
Start date: February 2027 · Duration: 6 months
Please include your latest academic transcripts with your application. Applications submitted without transcripts will not be considered.
In this 6-month internship or master thesis starting in February 2027, you will tackle a growing challenge: AI is dramatically reducing the time between CVE publication and active exploitation. Exploits can emerge within hours, while patch deployment in complex environments often takes days or weeks.
You will investigate how an AI-driven system could generate WAF (Web Application Firewall) rules from published CVEs to protect systems until permanent fixes are deployed. The exact scope will be defined together with you: a broad proof-of-concept, or a deeper study of a specific topic such as CVE analysis, attack pattern extraction, WAF rule generation or rule validation.
We are ELCA, one of the largest Swiss IT tribe with over 2,300 experts. We are multicultural with offices in Switzerland, Spain, France, Vietnam and Mauritius. Since 1968, our team of engineers, business analysts, software architects, designers and consultants provide tailor-made and standardized solutions to support the digital transformation of major public administrations and private companies in Switzerland. Our activity spans across multiples fields of leading-edge technologies such as AI, Machine & Deep learning, BI/BD, RPA, Blockchain, IoT and CyberSecurity.

With more than 2,300 experts, the ELCA Group is a leading independent Swiss IT service and solution provider, specialized in IT consulting, Cybersecurity, Cloud, Data & AI, Digital experience, Software development, Business applications and systems' integration across all industries. ELCA helps its clients to better compete in the digital era and gain in agility. The privately held company has offices in Pully (HQ), Zurich, Geneva, Bern, Basel, Rapperswil and Fehraltorf, as well as offshore centers in Italy, Spain, Mauritius and Vietnam.