Most web security intern listings fail the same way: they describe a person rather than a job. Candidates cannot tell what they would do on Monday, so the strong ones apply somewhere clearer.
The "Web" qualifier brings browsers, devices and accessibility into scope. Decide which browsers and devices you actually support before writing the brief, because that decision is the job.
People searching for web security intern often also look at api security intern. The skills overlap heavily; what differs is emphasis — this brief leans on the web side of the work, while api security intern leans on api. If your requirement genuinely spans both, say so in the listing rather than picking one title and hoping.
Below: the skills worth testing, the work a student can genuinely finish in a term, 2026 stipend bands, and questions that have a wrong answer. Posting is free and takes about two minutes.
What a single Application Security intern actually does in the first 90 days
Each of these is work a team member would otherwise do. That is the test of a good intern brief: real work already on someone's list, not a project invented to keep the intern busy.
- Fix the top pages on mobile and prove the improvement with real measurements
- Threat-model one upcoming feature before it is built
- Run a secure code review on the authentication path and file fixable issues
- Set up dependency scanning with a triage policy that does not block everything
Application Security skills worth screening for
Screen on the first three. The rest are teachable inside a term, and treating them as entry requirements shrinks your pool for no gain.
- 1Testing on something other than the laptop they built it on
- 2OWASP Top 10 in practice, not as a list
- 3Authentication and session security
- 4Input validation and output encoding
- 5Secure code review
- 6Dependency and supply-chain risk
- 7Threat modelling a feature
- 8Working with developers rather than against them
The tools column is where CV inflation happens. Pick two and ask what went wrong the last time they used them; the answer is unfakeable.
Screening questions for web security intern
These separate practice from theory. Ask two, listen for a specific example, then follow the example rather than moving to the next question.
How do you get developers to fix your findings?
What a good answer shows: Collaboration skill — the reason most appsec programmes fail
Explain CSRF and why a token fixes it.
What a good answer shows: Whether they understand the mechanism
What is the difference between authentication and authorisation bugs?
What a good answer shows: Precision
Score every candidate on the same questions. Comparing free-form conversations across a shortlist is where inconsistency, and bias, get in.
Where the Application Security candidates come from
MyInternships.in carries a verified, India-wide pool of students and fresh graduates — from IITs, NITs, BITS, IIMs and Symbiosis through to strong regional engineering and commerce colleges. Profiles carry skill tags, so you can filter on Burp Suite and OWASP ZAP rather than reading résumés.
- Skill tags — filter directly on Burp Suite, OWASP ZAP, Snyk or Dependabot and the rest of the Application Security stack
- Languages, for roles with customer or field contact across states
- Institute tier, if a specific campus cohort matters for this role
- Availability window and notice, so a six-month role does not shortlist a six-week candidate
- Prior application security exposure — coursework, personal projects or a previous internship
Skill tags come from the candidate’s own projects and verified profile, so filtering on Burp Suite or OWASP ZAP returns people who have used them rather than people who listed them.
What to pay a single Application Security intern in 2026
₹17,000–₹40,000 a month is the band we see for this role across India. The spread is mostly city and company stage, not candidate quality.
The saving is a few thousand rupees; the cost is a candidate who starts feeling undervalued and treats the term as temporary. Decide the number, publish it, honour it.
Bengaluru, Hyderabad, Pune, Mumbai, Gurugram and Noida sit at the top of the band. Tier-2 cities typically run 25–40% lower for the same skills and the same output.
Listings that state a stipend get noticeably more qualified applications than "as per industry standards", which candidates read as low or undecided.
Six-month commitments generally command more per month than six-week ones, because the candidate is giving up other options. Price the commitment, not just the hours.
Getting one Application Security intern to actually produce something
The difference between an intern who ships and one who does not is almost never talent. It is whether the work was ready on their first day and whether someone read it on their second week.
Laptop, accounts, repository or dataset access, and a task small enough to finish in two days. Interns who spend week one waiting for access rarely recover the momentum.
Read their work in the first week, not the fourth. Early correction on a small piece of Application Security work is cheap; late correction on a term’s work is not.
Someone who wants the output and will complain if it is wrong. Work with no audience is the fastest route to a disengaged intern.
Write down what a successful term would produce. Otherwise the end-of-term assessment becomes a memory of impressions, and that helps nobody.
How to post web security intern on MyInternships.in
You do not need a prepared job description. Answer a few questions in the chat and the assistant drafts the listing, title and skill tags for you.
Describe the role the way you would to a colleague: what the application security work is, how long for, and what you can pay. The assistant asks the rest.
It drafts the description, suggests the title and tags the Application Security skills so the right candidates see it. You edit anything before it publishes.
One-time company verification protects the pool from fake listings, which is why response rates here hold up on roles that would be ignored elsewhere.
First applications typically land the same day. Contact details and résumés are available on any paid plan; the free plan shows you the applications.
Free plan: one listing, live after verification. Starter ₹499: five listings a month, published instantly, full applicant contact and résumé access. Growth ₹999: fifteen listings with AI candidate matching.
Mistakes that cost you the good Application Security candidates
Four failures we see repeatedly on this kind of role, in rough order of what they cost.
A Application Security listing with fourteen required tools reads as a company that does not know what it needs. Strong candidates self-select out; the ones who apply anyway have inflated their CVs to match.
CGPA has almost no relationship with output in this role. One project they can explain in depth, including what went wrong, predicts far better.
"Assist the team" tells a candidate nothing and tells you nothing at review time. Name the work, in the listing, from the deliverables above.
Interviews reward confidence, and confidence in early-career candidates is distributed unevenly by background rather than by ability. Score the answers, not the delivery.
Web Security Intern — frequently asked questions
How much Application Security experience should we expect?+
None professionally, and that is the point. What you should expect is evidence: something built, run or fixed involving Burp Suite or OWASP ZAP, that they can talk about in depth. Screen on testing on something other than the laptop they built it on and oWASP Top 10 in practice, not as a list; treat everything else on the list as trainable during the term.
What should we set as the goal for the term?+
One finished thing. Fix the top pages on mobile and prove the improvement with real measurements is the right size: real work someone on the team would otherwise do, small enough to finish, visible enough to assess. If they move quickly, threat-model one upcoming feature before it is built is the natural second piece. A term with three half-finished projects assesses nothing and teaches less.
What stipend should we pay web security intern in India?+
₹17,000 to ₹40,000 a month covers most of the market for this role. Metro product companies pay at the top of the band; tier-2 cities and services firms 25–40% lower. An unpaid listing filters for who can afford to work free rather than who is good, and roughly halves the applications you receive.
What is the fastest way to tell a strong Application Security candidate from a weak one?+
Ask about something that went wrong. "How do you get developers to fix your findings?" gets you collaboration skill — the reason most appsec programmes fail, and two follow-up questions on their own example will tell you the depth. Candidates who have only studied the topic run out of specifics almost immediately.
What does it cost us in time to supervise one Application Security intern?+
Realistically two to four hours a week of a competent person: a longer session early on, then short daily availability and a weekly review. Below that, the intern stalls and produces nothing you can use. Above it, you are doing the work yourself. That time is the true cost of the hire, and it is what the stipend line in your budget does not show.
Does the "Web" in Web Security Intern change who we should hire?+
The "Web" qualifier brings browsers, devices and accessibility into scope. Decide which browsers and devices you actually support before writing the brief, because that decision is the job. In screening terms, that means adding one specific check: testing on something other than the laptop they built it on.
What documents does a Application Security intern usually need at the end?+
Most Indian colleges ask for a completion or experience certificate, and many also require a mentor evaluation on the institution's own form. Ask which format the candidate's college needs during onboarding rather than in the final week — it takes two minutes then and becomes a scramble later.
How quickly do applications arrive?+
First applications typically arrive within about two hours of the listing going live, and most employers hiring a Application Security intern have a workable shortlist inside a week. Speed depends more on how specific the brief is than on the stipend — a listing with a named project and named tools consistently outperforms a generic one at the same money.
Related roles employers hire alongside web security intern
Tools and pages for your hiring
Hire web security intern — post in about two minutes
Answer a few questions and our AI writes the description, suggests the title and tags the Application Security skills. Your company is verified, the listing goes live, and applications start arriving.
