
A Cybersecurity Internship at ixigo that actually touches real regulatory frameworks — not just theoretical concepts — is genuinely rare at the entry level, but that’s exactly what this ixigo posting offers: direct exposure to India’s DPDP Act, PCI DSS, and ISO 27001 compliance work, at a company serving over 54 crore annual active users.
Why ixigo’s security function matters more than it might first appear
ixigo isn’t a small company — it operates ixigo, ConfirmTkt, and AbhiBus, handling travel bookings and sensitive user data (payment details, travel documents, personal information) at genuinely massive scale across India. That means the Information Security team’s work here connects to real, high-stakes data protection responsibilities, not a token security function bolted onto a smaller operation.
What the internship actually covers
- Supporting Information Security Governance, Risk & Compliance (GRC) activities
- Assisting in vulnerability management, security assessments, and remediation tracking
- Reviewing CVEs, threat intelligence, and security advisories as part of ongoing monitoring
- Supporting compliance initiatives tied specifically to India’s DPDP Act, alongside PCI DSS, ISO 27001, and PIMS (ISO 27701)
- Preparing security policies, standards, procedures, and documentation
- Participating in security awareness and phishing simulation exercises
- Supporting vendor security assessments and privacy reviews
- Researching emerging cyber threats, AI security risks, and regulatory updates
This is a genuinely broad GRC-and-technical blend — spanning documentation-heavy compliance work alongside hands-on vulnerability and threat research, rather than sitting narrowly in just one lane.
What ixigo is actually screening for
The required-knowledge list here is unusually specific and worth taking seriously as prep material in its own right:
- Basic understanding of the DPDP Act, 2023 and its associated Rules
- PCI DSS fundamentals, along with PIMS (ISO 27701) and ISO 27001 basics
- Familiarity with the NIST Cybersecurity Framework and OWASP Top 10
- Understanding of the MITRE ATT&CK Framework, plus CVSS and CVE concepts
- Network security fundamentals — TCP/IP, HTTP/HTTPS, DNS, SSH, TLS
- Authentication and authorization concepts
- Basic cloud security awareness across AWS, Azure, or GCP
- Basic understanding of Vulnerability Assessment & Penetration Testing (VAPT)
What genuinely strengthens an application
- Hands-on familiarity with tools like Burp Suite, Wireshark, Nmap, or Nessus
- Relevant certifications — Security+, CEH, or ISO 27001 — explicitly called out as a plus, though not mandatory
- Strong analytical thinking combined with genuine curiosity about emerging threats, rather than static, memorized knowledge
What you’d actually walk away with
Beyond resume material, ixigo’s own listing is specific about the learning outcomes: hands-on exposure to enterprise-level cybersecurity and privacy programs, direct experience with industry-standard frameworks, mentorship from experienced security professionals, and genuine exposure across governance, compliance, security operations, and privacy work — a combination that’s increasingly valuable as data protection regulation tightens across India.
A note on the broader hiring context at ixigo
While this listing doesn’t detail its specific interview stages, ixigo’s broader technical hiring process (based on documented candidate experiences for other roles) typically includes an online assessment covering quantitative, verbal, and reasoning sections alongside coding questions, followed by one or two technical interview rounds and a discussion of past projects. Given this role’s compliance-heavy nature, expect a security-specific interview to weigh conceptual framework knowledge (DPDP Act, ISO standards) at least as heavily as pure technical skill.
Questions Candidates Commonly Have
1. Is this internship suited for someone without prior cybersecurity certifications? Yes — certifications like Security+ or CEH are explicitly listed as a plus, not a requirement. Strong conceptual understanding across the listed frameworks matters more at this stage.
2. Is this a remote internship? No — based on ixigo’s broader internship listings, roles are typically on-site in Gurugram; this listing doesn’t indicate a remote option.
3. Does this role require hands-on penetration testing experience? No — only a “basic understanding” of VAPT concepts is listed as required, not hands-on penetration testing expertise, making this genuinely accessible to students without professional security experience.
4. Is the stipend for this specific role officially confirmed by ixigo? No — this listing doesn’t disclose a stipend figure. The ₹15,000–20,000/month estimate is based on ixigo’s publicly reported stipends for other comparable internship roles, not a confirmed number for this specific position.
About ixigo
ixigo is an India-based online travel technology company that helps travellers plan, book, and manage trips across rail, air, buses, hotels, and cabs. Launched in 2007 by Aloke Bajpai and Rajnish Kumar, the company focuses on empowering Indian travellers with AI-driven, personalized travel recommendations. Through its ixigo, ConfirmTkt, and AbhiBus apps, it operates as the leading OTA (online travel agency)...
View Company Profile →Top Interview Questions
Prepare with commonly asked questions for this role
The DPDP Act, 2023 is India's Digital Personal Data Protection law, governing how organizations collect, process, and secure personal data. For a travel platform like ixigo handling sensitive user data — payment details, travel documents — compliance directly affects how data can be stored, shared, and protected, making it central to the company's actual operations, not just a legal formality.
A vulnerability is a weakness in a system that could potentially be exploited — like unpatched software. A threat is the actual potential for someone or something to exploit that vulnerability and cause harm. Risk emerges from the combination of the two, plus the potential impact if exploitation actually occurs.
The OWASP Top 10 is a regularly updated list of the most critical web application security risks, used broadly across the industry to prioritize security efforts. A well-known example is Broken Access Control, where users can act outside their intended permissions due to improperly enforced restrictions.
I'd check the CVSS score to gauge severity, review which systems or software versions are affected, then cross-reference against ixigo's actual technology stack to determine real exposure, before recommending prioritized remediation steps based on genuine risk rather than reacting to every disclosure equally.
Technical controls alone don't guarantee security if there's no structured governance ensuring they're consistently applied, documented, and audited — GRC work is what makes security efforts sustainable and legally defensible over time, not just reactive.
