
As a Security Operations Intern at Sky Mavis, you will own the design, delivery, and operations of a new in-house security awareness training program for the company. You'll work at the intersection of security operations and software delivery: you'll author training curriculum and quiz content, build and deploy a full-stack platform (Solidity smart contracts, Express/TypeScript/PostgreSQL backend, React frontend) to deliver it, and then run the program day-to-day with audit-ready reporting. You leave with hands-on experience running a real security program for a company at scale and the platform you shipped to production.
What you'll do
- Design and author security awareness training curriculum covering phishing and social engineering, password and MFA hygiene, data handling and classification, secure remote work, and Web3-specific threats such as wallet security, seed phrase protection, approval scams, and fake dApps.
- Map each training module to compliance requirements it satisfies (SOC 2 CC1/CC2, ISO 27001 A.6.3 awareness controls) so auditors can trace evidence to controls.
- Operate the training program day-to-day: enroll employees, configure module deadlines and renewal cycles, monitor completion rates, and coordinate with the People team to chase stragglers.
- Produce audit-ready reporting including completion evidence exports, on-chain verification links for auditors, and periodic metrics for the security team (completion %, average scores, weakest topics).
- Use quiz analytics to identify knowledge gaps and iterate on training content, treating awareness as a measurable security control.
- Document program runbooks (onboarding a new hire, adding a module, annual renewal campaign, audit evidence collection) to ensure the program is sustainable beyond the internship.
- Implement the training platform from an existing specification under senior review: Solidity contracts for completion tracking and a soulbound certificate NFT, an Express/TypeScript/PostgreSQL backend with server-side quiz scoring and signed attestations, and a React frontend for the module player, quiz flow, dashboards, admin analytics, and public certificate verification.
- Test and harden the platform: run contract tests (100% must pass), backend integration tests, and the mandatory security-audit and business-logic checks before every PR to ensure zero Critical/High findings before deploy.
- Deploy the platform and provide ongoing support.
What you bring
- You are a final-year student or recent graduate in Information Security, Computer Science, or a related field, or you have equivalent practical experience.
- Solid security fundamentals: understanding of common attack vectors (phishing, social engineering, credential theft, malware delivery), basic OWASP Top 10 awareness, and recognition that the human layer is a primary attack surface.
- Genuine interest in security awareness and security operations: you can distinguish effective training from checkbox compliance and care about measuring behavior change, not just completion rates.
- Familiarity with a compliance or control framework (SOC 2, ISO 27001, NIST CSF).
- Working programming ability in TypeScript/JavaScript (Node.js, REST APIs, basic SQL, basic React) sufficient to implement from a detailed specification with senior review and AI-assisted development tooling.
- Strong written communication skills: you will author training content and audit documentation that non-technical employees and external auditors will read.
- Interest in Web3 security including wallet threats and on-chain verification, with motivation to learn Solidity basics quickly (prior experience not required).
- Understanding of Git workflows (branching, pull requests, code review).
Nice to have
- Security research experience or hands-on or Blue CTF experience.
- Prior exposure to an awareness training or phishing-simulation platform such as KnowBe4 or GoPhish as an admin or content author.
- Experience with SOC/security operations tooling or contributing to audit evidence collection.
- Exposure to Solidity, Hardhat, ethers.js, or any EVM chain (Ronin is a plus).
- Experience creating instructional content such as slides, videos, or quizzes, or running internal campaigns.
About Sky Mavis
Sky Mavis creates Axie Infinity, the most successful Web3 game ever, and Ronin, a purpose-built blockchain that ranked as the 4th most-used chain in 2024 behind Ethereum, Bitcoin, and Solana. The company has processed over $4.3 billion in on-chain volume and is backed by more than $170 million from top-tier investors including a16z, Accel, Libertus Capital, and Paradigm.
What security roles in crypto pay
116 salaries · our own dataMost security roles in crypto pay between $139k and $264k, with a median of $195k.