Qualys, Inc.

Senior Security Research Engineer

Qualys, Inc.
Apply
2 hours ago
Pune, IndiaSenior

Responsibilities

  • Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
  • Research newly disclosed, zero-day, and actively exploited vulnerabilities and prioritize work based on real-world risk.
  • Analyze vulnerability root causes, attack vectors, exploitability conditions, and business impact.
  • Build safe, controlled exploit-validation techniques that emulate attacker behavior without affecting production systems.
  • Write validation logic to determine whether WAFs, firewalls, EDRs, IPS, and compensating controls block exploitation.
  • Set coding standards and quality guidelines for signatures and detection content.
  • Improve automation across vulnerability research, exploit validation, content generation, testing, and release.
  • Apply AI and LLM technologies to accelerate security research and improve tooling and workflows.
  • Review technical designs, research methods, and code contributions for quality and consistency.
  • Lead complex research projects, mentor technical teammates, and collaborate with Engineering and Product.

Requirements

  • 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
  • Strong background in vulnerability analysis, exploit development, and modern attack techniques.
  • Solid understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
  • Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
  • Proficiency with Python and Bash scripting.
  • Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
  • Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics.
  • Track record of leading projects and mentoring technical teammates.
  • Strong written, verbal, and technical communication skills.
  • Preferred experience applying AI or LLM to security research or detection engineering.
  • Contributions to CVEs, security advisories, open-source security tooling, or published research are preferred.
  • Relevant certifications such as OSCP, OSCE, OSED, or GXPN are preferred but not required.
  • Experience building detection content or signatures for IPS, WAF, or EDR platforms is preferred.

Benefits

  • The role offers freedom to choose research topics and areas of specialization.
  • The position includes opportunities for career growth at Qualys.

Tech Stack

BashPython

Categories

Qualys, Inc.

About Qualys, Inc.

1,001-5,000 employees
Contact me