IT Intern

Mayo Clinic · Rochester, MN, United States · This position has a predetermined rate of $25.00 per hour.

  • Paid
  • Full time

About the role

Mayo Clinic — 90-Day Internship

Secure SDLC & Agentic DevSecOps

Position Overview

AI is changing not only the software organizations build, but also **how software is designed, coded, tested, secured, deployed, and operated**.

Mayo Clinic is advancing a **Secure Software Development Lifecycle (Secure SDLC)** that incorporates modern AI-assisted engineering and emerging **agentic DevSecOps** capabilities while maintaining appropriate security, quality, traceability, and engineering controls.

The **Secure SDLC & Agentic DevSecOps Intern** will work directly with technical leadership on the design, build, testing, and documentation of these next-generation software delivery practices.

This is a **90-day learning-focused technical internship** for students interested in software engineering, cybersecurity, DevSecOps, automation, AI engineering, or software architecture. The intern does not need professional software engineering experience but should be eager to understand how modern software moves securely from an idea to production.

What You'll Do

The intern will contribute to work at the intersection of **software engineering, security, automation, and AI**.

Activities may include:

  • Help design and document a **Secure SDLC** spanning planning, requirements, architecture, development, testing, security validation, deployment, operations, and retirement.
  • Map security and engineering controls to specific stages of the software delivery lifecycle.
  • Help design and test **AI-assisted and agentic software development workflows**.
  • Explore how **Claude, ChatGPT/Codex, GitHub Copilot, and other approved AI engineering tools** can participate in development and DevSecOps workflows.
  • Build or test workflows in which AI assists with activities such as requirements analysis, coding, test generation, documentation, code review, security analysis, and remediation.
  • Work with **GitHub repositories, issues, branches, pull requests, CI/CD pipelines, and automated checks** to understand how software delivery controls can be implemented.
  • Help evaluate where AI agents can safely perform tasks autonomously and where **human review or approval** should remain required.
  • Assist with designing repeatable workflows for AI-generated code and agent-created changes.
  • Help define evidence and traceability requirements for software and AI-assisted engineering activities.
  • Experiment with automated testing, static analysis, dependency scanning, security checks, policy validation, and other DevSecOps capabilities.
  • Help develop **reference implementations, templates, workflows, diagrams, or proofs of concept** that demonstrate the Secure SDLC.
  • Document findings, design decisions, limitations, risks, and recommended engineering patterns.
  • Collaborate with software engineering, security, architecture, platform, and AI teams.

Areas You May Explore

Depending on the project and the intern's interests, the internship may provide exposure to:

AI-Assisted Software Engineering

  • GitHub Copilot
  • Claude
  • ChatGPT/Codex
  • AI-assisted coding and testing
  • AI code review
  • Prompt and context engineering

Secure SDLC

  • Secure design
  • Threat modeling
  • Code review
  • Software testing
  • Security testing
  • Software supply-chain concepts
  • Traceability and evidence
  • Release and deployment controls

DevSecOps

  • Git and GitHub
  • Pull-request workflows
  • CI/CD
  • GitHub Actions or similar automation
  • Automated testing
  • Static analysis
  • Dependency and vulnerability scanning
  • Infrastructure and deployment concepts

Agentic Engineering

  • AI agents
  • Tool use and orchestration
  • Human-in-the-loop workflows
  • Agent permissions and boundaries
  • Automated software engineering tasks
  • Agent-generated code and pull requests
  • Validation and approval patterns

Basic Skills

Candidates should have some foundational technical experience from coursework, personal projects, internships, or independent learning.

Helpful skills include:

  • Introductory programming experience in **Python, Java, JavaScript/TypeScript, C#, or another programming language**.
  • Basic understanding of the **Software Development Lifecycle (SDLC)**.
  • Familiarity with **Git and GitHub**, including repositories, commits, branches, and pull requests.
  • Basic understanding of software testing and debugging.
  • Interest in cybersecurity, secure software development, DevOps, or DevSecOps.
  • Interest in generative AI and AI-assisted software engineering.
  • Familiarity with **Claude, ChatGPT/Codex, GitHub Copilot, or similar AI development tools** is helpful but not required.
  • Strong analytical and problem-solving skills.
  • Ability to learn unfamiliar technologies and experiment with new approaches.
  • Ability to clearly document technical concepts, results, and decisions.
  • Curiosity about both **how software works and how it can fail**.

Experience with APIs, CI/CD, GitHub Actions, cloud platforms, containers, security tools, or AI agents is beneficial but **not required**.

What You'll Learn

By the end of the internship, the intern should have practical exposure to:

  • How enterprise software moves from idea through production.
  • Secure software engineering principles.
  • Modern GitHub-based development workflows.
  • CI/CD and DevSecOps.
  • Software security and supply-chain concepts.
  • AI-assisted software engineering.
  • Agentic development workflows.
  • Human oversight and controls for AI agents.
  • Building automation into an enterprise SDLC.
  • Balancing development speed, security, reliability, and governance.

Example 90-Day Experience

Days 1–30 — Learn & Map

Learn the current SDLC, GitHub development workflows, security practices, DevSecOps concepts, and available AI-assisted engineering technologies. Map a representative application from idea through deployment and identify opportunities for automation and AI assistance.

Days 31–60 — Build & Experiment

Help build and test components of the Secure SDLC. Create or modify sample repositories, pipelines, automated checks, templates, or agentic workflows. Experiment with AI-assisted coding, testing, review, documentation, and security activities.

Days 61–90 — Integrate & Demonstrate

Complete a scoped Secure SDLC or Agentic DevSecOps proof of concept. Demonstrate how software can move through a defined engineering workflow with appropriate automation, security controls, AI assistance, traceability, and human approval.

Present the solution, lessons learned, and recommendations for future development to Mayo Clinic technology stakeholders.

This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.

The incumbent must be enrolled in a bachelors, masters or graduate degree program from a college or university. Typically, this internship would occur after the student has taken most of the courses required by the degree program. Where applicable - the degree program must require an internship as a graduation requirement (or offer as a credit option).

More at Mayo Clinic