About the role#
The Security Controls Oversight, Risk & Evaluation (SCORE) team evaluates risk, validates control effectiveness, and delivers insights to help Security leaders manage risk and meet regulatory expectations. This 12-week internship runs from May 2027 through August 2027. You will work on projects related to risk and control process modernization, reporting enhancement, and process rationalization.
What you'll do#
- Support Risk & Control Identification and Assessment (RCIA) workshops and RCSA activities by documenting process information, risks, controls, and outcomes.
- Review and analyze process documentation, narratives, procedures, and maps to identify risks and control opportunities.
- Participate in security control testing by collecting, organizing, and reviewing evidence under supervision.
- Document test procedures, results, observations, and workpapers.
- Perform data analysis and validation to support risk assessments, control evaluations, and reporting.
- Maintain risk and control inventories within governance, risk, and compliance (GRC) systems.
- Track action items, issues, remediation efforts, and testing milestones.
- Create executive-ready summaries, presentations, and status reporting materials.
- Research regulatory requirements, industry standards, and practices related to operational risk, information security, and controls management.
- Collaborate with risk managers, control testers, process owners, and business stakeholders.
- Participate in team meetings, project discussions, and training to gain exposure to enterprise risk management.
What you'll need#
- Currently enrolled in an accredited college or university pursuing a Bachelor's or Master's degree in Business, Risk Management, Accounting, Information Security, or related fields.
- Anticipated graduation date of December 2027 or later.
- Strong analytical, problem-solving, verbal, and written communication skills.
- Organizational and time management skills with the ability to work independently or on a team.
- Proficiency with Microsoft Office products including Excel, Word, PowerPoint, and Teams.
- Coursework or experience in audit, risk management, compliance, internal controls, or cybersecurity.
- Familiarity with risk assessment or control frameworks such as COSO, NIST, FFIEC, ISO 27001, or COBIT.
- Understanding of governance, risk, and compliance (GRC) concepts.
- Experience using data analysis tools such as Excel, Power BI, or SQL.
- Interest in pursuing careers in internal audit, compliance, risk management, security governance, or cybersecurity.
Location & details#
- This is a full-time, paid, on-site internship.
- Working hours are Monday through Friday, 8:00 AM to 4:30 PM.
- Locations: Vienna, VA; Pensacola, FL; or Winchester, VA.
About Navy Federal Credit Union
Navy Federal Credit Union is a nonprofit financial institution founded in 1933. It serves the Armed Forces, Department of Defense, veterans, and their families. With over 15 million members and more than 25,000 employees, it operates as the largest credit union in the world. The organization maintains its headquarters in Vienna, Virginia, alongside additional campuses in Florida, California, and Virginia.
How to get in at Navy Federal Credit Union
Securing an internship at Navy Federal Credit Union requires speed because early applicants are often reviewed before the candidate pool becomes unmanageable. Intern Insider sends an instant alert the moment a role matching your target is published anywhere, helping you apply among the first. This timing often makes the difference between being seen and getting lost in a high volume of submissions. You can also improve your chances by reaching out to the right people. Intern Insider surfaces the recruiters behind the company roles so you can reach out directly to ask about the position or a referral. This approach often improves response rates compared to submitting an application into a general queue.


