Internship
Job Description:
Leonardo is an international industrial group, one of the world leaders in Aerospace, Defense, and Security, which creates multi-domain technological capabilities in Helicopters, Aircraft, Aerostructures, Electronics, Cyber Security, and Space. With over 60,000 employees worldwide, the company has a solid industrial presence in Italy, the United Kingdom, Poland, the United States, and operates in 150 countries also through subsidiaries, joint ventures, and participations. A protagonist in major strategic programs globally, it is a technological and industrial partner for Governments, Defense Administrations, Institutions, and businesses. In 2024, Leonardo recorded consolidated revenues of € 17.8 billion, new orders of € 20.9 billion, and invested € 2.5 billion in R&D activities. Innovation, continuous research, digital industry, and sustainability are the pillars of its business worldwide.
Experienced tutors in their field will guide you, allowing you to deepen your theoretical knowledge and develop your thesis, preparing you in the best possible way for future professional challenges.
The topics proposed for theses to be developed at Leonardo embrace a vast spectrum of technological, research, and innovation areas: from Artificial Intelligence to High-Performance Computing, from Cyber Security to Materials Engineering, passing through the aerospace sectors. You will be able to explore the most cutting-edge areas of your field of study, with creativity and a spirit of innovation.
To support you during this experience, which lasts a maximum of six months, a reimbursement of expenses is also provided.
We are looking for 1 young student to be placed in an internship, with the aim of developing their degree thesis on the topic of Cybersecurity on UAS legacy: "Vulnerability verification through formal models" at the Ronchi dei Legionari site.
The increasing integration of Unmanned Aerial Systems (UAS) into critical operational contexts makes it necessary to systematically address the vulnerabilities of legacy UAS, which are vulnerable because they were designed without current cyber defenses.
This thesis aims to bridge this gap through a methodological approach based on:
Reverse engineering hardware/software, identifying vulnerable entry points.
Formal models that formalize and verify security properties (integrity, authenticity, availability) ensuring the correctness of countermeasures.
Combining these approaches results in a methodology to retroactively strengthen the resilience of existing systems, reducing the risks of attacks and improving the security of the UAS system.
Main activities:
Analysis of the legacy UAS system
Collection and study of available documentation;
Reconstruction of the software/hardware architecture using reverse engineering techniques;
Identification of attack surfaces and structural vulnerabilities.
Reverse engineering and formal modeling
Extraction of functional behaviors and communication flows;
Definition of formal models for verifying security and resilience properties;
Validation of models through simulations and static/dynamic analysis.
Cybersecurity and resilience
Threat assessment according to standards and best practices (e.g., DO 326A, NIST, ENISA);
Definition of technical and procedural countermeasures applicable to legacy systems.
Main activities:
Analysis of the legacy UAS system
Collection and study of available documentation;
Reconstruction of the software/hardware architecture using reverse engineering techniques;
Identification of attack surfaces and structural vulnerabilities.
Reverse engineering and formal modeling
Extraction of functional behaviors and communication flows;
Definition of formal models for verifying security and resilience properties;
Validation of models through simulations and static/dynamic analysis.
Cybersecurity and resilience
Threat assessment according to standards and best practices (e.g., DO 326A, NIST, ENISA);
Definition of technical and procedural countermeasures applicable to legacy systems.
Support for regulatory compliance
Analysis of emerging regulatory requirements for UAS and critical systems;
Contribution to the preparation of evidence, technical reports, and compliance documentation.
Interdisciplinary collaboration
Interface with engineering, security, certification, and safety teams;
Participation in technical reviews, internal audits, and governance activities.
Educational qualification: Master's degree in Computer Science, Electronic Engineering, Automation Engineering.
Seniority: Junior
Technical knowledge and skills:
Proficiency in main programming languages, with the ability to develop scripts, analysis tools, and small applications;
Knowledge of TCP and UDP network communication protocols;
Understanding of fundamental cybersecurity concepts, including common vulnerabilities in embedded systems and network protocols;
Ability to identify elementary attack surfaces in software systems and communications.
Behavioral skills:
Proactivity;
Ability to work in a team;
Learning orientation;
Flexibility;
Communication;
Results orientation.
Language skills:
IT knowledge:
How does the selection process work?
Following the collection of applications, CVs that best meet the required qualifications are evaluated and identified.
Selected candidates will have an introductory interview with the Human Resources team and with the Business, where technical topics, motivation, and personal aptitudes will be explored.
At the end of the process, the person receives feedback, whether the outcome is positive or negative.
We look forward to your application.
By collaborating with us, you will constantly face the challenges of high technology, enhance your skills, and build a professional path of excellence.
Seniority: Junior
Primary Location: IT - Ronchi dei Legionari
Contract Type:
Hybrid Working: In loco
Sign up to apply and find out right away if you're a fit.
Your agent will tell you — in seconds.
Sign up and I'll tell you right away how well Leonardo matches you — what you already have, and what's missing. Then I stay on it: I search for you and only write when I find something worth your time.