more than technique. Knowing exactly where the boundary is, and stopping at it, is part of the job.
  • The best remediation advice is written for the person who has to ship it, in the terms of their codebase.
  • Most real-world issues are not exotic. They are authorisation checks that were never written.

Tools

  • Burp Suite
  • Caido
  • OWASP ZAP
  • ffuf
  • Nmap
  • SQLMap
  • Wireshark
  • Linux
  • Git

How the team worked

  • Recon and mapping before testing — understanding the application's own model of itself first
  • Methodology checklists per class of vulnerability, so coverage is repeatable rather than intuitive
  • Peer review of findings before they reached the client
  • Structured reporting: impact, reproduction, evidence, remediation, references

Skills

  • Web application security
  • Vulnerability assessment
  • Technical reporting
  • Remediation guidance

Cybersecurity Intern

Oteria·France

Internship2024

First placement. Broad exposure: how a security team actually operates day to day, and how the work is organised before anyone touches a tool.

What I worked on

  • Supported assessments by handling reconnaissance and information gathering within scope
  • Set up and maintained lab environments used to reproduce issues safely
  • Reviewed configurations against hardening baselines and documented the gaps
  • Kept internal documentation current as procedures changed

What I took away

  • Security work is mostly method. The tools are the least interesting part of the day.
  • Being able to explain what you did — and why you stopped where you stopped — matters as much as the result.
  • Reproducibility is not optional. If it only worked once, on your machine, it did not happen.
  • Asking a question early is cheaper than a wrong assumption discovered late.

Tools

  • Burp Suite
  • Nmap
  • Gobuster
  • Docker
  • Linux
  • Git

How the team worked

  • Weekly planning with clear ownership of each task
  • Documented procedures for anything performed more than once
  • Reviews before anything left the team

Skills

  • Reconnaissance
  • Lab environments
  • Configuration review
  • Documentation

Looking for the next one

Looking for an apprenticeship in application security, starting September 2026.

Get in touch →

The rest of the picture

Internships are one part of it. The projects, the lab and the write-ups are where most of the learning actually happened.