Avatar for SourceIQ
SourceIQ
Actively Hiring
SourceIQ is a cloud-based platform that automates supplier management and sourcing
  • Top 10% of responders
    SourceIQ is in the top 10% of companies in terms of response time to applications
  • Responds within two weeks
    Based on past data, SourceIQ usually responds to incoming applications within two weeks
  • B2B
  • +1

Security Analyst Intern (Cybersecurity, Governance, Risk & Compliance)

Posted: 2 weeks ago• Recruiter recently active
Remote Work Policy

Remote only

Company Location
Visa Sponsorship

Not Available

Preferred Timezones
Central Time, Eastern Time
Collaboration Hours
8:00 AM - 5:00 PM Central Time
RelocationNot Allowed
Skills
Cloud Computing
Information Security
Cyber Security
Network Security
Security
Services
Cybersecurity
Azure
Monitoring
Microsoft Azure
SAML
SOC2
GDPR
RBAC
CSA
GDPR Compliance
MFA
Entra ID
Strong Experience in ITGCs, ITACs, SOC1/SOC2s, and SOX Requirements Specific to IT En

About the job

Company: SourceIQ
Location: Remote
Duration: 3–6 months (with potential for conversion to full-time)
Compensation: *Unpaid (Academic credit available)
*
Start Date:
Flexible (Rolling applications)

About SourceIQ

SourceIQ is an AI-powered supplier management and sourcing platform transforming how enterprises discover, evaluate, onboard, and collaborate with suppliers. We automate compliance, analytics, and sourcing workflows from end to end, helping companies streamline procurement operations.
We're building the infrastructure layer for enterprise procurement—a platform designed to consolidate a fragmented $50B market by becoming the centralized intelligence and data layer that integrates with all procurement tools.

As we expand into enterprise markets, security, privacy, compliance, and risk management are becoming core pillars of our product strategy. Our CISO Advisory Board actively reviews our platform, architecture, controls, and compliance roadmap to ensure SourceIQ meets enterprise security expectations.

The Role

As a Security Analyst Intern, you'll work directly with SourceIQ leadership, engineering teams, and our CISO Advisory Board to strengthen the company's security posture, compliance readiness, and enterprise security program.
This is a highly hands-on internship where you'll help build the security foundations required to support enterprise customers, security assessments, procurement reviews, SOC 2 readiness, and future compliance initiatives.

You'll contribute to real-world security projects including data classification, security documentation, RBAC design, privacy assessments, identity management reviews, API security analysis, cloud security controls, and enterprise security packaging.

This role is ideal for students interested in:

  • Cybersecurity
  • Governance, Risk & Compliance (GRC)
  • Security Operations
  • Cloud Security
  • Identity & Access Management
  • Enterprise Security Architecture
  • Privacy & Regulatory Compliance

You'll work closely with the Head of Technology, Product Team, Engineering Team, and members of our CISO Advisory Board.

What You'll Do

Security Governance & Risk Management (Primary Focus)

  • Assist with maintaining the SourceIQ CISO Board Security Readiness Checklist
  • Track security initiatives and remediation efforts across departments
  • Participate in biweekly security review meetings and document action items
  • Help identify security risks and assess mitigation options
  • Maintain security registers, audit logs, and security documentation repositories
  • Support risk assessment and risk management processes

Data Classification & Privacy

  • Catalog and classify data elements across the SourceIQ platform
  • Assist in creating and maintaining the Data Classification Matrix
  • Identify PII, confidential business data, and regulated information
  • Review data collection practices against GDPR and privacy requirements
  • Document business justification for collected supplier and user data
  • Help define retention, deletion, and data handling requirements
  • Assist with privacy impact assessments

Identity & Access Management (IAM)

  • Support RBAC design and documentation efforts
  • Help define user personas and permission models
  • Review least-privilege access requirements
  • Assist with multi-tenant access control validation
  • Evaluate authentication processes including SSO, MFA, and passwordless options
  • Support identity provider integrations such as Microsoft Entra ID and Okta

Security Documentation & Compliance

Help create and maintain:

  • Security Overview Documents
  • Data Flow Diagrams
  • Architecture Diagrams
  • Incident Response Plans
  • Business Continuity Plans
  • Disaster Recovery Documentation
  • Shared Responsibility Matrices
  • Security Questionnaires
  • Assist with customer security reviews and vendor assessments
  • Support the development of enterprise security packages
  • Help maintain security policies and standards

Cloud & Application Security

  • Review Azure inherited and customer-managed controls
  • Assist with Shared Responsibility Model documentation
  • Support API security reviews and documentation efforts
  • Participate in security architecture discussions
  • Review encryption, authentication, and authorization practices
  • Assist in vulnerability management tracking and remediation verification
  • Help perform security control gap assessments

Cloud & Application Security

  • Review Azure inherited and customer-managed controls
  • Assist with Shared Responsibility Model documentation
  • Support API security reviews and documentation efforts
  • Participate in security architecture discussions
  • Review encryption, authentication, and authorization practices
  • Assist in vulnerability management tracking and remediation verification
  • Help perform security control gap assessments

Collaboration & Process

  • Follow Jira tasks and sprint cycles
  • Participate in weekly security and engineering meetings
  • Collaborate with engineering, product, and leadership teams
  • Present findings and recommendations clearly
  • Use AI-powered tools such as Microsoft Copilot, GitHub Copilot, and ChatGPT responsibly for research and documentation

Required Qualifications

Technical & Security Skills (Must Have)

✅ Currently pursuing a degree in Cybersecurity, Information Security, Computer Science, Information Systems, Risk Management, or a related field
✅ Fundamental understanding of cybersecurity principles
✅ Knowledge of security concepts such as:

  • Authentication
  • Authorization
  • Encryption
  • MFA
  • RBAC
  • Network Security
  • Secure Data Handling

✅ Familiarity with Microsoft Azure or other cloud platforms
✅ Understanding of common compliance frameworks and standards
✅ Strong documentation and analytical skills
✅ Experience using Microsoft Office, Google Workspace, or similar tools
✅ Comfortable learning and utilizing AI-assisted productivity tools

Nice to Have

  • Familiarity with SOC 2, ISO 27001, NIST CSF, CIS Controls, or CSA STAR
  • Experience with Microsoft Entra ID
  • Understanding of GDPR and privacy regulations
  • Knowledge of cloud security concepts
  • Experience with Azure Security Center / Microsoft Defender
  • Exposure to vulnerability management processes
  • Familiarity with penetration testing concepts
  • Experience completing security questionnaires
  • Knowledge of API security best practices
  • Previous participation in cybersecurity clubs, labs, competitions, or internships

What You'll Learn

Security & Compliance

  • Enterprise security program development
  • SOC 2 readiness and audit preparation
  • Security governance and risk management
  • Privacy and data protection strategies
  • Regulatory compliance fundamentals

Cloud Security

  • Azure security architecture
  • Shared responsibility models
  • Cloud security controls and monitoring
  • Identity and access management
  • Enterprise authentication strategies

Application Requirements

Please submit the following:

Resume/CV highlighting cybersecurity, security, compliance, or technology experience
LinkedIn profile
Any cybersecurity projects, labs, CTFs, or security-related coursework
Brief cover letter (200–300 words) answering:

Why are you interested in cybersecurity?
What area of security interests you most?
Describe a security challenge or project you've worked on.

About the company

SourceIQ company logo

SourceIQ

Actively Hiring
SourceIQ is a cloud-based platform that automates supplier management and sourcing11-50 Employees
Company Size
11-50
Company Type
Technology Provider
Company Type
Artificial Intelligence
Company Type
Enterprise Software Company
Company Type
Marketplace
Company Type
Small And Medium Business
Company Industries
Artificial Intelligence / Machine Learning
  • Top 10% of responders
    SourceIQ is in the top 10% of companies in terms of response time to applications
  • Responds within two weeks
    Based on past data, SourceIQ usually responds to incoming applications within two weeks
  • B2B
  • Early Stage
    Startup in initial stages
Learn more about SourceIQ image

Similar Jobs

Archesys company logo
Archesys
Improving the government services that impact everyday lives