The intern will support the IT team in implementing and documenting cybersecurity controls, including NIST and CMMC compliance requirements. They will also assist with vulnerability management, security monitoring, evidence collection, and security awareness initiatives.
Requirements overview
Candidates must be pursuing or have recently completed a degree in Cybersecurity, IT, or a related field with a foundational understanding of security principles. Familiarity with NIST frameworks and strong technical documentation skills are required.
AIRO Group is a multi-faceted aerospace, autonomy and air mobility company with differentiated technologies and capabilities that dynamically address high growth market trends across the aerospace and aviation ecosystems.
AIRO operates from offices in the US, Canada and the EU, providing innovative, industry-leading products and services via its four synergistic divisions: Advanced Avionics, Electric Air Mobility, Uncrewed Air Systems, and Training. To learn more, visit: www.theairogroup.com
Together, these AIRO divisions represent a transformation of the aerospace industry by providing a diversified offering of capabilities positioned to be the first mid-tier, full-spectrum aerospace and defense company offering transformative solutions for the industry.
The AIRO Group, through its unique divisions and recognized brand offerings, offer robust solutions for the next generation of avionics, manned and unmanned mobility, and multi-modal transportation for defense and commercial markets.
Position Overview:
We are seeking a motivated Cybersecurity & Compliance Intern to support the Information Technology team in strengthening the organization’s cybersecurity and compliance program. The ideal candidate will have a foundational understanding of cybersecurity principles and familiarity with NIST Cybersecurity Framework, NIST SP 800-171, and/or Cybersecurity Maturity Model Certification (CMMC) requirements.
This position will provide hands-on experience supporting cybersecurity controls, documentation, security assessments, evidence collection, vulnerability management, asset management, and compliance activities. The intern will work closely with the IT Director and other IT personnel to help implement and document security practices across the organization.
Key Responsibilities:
NIST / CMMC Compliance
Assist with implementation and documentation of NIST SP 800-171 and CMMC security controls.
Review existing policies, procedures, and technical configurations against applicable NIST/CMMC requirements.
Help maintain a System Security Plan (SSP) and supporting compliance documentation.
Assist with developing and maintaining Plans of Action & Milestones (POA&Ms) where applicable.
Research NIST, CMMC, DoD, and related cybersecurity requirements and translate requirements into actionable IT tasks.
Assist with preparing documentation and evidence for internal assessments and future CMMC assessments.
Track control implementation status and identify missing documentation or evidence.
Security Operations
Assist with vulnerability and patch management activities.
Review security alerts, endpoint security information, and other cybersecurity monitoring data.
Assist with endpoint, network, identity, and Microsoft 365 security reviews.
Help verify that systems are configured according to established security standards.
Assist with user access reviews, account management, and access-control documentation.
Participate in periodic reviews of security logs, audit records, and security configurations.
Assist with identifying and documenting potential security risks.
Documentation & Evidence
Collect and organize evidence demonstrating implementation of cybersecurity controls.
Maintain compliance evidence repositories and control documentation.
Create screenshots, reports, configuration records, and other artifacts required to demonstrate control implementation.
Maintain accurate records of assets, users, systems, applications, and security controls.
Assist with documenting IT processes and standard operating procedures.
Security Awareness
Assist with cybersecurity awareness and training initiatives.
Help develop security communications and educational materials for employees.
Support phishing-awareness and other security-awareness activities.
Promote secure handling of company and sensitive information.
General IT Support
Assist the IT team with cybersecurity-related projects and initiatives.
Participate in IT infrastructure and security assessments.
Assist with hardware and software inventory activities.
Support implementation of security improvements and remediation efforts.
Perform other cybersecurity and IT-related duties as assigned.
Qualifications:
Required Qualifications
Currently pursuing or recently completed a degree or certificate in Cybersecurity, Information Technology, Computer Science, Information Assurance, or a related field.
Foundational understanding of cybersecurity principles.
Familiarity with NIST SP 800-171, NIST 800-53, NIST Cybersecurity Framework, CMMC, or similar security frameworks.
Strong attention to detail and organizational skills.
Ability to document technical information clearly and accurately.
Strong analytical and problem-solving skills.
Ability to handle confidential information appropriately.
Ability to work independently while knowing when to ask questions.
Preferred Qualifications
Coursework, training, or certification related to NIST, CMMC, cybersecurity, or information security.
Familiarity with the 14 CMMC/NIST SP 800-171 control families, including:
Access Control
Awareness and Training
Audit and Accountability
Configuration Management
Identification and Authentication
Incident Response
Maintenance
Media Protection
Personnel Security
Physical Protection
Risk Assessment
Security Assessment
System and Communications Protection
System and Information Integrity
Experience with Microsoft 365, Entra ID/Azure AD, Windows, endpoint security, or networking.
Familiarity with vulnerability management, patch management, MFA, least privilege, or security logging.
Experience working with spreadsheets, ticketing systems, documentation platforms, or compliance-management tools.
Security-related certifications such as Security+, Network+, ISC2 CC, or equivalent are a plus.
Skills & Competencies
Cybersecurity fundamentals
NIST/CMMC control awareness
Documentation and evidence management
Risk identification and analysis
Attention to detail
Technical writing
Problem solving
Organization and project tracking
Confidentiality and professional judgment
Ability to learn new technologies quickly
Physical and Mental Requirements:
Standing and sitting for extended periods of time,
Lifting up to 25 pounds in a safe and prudent manner,
Ability to work and communicate well with other employees and management, customers, visitors, vendors.
Ability to perform work utilizing manual dexterity of the hands,
Ability to push, pull, bend, stoop, reach above and below shoulders, and full use of upper extremities,
Ability to easily move through an approximately 25,000 square foot warehouse building,
Ability to read, write, and understand English,
Correctable vision and hearing.
Company Benefits:
Paid Time Off (PTO)
Paid Holidays
Parental Leave
Medical, Dental, Vision Insurance
Health Savings Account (HSA)
401(k) with company match
Employee Assistance Program (EAP)
Commuter Benefits
Basic Life Insurance – fully paid by the company for employees and their dependents
Long-Term Disability Insurance – fully paid by the company
Voluntary Short-Term Disability Insurance
Supplemental Life Insurance options
This job description is not intended to be all-inclusive, and the employee may also be asked to perform other reasonably related job duties as assigned by their immediate supervisor as required. All employees may be required to perform duties outside of their normal responsibilities from time to time as needed. The AIRO Group is an Equal Opportunity Employer.