
Senior Security Research Engineer
Qualys, Inc.1 hour ago
Pune, IndiaSenior
Responsibilities
- Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
- Research zero-day, newly disclosed, and actively exploited vulnerabilities and prioritize work based on real-world risk.
- Analyze vulnerability root causes, attack vectors, exploitability conditions, and business impact.
- Develop safe exploit-based validation techniques that emulate attacker behavior without affecting production systems.
- Write validation logic to determine whether WAFs, firewalls, EDRs, IPS, and compensating controls block exploitation.
- Set coding standards and quality guidelines for signatures and detection content.
- Improve automation, tooling, workflows, content generation, testing, and release processes.
- Review technical designs, research methods, and code contributions for quality and consistency.
- Lead projects, mentor technical teammates, and collaborate with Engineering and Product.
- Apply AI and LLM technologies to accelerate security research and detection engineering.
Requirements
- 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
- Strong background in vulnerability analysis, exploit development, and modern attack techniques.
- Solid understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
- Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
- Proficiency with Python and Bash scripting.
- Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
- Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics.
- Track record of leading projects and mentoring technical teammates.
- Strong written, verbal, and technical communication skills.
- Preferred: experience applying AI or LLM to security research or detection engineering.
- Preferred: contributions to CVEs, security advisories, open-source security tooling, or published research.
- Preferred: OSCP, OSCE, OSED, or GXPN certifications.
- Preferred: experience building detection content or signatures for IPS, WAF, or EDR platforms.