
Senior Web Application Security Engineer
Qualys, Inc.2 hours ago
Pune, IndiaSenior
Responsibilities
- Research and implement vulnerability detections for current web application technologies and CVEs.
- Fine-tune detection logic and payloads to achieve zero false positives for the Qualys Web Application Security product.
- Create exploits and proof-of-concept implementations for web application vulnerabilities.
- Develop security-related tools and programs and analyze network traffic and packet captures.
- Work with web application firewall rules, scanners, and open-source security tools.
Requirements
- Require 4–8 years of industry experience in web application security.
- Strong JavaScript programming skills and scripting experience with Python and Bash.
- Knowledge of HTTP, web application vulnerabilities, OWASP Top 10, APIs, and LLMs.
- Experience with DAST or black-box tools, Burp, ZAP, SQLMap, cURL, Selenium, and Postman scripting.
- Experience with network analysis, packet captures, regular expressions, Windows or Unix system administration, and database/SQL concepts.
- Exposure to Java, Metasploit, Nessus, web application firewalls, ModSecurity, XML/XPath, JSON, and Swagger.
- Strong analytical, problem-solving, troubleshooting, independent-working, and attention-to-detail skills.
- Security certifications and published research are listed as additional qualifications.
- Bachelor's or master's degree in Computer Science or Engineering, or equivalent practical experience.