Qualys, Inc.

Senior Security Research Engineer

Qualys, Inc.
Apply
1 hour ago
Pune, IndiaSenior

Responsibilities

  • Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
  • Research zero-day, newly disclosed, and actively exploited vulnerabilities and prioritize work based on real-world risk.
  • Analyze vulnerability root causes, attack vectors, exploitability conditions, and business impact.
  • Develop safe exploit-based validation techniques that emulate attacker behavior without affecting production systems.
  • Write validation logic to determine whether WAFs, firewalls, EDRs, IPS, and compensating controls block exploitation.
  • Set coding standards and quality guidelines for signatures and detection content.
  • Improve automation, tooling, workflows, content generation, testing, and release processes.
  • Review technical designs, research methods, and code contributions for quality and consistency.
  • Lead projects, mentor technical teammates, and collaborate with Engineering and Product.
  • Apply AI and LLM technologies to accelerate security research and detection engineering.

Requirements

  • 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
  • Strong background in vulnerability analysis, exploit development, and modern attack techniques.
  • Solid understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
  • Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
  • Proficiency with Python and Bash scripting.
  • Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
  • Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics.
  • Track record of leading projects and mentoring technical teammates.
  • Strong written, verbal, and technical communication skills.
  • Preferred: experience applying AI or LLM to security research or detection engineering.
  • Preferred: contributions to CVEs, security advisories, open-source security tooling, or published research.
  • Preferred: OSCP, OSCE, OSED, or GXPN certifications.
  • Preferred: experience building detection content or signatures for IPS, WAF, or EDR platforms.

Tech Stack

BashPython

Categories

Qualys, Inc.

About Qualys, Inc.

1,001-5,000 employees
Contact me