
Lead Security Research Engineer
Qualys, Inc.1 hour ago
Pune, IndiaStaff+
Responsibilities
- Lead vulnerability research initiatives across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
- Research newly disclosed, N-day, and actively exploited vulnerabilities.
- Develop exploit-based exposure validation techniques to confirm real-world exploitability.
- Review technical designs, research methodologies, and code contributions for quality and consistency.
- Partner with Engineering and Product teams on roadmap decisions and security content strategy.
- Design safe validation mechanisms that emulate attacker behavior without affecting production systems.
- Analyze vulnerability root causes, attack vectors, exploitability conditions, and business impact.
- Mentor and guide Security Research Engineers on vulnerability analysis, exploit analysis, and signature creation.
- Build validation logic to assess whether WAFs, firewalls, EDRs, IPS, and compensating controls prevent exploitation.
- Drive automation for vulnerability research, exploit validation, content generation, testing, and release processes.
- Establish best practices, coding standards, and quality guidelines for signature development.
Requirements
- Bachelor's degree in a relevant field or equivalent experience.
- 8+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
- Deep understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
- Strong expertise in vulnerability analysis, exploit development, and attack techniques.
- Extensive knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
- Strong coding background.
- Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
- Knowledge of OWASP Top 10, common attack techniques, and modern threat actor tactics.
- Excellent written, verbal, and technical communication skills.
- Demonstrated experience leading projects and mentoring technical teams.
- Preferred knowledge of Lua, Bash, Python, cloud platforms such as AWS, Azure, or Oracle, regular expressions, Docker, Kubernetes, vulnerability scanners, IDS, and security tools.
- Preferred OSCP, CISSP, or SANS GIAC certification.