praktikumjobs.ch
← All jobs

Cybersecurity Consulting Internship – Multi-agent system for AI-assisted penetration testing

Wavestone1

Employment type
Internship
Location
Switzerland
First posted
Apply now

Penetration testing remains a largely artisanal activity: a significant portion of the auditor's time is devoted to reconnaissance, enumeration, and the replay of known techniques, at the expense of high-value-added analysis.

In parallel, artificial intelligence is becoming a permanent fixture in practices, and models with top-tier cyber capabilities are arriving on the market, including on the offensive side. This is notably illustrated by Mythos with its vulnerability identification capabilities which created widespread awareness, or even by the OpenAI - Hugging Face incident. The demonstration is clear: agents equipped with cyber capabilities, which become increasingly performant as models and architectures (e.g., multi-agent) evolve, present considerable potential for conducting penetration tests.

  1. Internship Objective
  2. The study phase

Reporting to the Swiss office of Wavestone, the objective of the internship is to design and prototype a multi-agent system capable of conducting penetration tests in a quasi-autonomous manner, under human supervision, on representative infrastructures (Active Directory, Windows, Linux, etc.), by producing reliable and demonstrated observations.

Preparatory work:

Achieving the objectives requires preparatory work on the following points:

  • State of the art of AI tooling applied to offensive security: existing frameworks, academic work, public feedback, and observed limitations.
  • Rapid overview of deployable models (open source executed locally or commercial) and their trade-offs: reasoning, cost, latency, hosting, confidentiality of audit data.
  • Scoping the rules of the game: authorization perimeter, prohibited or irreversible actions, logging, and reversibility. All work is conducted on an isolated laboratory and on explicitly authorized environments.

We offer an internship structured around the following objectives:

Objective 1: Design and prototype a (quasi) autonomous multi-agent system independent of the model

  • Design a multi-agent architecture covering the entire flow of a penetration test and distributing the work among specialized agents: reconnaissance, exploitation, review, challenge, writing, etc.
  • The system must ensure the autonomous orchestration of these agents, allowing it to start from a mission objective to arrive at a final report with proven results.
  • The architecture must remain independent of the underlying model, so as to be able to assign the best-suited model to each role, whether it is executed locally or consumed via a commercial API.

Objective 2: Guarantee reliability, limit false positives, and demonstrate observations

  • Implement mechanisms guaranteeing that no conclusion is retained without having been challenged and then demonstrated (e.g., cross-reading, antagonistic agents, deterministic replay of observations, and systematic conservation of artifacts, etc.).
  • The system must provide a reconstructed attack path and end-to-end traceability of its actions, so that an auditor can verify the reasoning followed by themselves.
  • Define the method for evaluating the reliability and performance of the designed system, and iterate based on these indicators to improve the solution.

Objective 3: Test the system on a realistic infrastructure, with a human in the loop

  • Define and implement the human supervision model: explicit validation before any intrusive or potentially destructive action, the possibility for the operator to take back control at any time, and technical perimeter safeguards.
  • Test the prototype on a laboratory representative of the environment to be audited for the evaluation (e.g., GOAD for Active Directory, AWSGoat/AzureGoat for the cloud, etc.) according to what has been chosen. The solution must perform a pentest of the environment in a (quasi) autonomous manner.
  1. Contributions to the consulting firm

As a trainee consultant, you will also be required to contribute to the operational missions of our clients.

We also give you the opportunity to participate actively in the internal life of the firm through:

  • Support for the development of our Cybersecurity expertise: contribution to prospecting actions and the development of commercial proposals.
  • Monitoring and internal sharing on AI applied to offensive and defensive security.
  • Production of materials aimed at acculturating other firm employees to the uses and limits of these technologies.
  • Participation in company events: afterworks, recreational activities and organized outings, meetings with market players, etc.

A student in a Master's program within a major engineering school or university in Switzerland, you are attracted to consulting and business transformation issues. You are convinced of the need to address the cybersecurity challenges of large groups.

You also possess the following skills:

  • Curiosity, sharp analytical mind, and the ability to master new subjects
  • Client orientation, excellent interpersonal skills, and sense of service
  • Taste for challenge and results
  • Attraction to entrepreneurship and innovation

Furthermore, you want to be an actor in an ambitious, fast-growing company project in Switzerland and internationally. You want to put your enthusiasm at the service of a firm that will be able to offer you rapid responsibility.

Join an international consulting firm that accompanies major strategic transformations.

We are Wavestone: passionate and solution-oriented experts, who place humans at the heart of performance and growth. Ambitious and in full expansion, we are developing our

Automatically translated from the original.

Posted 1 week ago