426,218open jobs
14,385companies
62,717added this week
Browse all
Location
In office
Seniority
Intern
Employment
Internship
Overview
Company
Impact
Profile match
Sky Mavis is a blockchain gaming studio founded in 2018 and headquartered in Ho Chi Minh City. It created Axie Infinity, the game that popularised play-to-earn economics and reached millions of players in Southeast Asia. The company also operates the Ronin network, a gaming-focused chain that now hosts third-party titles.

About Sky Mavis

Sky Mavis is building the future of gaming. We’re the creators of Axie Infinity, the most successful Web3 game ever, and Ronin, a purpose-built blockchain that ranked as the 4th most-used chain in 2024, behind Ethereum, Bitcoin, and Solana.

We’ve processed over $4.3 billion in on-chain volume and are backed by more than $170 million from top-tier investors, including a16z, Accel, Libertus Capital, and Paradigm.

Our team moves fast, builds with intention, and believes in a world where players truly own what they earn. If you’re excited by open economies, massive scale, and shaping new digital frontiers, join us.

About the Role

We are replacing our commercial third-party security awareness training vendor with an in-house platform. This internship sits at the intersection of security operations and software delivery. You will own the security awareness training program end-to-end: designing the training content and quiz bank, building and deploying the platform that delivers it (the architecture and specifications are already fully documented, and you'll work with AI-assisted development tooling under senior guidance), and then running it as an operational security program - enrollments, completion tracking, and audit-ready reporting.

You'll leave with something few interns get: hands-on experience running a real security awareness program for a whole company, plus the platform you shipped to production to run it on.

What You’ll Do

Security awareness program (primary focus)

  • Design and author the security awareness training curriculum: modules and quiz banks covering phishing and social engineering, password and MFA hygiene, data handling and classification, secure remote work, and Web3-specific threats (wallet security, seed phrase protection, approval scams, fake dApps).

  • Map each training module to the compliance requirements it satisfies (SOC 2 CC1/CC2, ISO 27001 A.6.3 awareness controls) so auditors can trace evidence to controls.

  • Operate the training program day-to-day: enroll employees, configure module deadlines and renewal cycles, monitor completion rates, and chase stragglers with the People team.

  • Produce audit-ready reporting: completion evidence exports, on-chain verification links for auditors, and periodic metrics for the security team (completion %, average scores, weakest topics).

  • Use quiz analytics to find knowledge gaps and iterate on content - treat awareness as a measurable security control, not a checkbox.

  • Document program runbooks (onboarding a new hire, adding a module, annual renewal campaign, audit evidence collection) so the program survives beyond the internship.

Platform delivery (the tool you'll run the program on)

  • Implement the platform from the existing specification under senior review: Solidity contracts (completion tracker + soulbound certificate NFT), Express/TypeScript/PostgreSQL backend with server-side quiz scoring and signed attestations, and the React frontend (module player, quiz flow, dashboards, admin analytics, public certificate verification).

  • Test and harden it: contract tests (100% must pass), backend integration tests, and the project's mandatory security-audit and business-logic checks before every PR - zero Critical/High findings before deploy.

  • Deploy, then support.

What We Look For

  • Final-year student or recent graduate in Information Security, Computer Science, or a related field (or equivalent practical experience).

  • Solid security fundamentals: common attack vectors (phishing, social engineering, credential theft, malware delivery), basic OWASP Top 10 awareness, and why the human layer is a primary attack surface.

  • Genuine interest in security awareness and security operations: you can explain what makes training effective versus checkbox compliance, and you care about measuring behavior change, not just completions.

  • Familiarity with a compliance or control framework (SOC 2, ISO 27001, NIST CSF)

  • Working programming ability in TypeScript/JavaScript (Node.js, REST APIs, basic SQL, basic React) - enough to implement from a detailed specification with senior review and AI-assisted tooling. This is a build-and-operate role, not a research role.

  • Strong written communication: you will author training content and audit documentation that non-technical employees and external auditors will read.

  • Interest in Web3 security - wallet threats, on-chain verification - with motivation to learn Solidity basics quickly (prior experience not required).

  • Understanding of Git workflows (branching, pull requests, code review).

Nice to Have

  • Security research/hand-on or Blue CTF experience.

  • Prior exposure to an awareness training or phishing-simulation platform (e.g., KnowBe4, GoPhish) as an admin or content author.

  • Experience with SOC/security operations tooling, or contributing to audit evidence collection.

  • Exposure to Solidity, Hardhat, ethers.js, or any EVM chain (Ronin is a plus).

  • Experience creating instructional content (slides, videos, quizzes) or running internal campaigns.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
426,218 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Remote/Hybrid • 7+ years exp
Python
JavaScript
Java
TypeScript
C#
C#
.NET
Frontend
Angular
React.js
DevOps
Rest API
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
QA
Swagger
Robot Framework
Apply
$150k – $165k per year • In office • 10+ years exp • Bachelor's Degree
SQL
Databases
Snowflake
Oracle
Analytics
Tableau
Power BI
Microsoft Excel
Apply
In office • Bachelor's Degree
SQL
Analytics
Power BI
Apply
Copilot AI Engineer 9 hours ago
Remote/Hybrid • 4+ years exp
Python
JavaScript
C#
C#
.NET
AI/ML
LangChain
Prompt Engineering
AI Agents
LLM
OpenAI
Hugging Face
Frontend
React.js
Apply
Senior AI Engineer 9 hours ago
Remote/Hybrid • 9+ years exp
Python
JavaScript
C#
C#
.NET
AI/ML
LangChain
Prompt Engineering
AI Agents
LLM
OpenAI
Hugging Face
Frontend
React.js
Apply
In office • Full-Time • 3+ years exp • Bachelor's Degree
Apply
In office • Full-Time • 2+ years exp • Bachelor's Degree
Python
DevOps
Terraform
Web3
Solana
Ronin
Bitcoin
Ethereum
Apply
Web3 Security Engineer 6 months ago
In office • Full-Time • 2+ years exp • Master's Degree
Python
Go
Solidity
Go
Chi
Cybersecurity
Threat Modeling
Web3
Solana
Ronin
Bitcoin
Smart Contracts
Ethereum
Apply
See all jobs
This is one of many
426,218 more open roles from verified company boards, updated every day.