Security and Resilience Industrial Placement Review
at Nationwide
Placement (10 Months+)
Information Technology
Swindon
Review Submitted: July 2025
Overall Rating
4.8 /5
The Overall Rating is the average of all the ratings given in each category. We take those individual ratings and combine them into one final score!
Overview of Role
Please give an overview of your role and what this involves on a day-to-day basis.
This involved tasks such as:
- Policy Review and Tuning
- Insider Risk Management
- Automation and Scripting
Were you given much responsibility during your placement / internship?
- Managing Security Mailboxes: I monitored and triaged emails sent to the team’s shared mailboxes, helping to identify and escalate potential security concerns or user queries related to data loss.
- Context Monitoring: I reviewed alerts generated by DLP tools, assessing the context of user activity to determine whether it posed a risk. This involved analysing data movement, user behaviour, and policy triggers to support accurate decision-making.
As I gained experience, I transitioned into a more engineering-focused role, where I took on more technical and investigative tasks, including:
- Rule Tuning: I worked on refining DLP rules and policies to reduce false positives and improve detection accuracy. This involved analysing alert patterns and collaborating with stakeholders to ensure rules aligned with business needs.
IT Faults and Security Incidents: I supported the investigation and resolution of technical issues and security incidents, helping to identify root causes and implement corrective actions.
- Exception Management: I assisted in reviewing and processing exception requests, ensuring that any deviations from standard security policies were justified, documented, and appropriately risk-assessed.
This progression allowed me to build a strong foundation in both the operational and engineering aspects of information security, giving me a well-rounded understanding of how DLP functions within a large organisation.
Please rate how meaningful the work you were doing was
Skills Development
Have you learnt any new skills, or developed your existing skills?
Working with Microsoft Purview and Defender for Endpoint gave me hands-on experience with enterprise-grade tools for data classification, compliance, and endpoint threat detection. I became familiar with ServiceNow, using it to track incidents, manage tasks, and document investigations, an essential part of working in a structured security operations environment.
In addition, I enhanced my Python scripting skills by contributing to automation and data analysis tasks, which helped me understand how scripting can support security operations. I also deepened my understanding of information security classifications, learning how data is categorised and protected based on sensitivity and regulatory requirements. Finally, I gained practical experience in insider threat detection, learning how behavioural indicators and technical controls are used to identify and mitigate internal risks.
How would you rate the training provided during your experience?
How would you rate your development of industry-specific skills during the experience?
How would you rate your development of personal / soft skills during the experience?
Please rate how these skills have helped you in your career development
Support and Guidance
How much support and guidance did you receive during your placement / internship?
How would you rate the support and guidance from your line manager?
How would you rate the support and guidance from the wider team?
Company Culture
What was the company culture and general atmosphere like?
How would you rate the inclusiveness of the culture?
How would you rate the social opportunities?
How would you rate the diversity initiatives?
How would you rate the charity, sustainability and corporate social responsibility (CSR) initiatives?
Overall Experience
To what extent did you enjoy your placement / internship?
However, I found the Social Impact project to be less relevant to my role and personal interests. While I understand and respect the intention behind encouraging community-focused initiatives, the project felt somewhat disconnected from the technical and security-focused nature of my placement. As a result, it was more difficult to stay engaged with that aspect of the programme compared to the core responsibilities I was genuinely passionate about.