Responsibilities
The InfoSec & GRC Intern will help strengthen the security posture of SIG’s software ecosystem. You will assist in reviewing SAST/SCA scan results, evaluating exceptions to standards, preparing audit evidence, supporting risk assessments, and maintaining security policies and documentation. This role provides exposure to both Application Security (AppSec) and Governance, Risk & Compliance (GRC) duties, supporting our secure‑by‑design engineering program.
Responsibilities and competency expectations reflect activities seen across leading GRC and AppSec internship roles in industry.
Application Security
- Review and triage static (SAST) and software composition analysis (SCA) scan findings, validating issues and collaborating with development teams on remediation.
- Participate in secure design discussions and support application security proof‑of‑concept evaluations under the guidance of senior AppSec engineers.
- Assist in enhancing SDLC security activities and tracking vulnerability remediation progress.
Governance, Risk & Compliance
- Help maintain and update security policies, standards, and procedural documentation.
- Review and help process exceptions to security standards, ensuring risks are documented and mitigation actions are captured. (Based on GRC documentation and policy support responsibilities.)
Audit & Certification Support
- Assist in internal and external audit preparation, collecting evidence to demonstrate control effectiveness.
- Support compliance activities for frameworks such as ISO 27001, ISO9001, ISO42001, SOC2, etc. including documentation gathering and follow‑ups on mitigation actions.
Education / Qualifications
- Currently pursuing a degree in Cybersecurity, Computer Science, Information Security, or related field.
- Strong written and verbal communication skills, with the ability to collaborate across cross‑functional teams
- Organized with strong attention to detail and ability to manage multiple tasks simultaneously.
Preferred Qualifications
- Foundational understanding of information security principles, compliance frameworks (ISO 27001, SOC 2, NIST CSF), and risk management concepts.
- Familiarity with SAST/SCA tools (e.g., GitHub Advanced Security, Snyk, Checkmarx).
- Basic scripting or automation experience (Python, PowerShell, or similar).
- Understanding of OWASP Top 10, secure coding practices, or common application vulnerabilities.
What You Will Gain
- Real‑world experience working with application security and GRC programs at scale.
- Exposure to secure‑by‑design engineering workflows, risk assessments, and enterprise assurance programs.
- Mentorship from senior Information Security, Compliance, and AppSec professionals.
- Experience supporting audit readiness, vulnerability management, and policy governance across a global product portfolio.
#LI-PB1
#LI-Remote
About Octave
Octave provides mission-critical software that empowers organizations to make informed decisions across every stage of the asset lifecycle - Design, Build, Operate and Protect - where performance, safety, and reliability are non-negotiable and failure is not an option.
Turning complex operational data into actionable intelligence, Octave connects expertise, real-world conditions and enterprise-scale insight to improve performance, resilience and incident response where it matters most.
Octave has more than 7,000 employees in 45 countries. Learn more at octave.com and follow us on LinkedIn.
Why work for Octave?
All in. Always forward. That's the way we do things around here. We put trust in our people because we believe it's the best way to unleash potential, bring ideas to life, and keep moving ahead. And it's why we're committed to creating an environment that's truly supportive, providing you with the resources you need to support your ambitions, no matter who you are or where you are in the world.
Everyone is welcome
At Octave, we believe that diverse and inclusive teams are critical to the success of our people and our business. Here, everyone is welcome. As an inclusive workplace, we don't discriminate. In fact, we embrace differences and are fully committed to creating equal opportunities, an inclusive environment, and fairness for all.
Respect is the cornerstone of how we operate, so speak up and be yourself. You're valued here.