Security Engineering Intern Red Team
Coinhako is a Singapore-based, MAS-regulated cryptocurrency trading platform. It lets users buy, sell, convert, and manage digital assets, and offers institutional services including custody and high-volume trading.
Funding
About Coinhako
Coinhako operates a cryptocurrency exchange and digital-asset platform in Singapore. Its products let users create accounts, fund them via PayNow or FAST bank transfer, and buy, sell, convert, and manage more than 200 cryptocurrencies. The company emphasizes security, regulatory compliance, and an intuitive experience for users at different experience levels. It also provides institutional services, including custody and high-volume trading solutions.
Skills
About the Role
You will conduct offensive security engagements across web, mobile, API, microservice, cloud, and internal-system surfaces. You will assess application security, perform penetration tests, and examine critical attack paths including authentication, wallet and key-management flows, transaction integrity, withdrawals, KYC, business logic, and privilege escalation. You will manually review production code to identify vulnerabilities, research emerging Web3, mobile, and cloud threats, and turn findings into proactive testing methods. You will also write scripts, automate offensive workflows, and build frameworks that expand red-team coverage.
Requirements
- Final-year university student pursuing a degree focused on Computer Science, Information Systems, or Engineering
- Knowledge of offensive security, penetration testing, or red teaming, with hands-on web and mobile application security experience through CTF competitions or bug bounty engagements
- Strong fundamentals in offensive security, application security, and security engineering
- Familiarity with Linux and cloud ecosystems, especially AWS
- Proficiency with Burp Suite, intercepting proxies, fuzzers, and pentesting tools
- Working knowledge of OWASP Top 10, ASVS, MASVS, CWE, and modern application-security frameworks
- Ability to script and automate in Python, Go, or similar languages
- Outstanding written and verbal English communication
- Advanced understanding or experience in cryptocurrency, blockchain, fintech, or finance trading is preferred
Responsibilities
- Conduct offensive security engagements across web, mobile, API, microservice, cloud, and internal-system surfaces
- Perform application security assessments and penetration tests
- Assess authentication, session handling, wallet and key-management flows, transaction integrity, withdrawals, KYC, business logic, and privilege escalation
- Conduct manual secure code reviews of production codebases
- Research emerging Web3, mobile, and cloud threats and translate them into proactive testing methodologies
- Write scripts, automate offensive workflows, and create frameworks to scale red-team coverage
Benefits
- Hands-on experience across multiple cybersecurity domains
- Mentorship from experienced security professionals
- Exposure to enterprise-grade security tools and technologies
- Opportunity to participate in real security operations and projects
- Flexible schedule to accommodate academic commitments
