A cybersecurity intern at mylife Diabetes Care supports risk management for connected insulin pump ecosystems, working across pump, sensor, app and cloud. Day-to-day involves STRIDE threat modelling, the CVSS 3.1-to-4.0 transition, SBOM/SOUP analysis, and Python/API automation, including exploring Agentic AI for post-market surveillance.
Support cybersecurity risk management activities for connected medical devices and their software ecosystems
Contribute to the transition from CVSS 3.1 to CVSS 4.0 and help define practical assessment approaches
Analyse system architectures, trust boundaries and security dependencies across pump, sensor, mobile app and cloud environments
Apply STRIDE threat-modelling methods to identify potential threats and vulnerabilities
Assess software components and their security implications, including SBOMs, SOUP and open-source or off-the-shelf libraries
Support the development of company procedures for cybersecurity during pre-market development and post-market surveillance
Help translate technical cybersecurity risks into potential patient safety risks
Collaborate with system engineers, software engineers and verification engineers to define and demonstrate appropriate mitigations
Explore how Agentic AI could support post-market surveillance by scanning external threat databases, vulnerability disclosures and industry information
Use Python and APIs to support automation, data analysis and experimentation with AI-supported workflows
Your profile
Currently studying or recently graduated in Computer Science, Cybersecurity, Systems Engineering, Biomedical Engineering or a related discipline
Strong curiosity about connected medical devices and system-of-systems architectures
Interest in threat modelling, particularly STRIDE
Interest in software security supply chains, SBOM, SOUP and third-party components
Interest in vulnerability scoring systems such as CVSS
Analytical and structured approach to complex technical problems
Ability to communicate clearly and collaborate with colleagues from different engineering disciplines
Hands-on familiarity with Python, APIs or automation is an advantage
Interest in applying Agentic AI to practical cybersecurity and engineering challenges
Very good command of English; German is an advantage