Qualys, Inc.

Senior Security Research Engineer

Qualys, Inc.
Apply
2 hours ago
Pune, IndiaSenior

Responsibilities

  • Analyze vulnerabilities down to affected code paths, trigger conditions, exploitable primitives, and patch changes.
  • Develop proof-of-concept exploits in laboratory environments to establish reachability, reliability, and real-world impact.
  • Build non-harmful vulnerability checks for customer hosts using distinguishing signals instead of harmful payloads.
  • Assess mitigation bypasses involving ASLR, DEP/NX, stack canaries, CFI, RELRO, sandboxing, and modern hardware mitigations.
  • Design compiler, platform, defense-in-depth, and other mitigations for vulnerability classes and individual bugs.
  • Adapt public offensive and detection tooling while distinguishing detection logic, payloads, and bypass-critical components.
  • Create matched vulnerable and patched lab environments for exploitation, regression testing, and mitigation validation.
  • Document exploitation reasoning, verdict logic, residual risk, known gaps, and implementation tradeoffs.

Requirements

  • At least 3 years of vulnerability research experience.
  • BE, B.Tech, or MCA degree, preferably in Computer Science, Information Technology, or a related field.
  • Practical native and binary exploitation experience.
  • Command of memory-corruption classes including stack and heap overflows, use-after-free, double-free, type confusion, integer overflows, off-by-one, and format-string bugs.
  • Experience with debugger and disassembler/decompiler workflows using tools such as gdb with pwndbg or GEF, WinDbg, IDA, Ghidra, or Binary Ninja.
  • Experience with pwntools or an equivalent tool.
  • Fluency in vulnerability classes, root-cause analysis, and variant analysis.
  • Proficiency in at least one of Python, C/C++, Go, or Rust.
  • Strong technical writing skills for documenting exploitation reasoning, verdict logic, residual risk, and known gaps.
  • Working fluency with AI and LLM tools such as Claude Code.
  • Preferred: published CVE research, exploit development, coordinated disclosure, fuzzing, program analysis, reverse engineering, source-code review, detection or scanning platform authoring, CTF experience, and reproducible lab orchestration with containers or virtual machines.

Tech Stack

Categories

Qualys, Inc.

About Qualys, Inc.

1,001-5,000 employees
Contact me