
Lead Security Research Engineer
Qualys, Inc.2 hours ago
Pune, IndiaStaff+
Responsibilities
- Set technical direction and own the roadmap for vulnerability detection libraries across the Qualys Scanner product suite.
- Lead research, design, and development of detection logic for databases, applications, operating systems, TCP/IP protocols, and network devices.
- Mentor and technically guide Senior and mid-level Research Engineers through design reviews, code reviews, and engineering standards.
- Explore and adopt AI/ML techniques for automated signature generation, false-positive and false-negative reduction, anomaly detection, and vulnerability triage.
- Design and scale automation frameworks for research, development, and validation tasks.
- Evaluate emerging technologies and threat trends and collaborate with customers, vendors, and internal stakeholders to expand detection coverage.
- Lead resolution of complex customer issues and drive systemic fixes for false positives and false negatives.
- Represent the team in cross-functional planning with technical estimates, risk assessments, and delivery commitments.
- Promote documentation, knowledge sharing, and engineering excellence.
Requirements
- At least 7 years of experience in network and systems security, including technical leadership or team mentorship.
- Deep understanding of TCP/IP, HTTP, FTP, SSH, and SSL/TLS protocols.
- Strong knowledge of security vulnerabilities and mitigation techniques.
- Hands-on experience with Python and Bash scripting.
- Hands-on experience with Docker, Kubernetes, containers, and orchestration tools.
- Familiarity with network analysis tools and packet capture analysis.
- System administration experience on Windows or Unix/Linux platforms.
- Strong understanding of VPNs, firewalls, and IDS/IPS technologies.
- Ability to prioritize, plan, and manage multiple workstreams and people in a fast-paced environment.
- Excellent written and verbal communication skills for technical and non-technical audiences.
- Preferred: experience applying AI/ML or LLMs to security problems and vulnerability detection.
- Preferred: knowledge of Lua or Java.
- Preferred: experience with VMware, VirtualBox, or Xen virtualization platforms.
- Preferred: understanding of AWS, Azure, or Oracle Cloud and their AI/ML services.
- Preferred: experience using or developing vulnerability scanners, IDS/IPS, security tools, or large-scale security automation.
- Preferred: OSCP, CISSP, or GIAC certifications.
- Preferred: track record of independently leading projects and small teams.
Benefits
- Opportunities for professional development, certifications, and continuous learning.
- Inclusive culture emphasizing innovation, ownership, and customer impact.