Join us at Vera Solutions, where innovation meets purpose. We’re a forward-thinking tech company dedicated to creating digital solutions that drive significant social change. We run on passion, blending diverse skill sets and experiences with a collective mission to help organizations tackle challenges and achieve greater impact. As a social enterprise and certified B Corporation, we reinvest a majority of our profits in our growth and continued pursuit of our mission and vision.
The DevOps Intern will be part of a growing Development/Products team. The Intern will support and contribute to the design and implementation of new features in all of Vera’s products, with a particular focus on the automation, reliability, and security of the pipelines that deliver them.
Because Vera’s products hold sensitive programme and beneficiary data for social impact organizations, security is not a separate discipline here, it sits inside the delivery pipeline. The Intern will learn how secure development practices are embedded into CI/CD rather than added after the fact.
The Intern should bring a desire to learn new technologies and processes, and an eagerness to develop new skills.
The Intern will join a team of passionate individuals with diverse backgrounds and experiences, all dedicated to improving the way social impact organizations operate. We’re a self-motivated, creative group, and we emphasize collaboration, flexibility, and professionalism.
DevOps
- Support the engineering team by researching and testing CI/CD automations and tooling
- Support the DevOps Lead in researching DevOps best practices to ensure Vera engineering is at the leading edge of CI/CD best practices
- Work closely with Engineering team members to improve and automate repetitive and inefficient processes
- Follow and contribute to internal best practices, commit to improving upon and learning new skills, and keep up to date with industry trends and developments
Cybersecurity
- Help integrate automated security checks into CI/CD pipelines, including static code analysis (SAST) and third-party dependency/vulnerability scanning
- Support secrets management practices, assist in auditing repositories and pipelines for hard-coded credentials and helping migrate them to a secrets vault
- Assist with routine access reviews across source control, CI/CD tooling, and cloud environments, applying the principle of least privilege
- Support periodic security reviews, including Health Check, profile and permission set audits, and sharing model checks
- Help triage and document findings from automated scans, tracking remediation alongside the engineering team
- Contribute to internal security documentation, checklists, and awareness material for the wider team
- Assist with incident response drills and support the team in following established escalation procedures
Essential
- Relevant coursework (completed or in progress) in Computer Engineering / Computer Science / BSc. I.T.
- Basic understanding of CI/CD concepts
- Basic knowledge of programming languages (Python, JavaScript)
- Awareness of common application security concepts, such as the OWASP Top 10, authentication and authorization, and safe handling of credentials
- Demonstrated success working in a team, self-management and proactive communication
- Excellent written and verbal communication and relational skills
- Excellent organizational skills and a passion for fine details
- Diligent work ethic and proven ability to work with drive and enthusiasm
- Insatiable desire to improve skills and knowledge of self and others
- Fluent English language skills
- Able to commit to a 1 year internship
Desirable
- Basic knowledge of cloud DevOps (Azure DevOps, AWS DevOps)
- Exposure to security tooling or practices in any of the following areas:
- Static/dynamic analysis: SonarQube, CodeQL, Checkmarx, PMD
- Dependency scanning: Dependabot, Snyk, OWASP Dependency-Check
- Secrets management: GitHub Secrets, HashiCorp Vault, AWS Secrets Manager
- Identity and access management, MFA, and least-privilege access models
- Awareness of data protection and privacy frameworks (India DPDP Act, GDPR) or security standards such as ISO 27001 or SOC 2
- Interest in social service work or international development
- Foundations in any of the following:
- Source Control: GitHub,GitLab
- CI/CD: CircleCI, Jenkins
- Testing Frameworks: Robot, Jest