Intern Application Security Engineer

CommerceAustin, TX
$25 - $35Hybrid

About The Position

Welcome to the Agentic Commerce Era At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you. Commerce is seeking an Application Security Intern to join the Cybersecurity team for an eight-week summer internship. This role is designed for a student or early-career candidate interested in application security, secure software development, vulnerability management, and how security teams partner with engineering in a modern SaaS environment. As an Application Security Intern, you will work under the guidance of experienced Application Security engineers to learn how BigCommerce identifies, evaluates, and helps remediate security risks across our products and platforms. You will contribute to practical tooling, documentation, and process improvements that help the team scale its AppSec program while gaining exposure to real-world bug hunting, security review, and incident response workflows. This is a hybrid role based in Austin, TX. We require 3 days a week in office and are looking for local candidates only.

Requirements

  • Current student or early-career candidate pursuing cybersecurity, computer science, software engineering, information systems, or a related field.
  • Interest in application security, ethical hacking, secure coding, vulnerability research, or software development.
  • Familiarity with basic web application concepts, APIs, Git, scripting, or common security topics such as OWASP Top 10.
  • Curiosity, good judgment, and willingness to ask questions.
  • Strong written communication skills and ability to document findings clearly.
  • Ability to work with a team, follow guidance, and handle sensitive information responsibly.

Nice To Haves

  • Coursework, labs, CTF participation, personal projects, or prior internship experience related to cybersecurity or software development.
  • Exposure to tools or concepts such as SAST, DAST, SCA, threat modeling, vulnerability management, or cloud security.
  • Basic scripting experience in Python, JavaScript, Bash, or a similar language.

Responsibilities

  • Learn the structure, goals, and day-to-day operating model of the BigCommerce Application Security program.
  • Support improvements to AppSec tooling, reporting, documentation, and team processes.
  • Assist with organizing or refining vulnerability management workflows, intake processes, dashboards, or knowledge base materials.
  • Shadow AppSec engineers during security reviews, bug hunting, triage, and remediation discussions.
  • Participate in guided hands-on security activities such as testing, reproducing findings, researching vulnerabilities, or validating fixes.
  • Observe how the team partners with engineering, product, infrastructure, and incident response teams.
  • Contribute to a small intern project that improves the AppSec team’s ability to measure, communicate, or scale its work.
  • Present a short summary of learnings, recommendations, and completed work at the end of the internship.

Benefits

  • Eight-week summer internship
  • Mentorship from security engineers
  • Exposure to engineering partnership models
  • A clearer understanding of potential career paths in application security, product security, and cybersecurity.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service