
Senior Security Research Engineer
Qualys, Inc.2 hours ago
Pune, IndiaSenior
Responsibilities
- Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
- Research newly disclosed, zero-day, and actively exploited vulnerabilities and prioritize work based on real-world risk.
- Analyze vulnerability root causes, attack vectors, exploitability conditions, and business impact.
- Build safe, exploit-based validation techniques that emulate attacker behavior without affecting production systems.
- Write validation logic to assess whether WAFs, firewalls, EDRs, IPS, and compensating controls block exploitation.
- Set coding standards and quality guidelines for signatures and detection content.
- Improve automation, tooling, workflows, testing, content generation, and release processes.
- Review technical designs, research methods, and code contributions for quality and consistency.
- Lead complex research projects, mentor technical teammates, and collaborate with Engineering and Product.
- Apply AI and LLMs to accelerate security research and detection engineering.
Requirements
- 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
- Strong background in vulnerability analysis, exploit development, and modern attack techniques.
- Solid understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
- Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
- Proficiency with Python and Bash scripting.
- Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
- Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics.
- Track record of leading projects and mentoring technical teammates.
- Strong written, verbal, and technical communication skills.
- Preferred experience applying AI or LLMs to security research or detection engineering.
- Preferred contributions to CVEs, security advisories, open-source security tooling, or published research.
- Relevant certifications such as OSCP, OSCE, OSED, or GXPN are preferred but not required.
- Preferred experience building detection content or signatures for IPS, WAF, or EDR platforms.
Benefits
- Hands-on senior individual-contributor role with ownership of complex research projects.
- Freedom to choose research topics and areas of specialization.
- Opportunities to mentor engineers and grow a career at Qualys.