- This internship is for the Winter Term: January 4 - April 30, 2027
- As a Software Engineer Intern on our Security team, you’ll get hands-on experience keeping Super.com’s products secure across the software lifecycle
- Your work spans offense and defense: building security tooling and proofs of concept (with AI), triaging findings from our security tools, and doing offensive testing to find issues before attackers do
- You don’t need to be an expert; this is a learning role where you’ll build real AppSec and DevSecOps skills on a team that ships
- You’ll report to our Staff Software Engineer - Security and work closely with product engineers, DevOps, and Fraud
- Expect frequent collaboration, mentorship, and a fast pace, with real ownership of the projects you take on
- You’ll ship meaningful security work during your internship
- Help add security tooling and checks to our CI/CD pipelines
- Build and improve security tooling by writing scripts and automation (primarily Python)
- Use AI to help with day-to-day security work
- Do offensive testing to find vulnerabilities in our products and build proofs of concept
- Help triage security findings and patch the straightforward ones, like SCA version bumps
- Work with engineers, DevOps, and Fraud, learning how security fits into how we build and ship
- Services are authored as K8s-based microservices powered by Python FastAPI backends and Typescript React front-end code
- Apps are built upon Postgres, Redis, Kafka, Elasticsearch, and Snowflake
- Our infrastructure runs on AWS and leverages hosted infrastructure technologies such as EKS, MSK, Elasticache, and RDS. We use Istio for service mesh, Helm, TF and Crossplane for IAC, and Kyverno for policy-as-code enforcement
- Security and application logs/metrics/events are managed through Datadog
- As an AI-First engineering organization,
we leverage modern AI development workflows using tools such as Cursor, Claude, and internally built AI agents to accelerate implementation and iteration across our codebases. You’ll own and advance our AI infrastructure in this role
Benefits
- Competitive base salary
- Yearly learning & development allowance
- Bi-annual performance &
compensation reviews
- Generous equity options
- RRSP & 401k employee contribution plan
- Health, dental, & vision insurance on day one
- Parental leave programs
- Wellness reimbursement
- Supplemental Life Insurance
- Unlimited PTO (yes, really!)
- Recharge days throughout the year
- Office in Toronto
- Permanent remote flexibility
- Work-from-home allowance- Comfortable in a fast-paced environment, with curiosity and a solid willingness to learn
- Strong communicator who can work across engineering, DevOps, and other teams
- Some hands-on experience finding vulnerabilities through CTFs, labs, or coursework
- Currently pursuing a degree in Computer Science, Cybersecurity, or a related field (or equivalent experience)
- Solid programming fundamentals (Python preferred)
- Genuine interest in application and infrastructure security, with some familiarity with the OWASP Top 10 and common vulnerability classes
- Familiarity with web technologies and networking fundamentals (e.g., HTTP, REST APIs, TLS, DNS)
- Relevant security certifications (e.g., Security+, eJPT, PJPT, or similar)
- Previous security or software engineering internship experience
- Success in Bug Bounty programs, CTF competitions, or similar
- Exposure to cloud or cloud security (AWS and/or Kubernetes preferred)
- Interest in using AI/LLMs to support security or engineering work
- Exposure to mobile development or mobile security
- Independent projects visible on GitHub- Deadline to Apply September 17, 2026 at 6:59 AM UTC
📌 Software Engineering Intern (Security) (Canada)
🏢 super
📍 Canada